Technology
What have we learnt from Origin Energy's data breach?
Key Points
Origin Energy data leak cybersecurity lessons have experts worried Three weeks ago, Origin Energy told 900,000 former and current customers that their information had been exposed in a data breach. The major cybersecurity data leak made headlines and raised the alarm that the threats were becoming more prevalent. It also showed that anyone with their information online could be vulnerable, according to Curtin University Associate Professor in AI and Cybersecurity, Mihai Lazarescu.
Origin Energy data leak cybersecurity lessons have experts worried
Three weeks ago, Origin Energy told 900,000 former and current customers that their information had been exposed in a data breach.
The major cybersecurity data leak made headlines and raised the alarm that the threats were becoming more prevalent.
It also showed that anyone with their information online could be vulnerable, according to Curtin University Associate Professor in AI and Cybersecurity, Mihai Lazarescu.
"There is no such thing as 100 per cent security,"he said.
Associate Professor Lazarescu, who has worked in cybersecurity for over 16 years, said whenever anyone put information online, there was a chance it could be compromised.
That included commonly used details, such as email addresses and first and last names.
"Never give your full name and date of birth because that is identifiable evidence," he said.
How did Origin Energy compare to Australia's biggest data breaches?
Origin's breach affected hundreds of thousands of customers, but it wasn't technically the largest.
Australian companies such as Canva, Optus, and Qantas had data breaches that affected millions of customers.
Canva
Read moreAustralian online design tool Canva suffered a data breach impacting 137 million of its users in 2019.
- A cybercriminal identified as Ghosticplayers breached Canva's defences but was stopped by Canva when it detected malicious activity in its systems.
- Access to usernames, real names, email addresses, country data, encrypted passwords and partial payment data of users was leaked.
Latitude
Read moreIn March 2023, Latitude, the Australian personal loan and financial service provider, was affected by a data breach that impacted more than 14 million people from Australia and New Zealand.
- The Latitude breach was one of Australia's largest breaches in recent history.
- The attack occurred when one set of employee credentials was stolen, allowing access to Latitude's customer data, including full names, physical addresses, email addresses, phone numbers, dates of birth, driver's licence numbers and passport numbers.
- Much of the information was data stored from 2005, which drew questions on why companies continue to store customer records beyond the required seven-year time frame.
Optus
Read moreIn September 2022, the Optus data breach impacted 9.8 million customers.
- The security incident brought up questions about Australian data security policies and how companies handled them.
- Cybercriminals believed to be working for a state-sponsored operation breached Optus's internal network, compromising personal information and impacting up to 9.8 million customers, almost 40 per cent of the population.
- Personal data included names, birth dates, addresses, phone numbers, passport information, driver's license numbers, government ID numbers, medical records & Medicare card ID numbers.
Medibank
Read moreIn December 2022, Medibank, the Australian health insurance giant, was the victim of a data breach affecting the personal details of 9.7 million customers.
- The attack was believed to be linked to a well-known ransomware group based in Russia, the REvil ransomware gang.
- The privacy breach was first discovered when REvil posted on a dark web blog a folder that contained 6GB of raw data samples, indicating that they had larger amounts of data to release, and demanded a $10 million ransom. The data included names, birthdates, passport numbers, medical claims data, and medical records.
Qantas
Read moreIn July 2025, up to 6 million Qantas customers were affected when the Australian airline confirmed a data theft incident that impacted a significant portion of its customer base.
- Data compromised included names, email addresses, phone numbers, dates of birth, and frequent flyer numbers.
- The breach was reportedly attributed to a cyber attack targeting the airline's call centre.
Origin
Read moreIn July 2026, Origin Energy, Australia's largest energy retailer with more than 4.8 million customers, announced that the information of 900,000 current and former customers was accessed during a data security breach.
- The energy provider confirmed it first became aware of a potential security threat in early July but initially did not believe it credible.
- The company said it was still working to determine the total number of people affected and would notify impacted customers.
- While there is no indication full payment card details were compromised, experts say the stolen information remains highly valuable and are urging affected customers to remain cautious about unsolicited emails, text messages and phone calls long after the breach.
The information included names, dates of birth, phone numbers, home addresses and email addresses, as well as the last four digits of some credit cards and the last three digits of some bank account numbers.
What does the Origin breach reveal about cybersecurity?
Associate Professor Lazarescu said the fact that a power company was potentially breached should have been expected, given how easy data could be accessed online.
"It will get worse," he said.
"99 per cent of people have no understanding of how difficult it is to protect data.
"It requires both the technical and administrative aspects of security to be perfect."
He said the only way to be fully protected online was to be "checking all the time", from bank statements to which information was given online.
Recent data from the Office of the Australian Information Commissioner (OAIC) showed most of the leaked customer information in data breaches included contact details, financial details and identity information.
Associate Professor Lazarescu said social media was also one of the easiest ways for criminals to access data.
"You see people posting online with photos with specific locations, timing. These are not secure," he said.
"When you have criminal groups that are very well organised and make a lot of money out of what they do, these are not beginners.
"I've seen groups that were based in Europe where there were 11-year-olds coding."
Associate Professor Lazarescu said having data leaked could not only put people at risk of being hacked but, in worst-case scenarios, their data could be sold on the dark web to criminal groups.
"It could create a situation that's expensive and complicated to fix," he said.
He said serious discussion should be taking place that outlined to customers what the risks of data leaking could entail and the potential consequences if security measures failed.
Hidden costs of data leaks
The severity of a data breach depends on the sensitivity of the data and the nature of the exposure, rather than just the total number of people affected.
Charles Sturt University computing professor Yeslam Al-Saggaf said the Origin data breach was "more concerning" than the Canva breach, despite fewer customers being affected.
"The value of data is low as these students don't have credit cards, don't have car loans, mortgages, and don't have driver's licences," Professor Al-Saggaf said.
"Whereas in the Origin data breach financial details of individuals and businesses have been compromised."
He said when individuals' and businesses' financial details were published online, it exposed them to a range of risks, such as losing money through payment redirection attacks and identity theft.
He said businesses and individuals could also face a situation with additional costs and an increase in insurance premiums.
Cyber insurance providers have noted the increase in cyber-attacks and, in turn, are raising premiums.
- According to a 2025 report by the Australian Signals Directorate's Australian Cyber Security Centre, the Australian Cyber Security Centre responded to 1,200 cybersecurity incidents in the last financial year, an 11 per cent increase.
- The average self-reported cost of a cyber incident for a small business had risen to 14 per cent, while medium businesses have seen a 55 per cent increase.
Cyber-hacking number one cause of data breaches
The Office of the Australian Information Commissioner (OAIC) received 1,205 data breach notifications in the 2025 calendar year, representing an 8 per cent increase from 2024, according to OAIC data.
Cyber hacking remains the primary cause of data breaches reported to the OAIC.
Of the data breaches notified in 2025, the majority were attributable to malicious or criminal activity.
Health service providers were the most commonly affected, accounting for 19 per cent of the total.
How can we protect our data from being leaked?
The Australian government said it had revised its cybersecurity policies to strengthen resilience against nation-state threat actors amid the rise in cyber attacks.
In 2025, the OAIC launched a new Notifiable Data Breaches (NDB) statistics dashboard to keep the public informed on the volume and type of data breaches occurring.
Professor Al-Saggaf said "people are becoming numb to the drama of data breaches", and people who remained naive to cybersecurity were most at risk.
"They happen every day in Australia because Australians are trusting, affluent, speak English, and some are not technically savvy," he said.
"We need to improve our literacy with respect to cybersecurity hygiene practices."
He advised using a strong, unique password that differed for each account, or using a password manager, to help protect individuals.
He said enabling multi-factor authentication could provide an additional layer of verification, and using secure payment methods on secure websites could also help avoid potential security risks.
But as scammers started to integrate artificial intelligence into their operations, he warned regular security measures would need to be strengthened.
"AI is going to make impersonation more sophisticated, so use more than one method to communicate with your close contacts if they ask for financial assistance, and keep an eye on bank balances and credit card statements," he said.
- Share options
- Copy link
- X (formerly Twitter)