Today, Origin Energy, Australia’s largest energy retailer, confirmed it is investigating what could become one of the largest data breaches in Australian corporate history. A hacker using the alias “John Doe” claims to have accessed the personal details of up to two million Origin customers.
The alleged hacker contacted both 7NEWS and The Australian on Wednesday, providing a sample of 50 customer records to verify the claim. The data reportedly includes names, addresses, email addresses, phone numbers, dates of birth, account numbers, property IDs, and detailed billing histories. Origin has stated it does not believe credit card or bank details were compromised.
The hacker alleges they contacted Origin’s board, security team, and customer care departments weeks ago but received no response. In an email to 7NEWS, “John Doe” wrote: “Despite my outreach to their board members, security teams, and customer care departments, Origin hasn’t made a public announcement about the breach or responded to negotiate next steps.” A 14-day countdown clock has been started, threatening public release of the full dataset if Origin does not engage.
Why This Breach Is Different
Origin Energy is not just another Australian company caught in a cyber incident. It manages critical national infrastructure. The energy sector is one of 11 “critical” industries governed by specific cybersecurity obligations under Australian law. A successful breach here carries implications far beyond stolen customer data.
UNSW Professor of Cyber Security Richard Buckland described the incident as a potential “canary in the coal mine”, warning that a compromised energy company could face scenarios where “they could cut off people’s power in winter or black things out.”
This is the second major breach in as many weeks. Last week, healthcare provider Partnered Health had sensitive medical records stolen from its network of 21 GP clinics across Sydney, Melbourne, and Canberra. The timing is especially concerning given that on July 14, the Australian Signals Directorate’s Australian Cyber Security Centre issued a joint advisory with the FBI and European intelligence agencies warning of increased malicious cyber activity linked to Russia’s Federal Security Service (FSB), specifically targeting the communications, defence, energy, and healthcare sectors.
The Response So Far
Origin has moved quickly to notify the relevant authorities, including the Australian Cyber Security Centre, the Australian Federal Police, and the Office of the Australian Information Commissioner. Cybersecurity researcher Jamieson O’Reilly commended the speed of Origin’s response: “Origin has done the right thing by moving quickly and bringing in the ACSC, the AFP and the Information Commissioner. Speed is everything in the first 48 hours of an incident like this, and AI is exactly why. Adversaries are AI-enabled now, and that means they move at a speed defenders have to plan for.”
Origin’s share price dropped 1.9 per cent on the announcement. If the breach is confirmed and the company is found to have failed in its security obligations, it could face fines of up to $50 million, or 30 per cent of its revenue.
The Extortion Playbook
Professor Damien Manuel, director of Deakin University’s Centre for Cyber Security Research and Innovation, said the hacker’s approach looks like a textbook extortion attempt. “To me, that suggests that they’re looking for a payout. They’re obviously trying to extort Origin Energy for a sum of money.”
Paying a ransom, however, is no guarantee. “The trouble with that is, criminals being criminals, can you really trust that they’re not going to release the data to somebody else or they’re not going to try again?”
UNSW’s Professor Sanjay Jha noted there is still very little verified information about the incident. “There is no way to verify if the data put to the media is authentic. Organised groups who do this kind of thing do resort to this tactic, like extortion first and then release data on the dark web.”
What This Means for Australians
With research from the War Studies Research Group finding that 47 per cent of Australians experienced some form of cybercrime last year, customer fatigue and anxiety are at unprecedented levels. If you are an Origin customer, here is what security experts recommend right now:
- Monitor your accounts for any suspicious activity, across both your energy accounts and your broader financial accounts.
- Change your passwords across your utility accounts and any email accounts that may share credentials.
- Be on high alert for phishing targeting you personally. Stolen billing histories can be used to craft convincing scam emails that appear to come from Origin or other utilities you use.
Origin has promised to provide further updates as its investigation continues. This is a fast-moving situation, and how the company handles the next 48 hours will set the tone for its response – and for how Australians judge the security of their critical infrastructure.
Every hour of delay is an hour an AI-enabled adversary uses to weaponise whatever they’ve taken.
Jamieson O’Reilly, Cybersecurity Researcher
Related Reading
- AI Agents, Copilot and the New Security Risk
- Security Experts Warn Washington: Banning Anthropic AI Models Could Backfire
- DeepSeek R1: The Revolutionary AI Disrupting the Tech Landscape
News Analysis · By Philip Hall · Published 22 July 2026
