Expert Reaction

EXPERT REACTION: Origin Energy investigates data breach

Publicly released:
Australia; NSW; VIC; QLD
Photo by Markus Spiske on Unsplash
Photo by Markus Spiske on Unsplash

One of Australia's largest energy providers, Origin Energy, has reported it is investigating a potential data breach after a hacker claimed to have gained access to the personal details of up to two million customers. The ABC has reported speaking with someone who claimed to be behind the hack and provided a sample containing real contact information. While the ABC was not able to confirm with Origin that the data was legitimate, a person whose phone number was in the sample confirmed with the ABC they had been Origin customers. The breach does not appear to include customer credit card or bank details, Origin adds.

Expert Reaction

These comments have been collated by the Science Media Centre to provide a variety of expert perspectives on this issue. Feel free to use these quotes in your stories. Views expressed are the personal opinions of the experts named. They do not represent the views of the SMC or any other organisation unless specifically stated.

Dr Rumpa Dasgupta is a Lecturer in Cybersecurity in the Department of Computer Science & IT at La Trobe University

"It could be another disappointing day for Australian consumers. Origin Energy, one of Australia's largest electricity and gas providers, is investigating claims by a hacker who alleges they have obtained the personal information of up to two million customers. While the company has not yet confirmed the claims or disclosed how the alleged incident occurred, the report has once again raised concerns about the security of customer data within Australia's critical infrastructure sector.

According to the hacker, the compromised data includes customers' names, phone numbers, dates of birth, email addresses, and copies of electricity bills, exposing individuals to identity theft, phishing, financial fraud, and other cyber-enabled crimes. An electricity bill is more than just an invoice. It can provide valuable insights into a household. Energy consumption patterns may reveal when residents are typically home or away, the types of appliances they use, occupancy trends, and even periods of extended absence, such as weekends or holidays. In the wrong hands, this information could be exploited not only for highly targeted phishing campaigns but also to support physical crimes such as burglary by identifying vulnerable properties.

As a key operator within Australia's critical energy sector, Origin Energy is subject to the Security of Critical Infrastructure (SOCI) Act 2018 and the Privacy Act 1988. If the reported breach is confirmed, it raises important questions about whether the company fully met its obligations under these two Acts. During this critical time, the technical investigation will be only one part of Origin Energy's responsibility. Equally important is how the company communicates with its customers. Uncertainty often creates as much harm as the breach itself. Customers deserve timely updates, clear explanations of what information may have been exposed, and practical guidance on protecting themselves from follow-on attacks."

Last updated:  23 Jul 2026 1:06pm
Contact information
Contact details are only visible to registered journalists.
Declared conflicts of interest None declared.

Gernot Heiser is Scientia Professor and John Lions Chair at UNSW Sydney.

"For the available information, my first impression is that this looks like an irresponsible downplaying of the seriousness by Origin. Credit card and bank account details are by far not the most sensitive information to leak. Date of birth is much more serious, as it is part of what uniquely identifies a person and cannot be changed. Changing a credit card number is annoying (I went through it only a month ago) but a straightforward process, and by now, multi-phase authentication approaches are standard, making it much harder to steal money with a stolen credit card number.

The underlying problem, besides companies consistently downplaying the damage they cause, is that our computing infrastructure, especially enterprise computing systems, is inherently insecure. It depends on massively complex systems no one can fully understand, that are full of faults that can be exploited to compromise these systems. And these days, AI tools are becoming increasingly effective at doing so.

However, in many cases these compromises are significantly aided by negligence, as we have seen in recent exploits (Telstra, Optus)

And the problem is that these companies are getting away with saying 'oops, we’re sorry' and no-one is held truly accountable.

What is needed is that there is a high cost of these incidents to individuals and society at large, and the companies (and their directors) must be made to pay for those costs."

Last updated:  23 Jul 2026 12:44pm
Contact information
Contact details are only visible to registered journalists.
Declared conflicts of interest None declared.

Professor Daswin De Silva is Professor of AI and Analytics and Co-Director of the La Trobe AI Institute at La Trobe University

"Origin Energy appears to have been alerted to a potential cybersecurity breach when the alleged hackers shared a subset of stolen customer data with an Australian news outlet. This is not yet established as a cyberattack as the investigation progresses with the Australian Cyber Security Centre and Australian Federal Police directly involved.

This subset of data contains highly sensitive customer data, including names, addresses, emails, dates of birth, phone numbers, and billing records, so the breach is likely authentic.

Origin is Australia’s largest energy retailer, holding the largest customer base of 4.7 million. As critical infrastructure, Origin is governed by the Federal Government's Security of Critical Infrastructure Act, which means cybersecurity must be front and centre for Origin's business operations.

This is a poor look for Origin as the largest operator of critical energy services and a highly visible public organisation.

This potential cyber-attack comes on the back of further alarming news of OpenAI's frontier AI model escaping a controlled test environment to hack into systems of a third-party organisation, Hugging Face, which contained data for achieving its testing objective.

Despite the continuing investigation, Origin must be proactive in contacting its 4+ million customers and provide assurances of service continuity and assurance of security and privacy of highly sensitive data that is potentially breached and how customers will be compensated and protected from subsequent attacks.”

Last updated:  23 Jul 2026 12:44pm
Contact information
Contact details are only visible to registered journalists.
Declared conflicts of interest None declared.

Dr David Tuffley is an Adjunct Senior Lecturer in the School of Information and Communication Technology at Griffith University

"Origin has notified the Australian Cyber Security Centre, AFP and privacy regulator, as they are required to by law. But as a matter of urgency, the company needs to establish what was accessed, notify those customers who are affected, explain to them exactly what data is involved, and provide practical support. Vague reassurance won't cut it - timely facts will."

Last updated:  23 Jul 2026 12:43pm
Contact information
Contact details are only visible to registered journalists.
Declared conflicts of interest None declared.

Dr Jacqueline Boaks is the Curriculum Lead for the Centre for Applied Ethics at Curtin University, Vice-President of the Australian Association for Professional and Applied Ethics, and Philosopher-in-Residence at the WA Data Science Innovation Hub.

“This is the latest in a long line of customer data breaches. Companies must do better. Delays in notifications, including reports that Origin ignored hackers’ emails, passive language (‘information may have been accessed’) and minimising language (suggesting customers should be less worried about non- payment details being leaked) are extremely disappointing.

Energy usage tells much more about us and our lives than ever before. With the increase of smart devices, including home systems that monitor and capture everything from when we arrive home to what we eat, much can be known about us through this data. This will only increase as our homes become more technologically sophisticated. We must ensure protections are in place.

Recent, growing calls for a digital duty of care would require providers and platforms to ensure the safety of users and their details. This matches safety legislation for physical products. Sellers of everything from toys to cars to food have an obligation to ensure a product is safe before selling it. A digital duty of care would oblige providers to keep up to date with known issues such as data vulnerabilities and have in place protections that are fit for purpose. The ethical and safety standards that we require of sellers of physical products can be brought to apply to online products and services, assuming we have the will to do so.”

Last updated:  23 Jul 2026 12:43pm
Contact information
Contact details are only visible to registered journalists.
Declared conflicts of interest None declared.

Professor Paul Haskell-Dowland is Professor of Cyber Security Practice at Edith Cowan University

"The Origin Energy security incident is, unfortunately, just another example of a critical service being the target of malicious criminal activity.  As has been said previously, this highlights the importance of our critical infrastructure and the high value of data/systems to criminals.

It will likely be some time before we will have a clear understanding of the cause of the incident and the subsequent damage. At present, we only know that customer data has been impacted (e.g. names, addresses, emails, dates of birth and phone numbers) and this will likely extend to billing information (e.g usage data). Origin has consistently reported that banking/card details have not been impacted.

While some will be unhappy that any personal information has been accessed, for many, this is just another incident where their personal details have been stolen.

The threat of public release of data is not unusual – it is quite common for criminals to steal data and to then threaten to publish the information unless a payment is made. Using court orders to prevent such publication (as with Partnered Health recently) is pointless as criminals will rarely obey such directives!

Customers of Origin must be cautious with any emails or text messages relating to the company or their data. While the initial payout is the target for criminal groups, subsequent sale of the data to third parties can result in the data being used for scam campaigns."

Last updated:  23 Jul 2026 12:42pm
Contact information
Contact details are only visible to registered journalists.
Declared conflicts of interest None declared.

Dr Fariha Tasmin Jaigirdar is a lecturer in cybersecurity at Deakin University

"Australia is once again absorbing news of a major cyber incident, this time involving Origin Energy and its 4.8 million customer accounts. Yet as with so many recent breaches, what the public receives is an announcement, not an explanation. The attack progression, the tactics and techniques employed, and the initial access vector remain undisclosed. This raises a question we do not ask often enough: what do these attacks actually teach us?

Disclosure, as currently practised, serves a narrow legal function. Genuine transparency would serve two cohorts: the technical community, which needs attack trails and lessons that strengthen collective defence, and customers, who deserve a clear account of what happened to their data. When neither audience is meaningfully informed, each incident becomes an isolated headline rather than shared learning.

Origin has stated it does not believe the affected data includes credit card or bank details. But how is public trust preserved when the reports indicate that one person, whose phone number appeared in the leaked sample, confirmed they had been an Origin customer until recently selling their house, and now fears further exposure?

Names, phone numbers, email addresses, and residential addresses are critical identity information; their potential compromise is, unequivocally, a matter of urgency.

That a former customer's details surfaced at all also raises a harder question: why is such data retained after the relationship ends?

Public trust is not preserved by reassurance. It is preserved by transparency, accountability, and data practices that respect people long after the bill is paid."

Last updated:  23 Jul 2026 12:42pm
Contact information
Contact details are only visible to registered journalists.
Declared conflicts of interest None declared.

Mihai Lazarescu is an Associate Professor at Curtin University

"If the breach is indeed confirmed, it is just another piece of evidence that defending critical systems that have personally identifiable information (PII) is a losing battle and one that will get more expensive with time. The truth is that 99% of people have no understanding of how difficult it is to protect data because it requires both the technical and administrative aspects of security (which involve people) to be perfect.

I have worked in this area for over 16 years, and even banks (I have done security work for three banks in Australia) that have massive budgets compared with most organisations have major problems. There is no such thing as 100% security, and you cannot “fix” people – mistakes will be made, and the question that everyone should be asking is why put such information in digital form online and have 24/7 connectivity, which massively increases the chance that it will be compromised.

In my opinion, critical infrastructure (power is an essential aspect of critical infrastructure) should not be connected to the Internet. Is it cheaper and more convenient? Yes, but at what cost? The fact that a power company was potentially breached should have been expected, and it will get worse. What should worry everyone is that operational technology devices, which are the fundamental base of industrial systems, have been and are going online. You want to turn off critical systems remotely? Digitisation makes it not just possible but likely. A serious discussion should be taking place that outlines in plain English to all stakeholders (and that includes the customers) what the actual risks are (instead of wishful thinking) and the consequences that will need to be faced when the security measures fail."

Last updated:  23 Jul 2026 12:42pm
Contact information
Contact details are only visible to registered journalists.
Declared conflicts of interest None declared.

Dr Rahat Masood is a Senior Lecturer in Cyber Security at UNSW Sydney

"While the investigation is still ongoing, it is encouraging to see Origin responding quickly and communicating openly with customers. As one of Australia's critical infrastructure providers, energy companies have significant cybersecurity obligations under the Security of Critical Infrastructure (SOCI) Act and are expected to have robust measures in place to detect, respond to and recover from cyber incidents.

Even if payment details were not compromised, personal information such as names, addresses, phone numbers and email addresses can still be valuable to cybercriminals and may be used for targeted phishing, identity theft and social engineering attacks. Incidents like this reinforce that cybersecurity is no longer just an IT issue; it is a core part of operating essential services. While it is too early to speculate on the cause of this incident, transparent communication and a well-managed response are critical for maintaining public trust."

Last updated:  23 Jul 2026 12:41pm
Contact information
Contact details are only visible to registered journalists.
Declared conflicts of interest None declared.

It is highly commendable that Origin Energy actively investigates potential cyber security incidents and notifies ACSC immediately. We see the changes that companies like Origin Energy are standing up against cyber attacks, rather than concealing them.

These types of incidents will never disappear. It is important that we continue encouraging victims to stand up and that the public support those companies who are willing to disclose the incident. It will help build a better cyber resilience.

Last updated:  23 Jul 2026 12:41pm
Contact information
Contact details are only visible to registered journalists.
Declared conflicts of interest None declared.
Journal/
conference:
Organisation/s: Australian Science Media Centre
Funder: None.
Media Contact/s
Contact details are only visible to registered journalists.