Skip to content
OrionX
Cybersecurity

Origin Energy's 900,000-Customer Breach Is a Warning for Every Australian Business

OrionX Team29 July 20265 min read

On 28 July 2026, Origin Energy told close to 900,000 current and former customers that someone had been inside their systems. Names, addresses, dates of birth, phone numbers, account details, and partial payment information were accessed. A hacker later claimed the real number was closer to two million and demanded a ransom.

Origin is a big company with a security team, a budget, and lawyers on retainer. If it can happen to them, "we're too small to be a target" stops being a real strategy.

This wasn't a one-off

Origin joins a run of major Australian breaches this year, and the pattern underneath it is worse than any single headline. The Office of the Australian Information Commissioner recorded 1,205 data breach notifications in 2025, an all-time high and an 8% jump on the year before. Fifty-nine per cent of those came from malicious or criminal attacks, not accidents or misconfigured systems.

Cloudflare's most recent survey of Australian businesses found 41% had experienced at least one breach in the past year. A third of those had been hit eleven times or more. Attackers aren't picking a handful of high-profile targets and moving on. They're running the same playbook against whoever leaves a door open.

Small businesses are very much included. The Australian Signals Directorate's 2024-25 Annual Cyber Threat Report puts the average cost of a cybercrime for a small business at $56,600, up 14% on the year before. That's not the cost of a headline-grabbing breach. That's the average. The JADEPUFFER incident from earlier this month is a useful illustration of how fast those costs stack up once attackers are already inside.

The compliance risk is catching up to the security risk

For years, the practical consequence of a breach in Australia was reputational: an awkward email to customers, maybe a news story that faded in a week. That's changing.

In February 2026, the Federal Court ordered FIIG Securities to pay $2.5 million after ASIC took action over cyber security failures spanning more than four years. It was the first time the Court had imposed civil penalties for cyber failures under general AFS licensee obligations, and it signals where regulators are heading: security isn't just good practice anymore, it's an enforceable obligation.

If your business holds personal information and a breach is likely to cause serious harm, you're generally required to notify the OAIC and the people affected under the Notifiable Data Breaches scheme. Get that wrong, or don't have the systems in place to even know a breach happened, and the compliance failure can end up costing more than the breach itself.

What actually reduces the risk

None of this requires an enterprise security budget. The controls that matter most are ordinary and well understood, they're just often left half-finished:

  • Multi-factor authentication everywhere it can go. Still the single highest-return control available, and still the one most commonly skipped on legacy systems or admin accounts.
  • Patching on a real schedule, not "when someone gets around to it." Unpatched software is behind a large share of the incidents in every one of these reports.
  • Knowing where your data actually lives. You can't protect what you haven't mapped. A lot of businesses discover during an incident that customer data is sitting in a spreadsheet nobody remembered existed.
  • An incident response plan you've actually tested. Origin's own timeline shows how much time can pass between "something looks odd" and "we're confident this is a breach." A plan that only exists as a document doesn't close that gap. The disclosure timeline from recent AI security incidents shows the same pattern plays out even at well-resourced organisations.
  • Third-party and vendor risk. A growing share of breaches start with a supplier, not the business itself. If you don't know how your vendors handle your data, that's a gap worth closing before a regulator or an attacker finds it for you.

The Essential Eight, the Australian Cyber Security Centre's baseline framework, covers most of this and is a reasonable target for any business handling customer data, not just APRA-regulated ones.

The honest takeaway

Origin Energy will absorb this. It has the resources to weather the fines, the customer churn, and the headlines. Most Australian businesses don't have that kind of runway, and the data says they're being hit just as often, if not more.

The businesses that come out the other side of an incident in reasonable shape are almost always the ones that did the unglamorous work beforehand: MFA turned on properly, systems patched, a plan that's been through a dry run, and a clear picture of where their data sits.

If you're not sure where your business stands against that list, that's worth a conversation before it's forced by an incident.


Sources: Bloomberg, "Origin Says About 900,000 Customers' Data Accessed in Breach" (28 July 2026); SecurityWeek, "Data Breach Confirmed After Australian Energy Giant Origin Is Hacked" (24 July 2026); CyberPulse, "The State of Cyber Security in Australia 2026," citing OAIC and ASD Annual Cyber Threat Report 2024-25; Corbado, "15 Biggest Data Breaches in Australia [2026]"; Insurance Business Australia on the FIIG Securities/ASIC penalty.

Trying to solve a problem with AI, cloud, or software? Let's talk it through.