Origin Energy's Data Breach Is a Window Into Australia's Worsening Cyber Problem
Nine hundred thousand customers had their details exposed. Two university professors say the breach is neither surprising nor isolated, and that ordinary Australians are bearing the hidden costs.

Key points
- Origin Energy told 900,000 current and former customers in 2025 that their personal and financial details had been exposed in a data breach.
- The Office of the Australian Information Commissioner received 1,205 data breach notifications in the 2025 calendar year, an 8 per cent rise on 2024.
- Cyber hacking is the single biggest cause of notified breaches in Australia, with health providers making up 19 per cent of victims.
- The average self-reported cost of a cyber incident rose 14 per cent for small businesses and 55 per cent for medium businesses in the last financial year.
- Experts warn AI-powered impersonation scams are making standard security habits less reliable on their own.
Origin Energy told 900,000 current and former customers this year that their personal and financial information had been exposed. The announcement made headlines, and rightly so. But the two cybersecurity researchers ABC News Australia spoke to for its original coverage were less shocked than most people would expect.
"It will get worse," said Mihai Lazarescu, an associate professor in AI and cybersecurity at Curtin University who has worked in the field for more than 16 years. "Ninety-nine per cent of people have no understanding of how difficult it is to protect data."
Is the Origin breach actually that bad?
By raw customer numbers, no. Canva, Optus, and Qantas have all suffered breaches touching millions of Australians. But Yeslam Al-Saggaf, a computing professor at Charles Sturt University, argues that counting heads misses the point.
"The value of data is low as these students don't have credit cards, don't have car loans, mortgages, and don't have driver's licences," he said, comparing the Canva breach to Origin's. With Origin, the exposed records included financial details of individuals and businesses. That opens the door to payment redirection attacks, where criminals trick someone into sending money to a fraudulent account, and to identity theft, where a criminal uses stolen personal details to impersonate you.
Professor Al-Saggaf warned that affected businesses and individuals could also face rising insurance premiums, since insurers covering cyber incidents have been responding to the surge in attacks by increasing what they charge. The Australian Signals Directorate's Australian Cyber Security Centre logged 1,200 cybersecurity incidents in the last financial year, up 11 per cent.
| Breach | Customers affected | Data exposed |
|---|---|---|
| Canva | Millions | Email addresses, names, hashed passwords |
| Optus | Millions | Identity and contact details |
| Qantas | Millions | Contact and booking details |
| Origin Energy | 900,000 | Contact and financial details |
What should ordinary people actually do?
Both researchers offered practical steps, not panic.
Professor Al-Saggaf recommends a strong, unique password for every account, ideally managed through a password manager app that remembers them for you. He also recommends enabling multi-factor authentication, which means requiring a second check such as a code sent to your phone whenever you log in, so a stolen password alone is not enough.
Associate Professor Lazarescu adds that limiting what you post publicly on social media matters more than most people realise. Photos tagged with specific locations and timestamps give organised criminal groups free intelligence. "These are not beginners," he said. "I've seen groups that were based in Europe where there were 11-year-olds coding."
Both experts flagged that AI tools are now helping criminals fake voices, faces, and messages far more convincingly than before. Professor Al-Saggaf's advice: if a close contact suddenly asks you to transfer money, verify through a second, separate channel before acting.
For anyone caught up in the Origin breach specifically, watching bank and credit card statements closely in the coming months is the most practical first step. Contact your bank promptly if anything looks unfamiliar.
Common questions
How do I know if my data was in the Origin breach?
Origin Energy contacted affected customers directly. If you received an email or letter from Origin about the breach, your information was exposed; if you are unsure, contact Origin's customer support line.
Can I just ignore breach notifications?
No. Acting quickly matters because criminals often try to use stolen data within weeks of a breach. Change passwords for any accounts that share details with Origin, enable multi-factor authentication where possible, and watch your bank statements.
What is multi-factor authentication and why does it help?
Multi-factor authentication means you need two pieces of proof to log into an account, typically your password plus a one-time code sent to your phone. Even if criminals have your password, they cannot get in without that second code.


