IronSights
All insights

threat intelligence

The energy sector is a data business now, and attackers have noticed

Two Australian energy companies were hit in 2026 for the same reason a bank is: the data. The grid stayed on, but customer and commercial records were the prize. What the Origin and Energy Action incidents say about a sector that holds far more than electrons.

By IronSights Editorial, Practitioner team27 July 20264 min read
ByIronSights Editorial27 July 20264 min read

When people worry about attacks on the energy sector, they picture the lights going out. That is the cinematic fear, and it is a real one for the operators who run generation and the grid. But the two Australian energy incidents that drew attention in 2026 had nothing to do with turning anything off. They were about data. The attackers were not after the power. They were after the records, and the energy sector holds a great deal of them.

Two incidents, one motive

In July 2026, Origin Energy disclosed to the ASX that it was investigating potential unauthorised access to customer data, after an individual approached the media directly, provided a sample of records as proof, and started a public countdown demanding contact. Origin holds around 4.8 million customer accounts. Earlier in the year, in May, the group SafePay listed the energy management consultancy Energy Action on its leak site, claiming roughly 470 gigabytes of stolen data. Energy Action says it manages more than ten per cent of Australia's commercial energy spend, which means it holds contract, usage and account information for a large slice of corporate Australia.

In neither case was the story about generation or the grid. In both, the value was the data: personal details in one, commercial and contractual information in the other. That is the pattern worth noticing. An energy retailer is a customer-data business that happens to sell electricity. An energy consultancy is a data broker that happens to advise on procurement.

Why energy firms are quietly data-rich

A retailer like Origin holds what any large consumer business holds: names, addresses, dates of birth, contact details and billing histories for millions of households. That is a and identity-fraud dataset of national scale, valuable regardless of the industry attached to it. A consultancy like Energy Action holds something subtler and arguably more sensitive: the energy contracts, consumption profiles and commercial terms of its business clients. That information reveals how other companies operate, what they spend and when their agreements come up for renewal, which is useful both to fraudsters and to anyone interested in a competitor's position.

The Energy Action case carries a second lesson that applies well beyond energy. A firm that aggregates data on behalf of many clients becomes a single target whose compromise reaches all of them. The clients did the sensible thing by outsourcing a specialised function, and inherited a shared point of failure they may never have assessed. Supply-chain risk is not only about software vendors. It is about anyone who holds your data because you asked them to.

The obligations are heavier here

Energy sits inside Australia's critical infrastructure regime. Under the Security of Critical Infrastructure Act, responsible entities in the sector carry specific duties, including reporting significant cyber incidents to the within defined timeframes, on top of the Notifiable Data Breaches obligations that apply to the involved. For an energy business, an incident is not only a commercial and reputational event. It is a regulated one, with reporting clocks that start early and run in parallel.

What other data-rich businesses should take from it

  • Know what you actually hold. Many organisations underestimate the sensitivity of their own records until an attacker itemises them in public. Map the data that would hurt most if exposed, and protect that first.
  • If you aggregate data for clients, you are a bigger target than your size suggests. Assume you will be probed as the soft route into organisations larger than you, and defend accordingly.
  • If you rely on a firm that holds your data, assess them. Ask what controls they run, how they would tell you about an incident, and what your exposure is if they are breached. Their weakness becomes yours.
  • Know your reporting duties before you need them. Critical infrastructure entities and any business holding personal data face timeframes that begin the moment an incident is suspected, not the moment it is understood.

The comforting version of energy-sector risk is the one where the danger is a blackout, because a blackout is someone else's problem: the operators, the regulators, the grid. The 2026 incidents point somewhere less comforting and more common. The valuable thing an energy company holds is often the same valuable thing a bank or a retailer holds, which is information about people and businesses, and it is exposed to exactly the same attackers. The grid stayed up. The data did not, and for most organisations the data is where the real risk has been sitting all along.

Keep reading

More from the IronSights team.