eCommerceNews Australia - Technology news for digital commerce decision-makers
Australia
Origin Energy probes alleged cyber incident over data

Origin Energy probes alleged cyber incident over data

Fri, 31st Jul 2026
Mark Tarre
MARK TARRE News Chief

Origin Energy is investigating an alleged cyber incident involving customer data after a hacker claimed to have accessed two million customer records.

The energy retailer disclosed the incident after a threat actor told local media they had exfiltrated data from Origin's systems. Origin has notified regulators and is working with external experts as it assesses the scope of the incident and the credibility of the claims.

Security researchers say the episode highlights Australia's continued appeal to cybercriminals. Recent incidents across sectors from healthcare to utilities have raised questions about how major organisations collect, store and secure personal information.

"Australia continues to be a high-value target for malicious actors because organisations hold huge amounts of customer data. Even where financial information isn't compromised, personal data can be weaponised for highly targeted phishing, identity fraud, social engineering and extortion," said Professor Craig Costello, Professor of Cybersecurity at Queensland University of Technology.

Costello said public claims of compromise are now common and can range from baseless boasts to serious intrusions.

"Australian organisations regularly face claims of cyber compromise. Some are opportunistic attempts by criminals seeking attention or extortion payments, while others are legitimate breaches. The challenge for organisations is responding quickly and responsibly while verifying the facts, because the consequences of both underestimating and overstating a cyber incident can be significant," he said.

The alleged Origin incident emerged soon after a major cyber attack on healthcare provider Partnered Health, sharpening scrutiny of the country's cyber resilience and of how organisations handle sensitive records across critical services.

High-value sectors

Healthcare operators and critical infrastructure providers hold extensive data on individuals and organisations, making them attractive targets for both financially motivated gangs and state-linked actors.

"Healthcare and critical infrastructure continue to be prime targets because they hold some of the most valuable data for cyber attackers. This data is deeply personal, making the impact especially serious and infinitely harmful," Costello said.

Regulators have urged organisations in these sectors to strengthen baseline security and improve incident response. The Federal Government has also signalled tougher penalties and stricter reporting rules after a run of large breaches in recent years.

Transparency and response

Specialists argue that how a company communicates during a suspected breach can matter as much as the technical details of the attack. Boards face pressure from customers, shareholders and regulators to disclose incidents quickly and provide clear guidance.

"Organisational transparency is critical when customer data has been compromised. Early disclosure demonstrates accountability, helps customers understand potential risks and enables timely regulatory engagement," Costello said.

KnowBe4 CISO Advisor Kawin Boonyapredee said the Origin case also shows how difficult it can be to trace the source of cyber risk in modern environments.

"While the cause of the Origin Energy breach has not yet been established, the incident is a reminder that organisations are operating in an increasingly complex threat environment where cyber risk can emerge from multiple directions, including internal systems, trusted third parties, compromised credentials, or sophisticated criminal operations."

Boonyapredee said incident preparation must go beyond preventive controls to include monitoring and recovery.

"For organisations, incidents like this highlight the importance of cyber resilience. Preventing attacks remains critical, but it's equally important to have the visibility, monitoring, governance and response capabilities needed to quickly identify, contain and investigate security events when they occur."

Customers of affected firms face a different set of risks. Stolen or leaked data can circulate for years and fuel scams that appear credible because they reference genuine account details or past transactions.

"For customers, the focus should now be on potential follow-on scams. When personal information is exposed, cybercriminals often use that data to make phishing emails, text messages and phone scams appear more legitimate. People should be especially cautious of unsolicited communications that create urgency, request personal information, or direct them to click links or provide account details."

Costello warned that advances in artificial intelligence will reshape both attack and defence for organisations that manage essential services.

"We know technology is evolving rapidly and AI capabilities are becoming more powerful, but the challenge is that we don't fully know what comes next. As technological advancements and AI lower barriers to entry and enable attacks to be executed at greater speed and scale, protecting these sectors becomes even more critical to Australia's cyber resilience," Costello said.