IronSights
All insights

incident response

The Origin Energy breach: a countdown clock, and the two controls that decide how this goes

An attacker claiming two million Origin Energy customer records went straight to the media and started a 14-day countdown. What is claimed versus confirmed, why the attacker's playbook matters, and the two controls that decide how an incident like this unfolds: access and logging.

By IronSights Editorial, Practitioner team22 July 20265 min read
ByIronSights Editorial22 July 20265 min read

On 22 July 2026, Origin Energy told the ASX it was investigating a potential security incident involving unauthorised access to customer data. By the time the filing landed, the story was already in the press, because the attacker put it there. An individual writing under an alias emailed an extortion demand directly to 7NEWS, gave The Australian a sample of fifty customer records as proof, and started a public countdown: fourteen days for Origin to make contact, or the data gets released.

What is claimed, and what is confirmed

The two are far apart right now, and the gap matters. The attacker claims access to more than two million customer records: names, phone numbers, email addresses, dates of birth, account numbers, billing details, property IDs and addresses. Origin has confirmed much less: that it is investigating potential unauthorised access, that it does not believe credit card or bank details are involved, and that it has notified the , the Australian Federal Police and the . The company holds about 4.8 million customer accounts. Its shares fell close to three per cent on the news.

A sample of fifty real records proves some level of access. It does not prove two million. Attackers routinely inflate their claims because the headline number is part of the pressure, and working out what was genuinely reached is slow, careful work inside the victim's own systems. That verification gap is precisely where the next two weeks of this story will play out.

The playbook: skip the company, go to the media

Nothing here was encrypted, as far as anyone has reported. There is no in this story so far, just data and a demand, which makes the pressure entirely about publicity. The attacker says they contacted Origin's board, security team and customer care first, and went public because the company did not engage. Whether that account is true or convenient, the tactic is now standard: email a newsroom, hand over a verifiable sample, start a clock, and let the media cycle do the extortion work for you.

For any business, the operational lesson is uncomfortable: the first you hear of your own breach may be a journalist calling for comment, with your response clock already running in public. The window where you could quietly investigate before saying anything is closing across the whole industry.

Why the first questions are about access and logs

When a claim like this lands on a desk, two questions matter before any statement is written: is it real, and what exactly could they reach? Both are answered, or left unanswerable, by decisions made months or years earlier.

The first is access control. Whether one compromised credential or one flawed system can reach millions of customer records is an architecture decision. Least privilege on accounts and service identities, segmentation between customer databases and everything else, on anything internet-facing, and alerts on unusually large queries all shrink the blast radius before an attacker ever shows up. A breach still hurts when those controls are in place. It hurts within limits.

The second is logging. Without authentication logs, database audit trails and export records, a company facing an extortion claim cannot confirm it, refute it, or scope it. 'We are investigating' stretches from days into weeks when the logs are thin, and every one of those days is spent underneath a countdown clock. With good logs, the questions have answers: which account, what was queried, how many rows, on which dates. That evidence is the difference between notifying the people actually affected and having to treat every customer on the books as exposed.

The obligations arrive faster than the answers

Under the , a company in this position must assess the incident promptly, within 30 days at the outside, and notify the OAIC and affected individuals if serious harm is likely. As an energy provider, Origin also sits inside the critical infrastructure regime, with its own incident reporting duties to the . And if any extortion payment were ever made, the Cyber Security Act 2024 requires businesses over $3 million turnover to report the payment within 72 hours. The decision about paying, and everything that should be weighed before it, deserves to be thought through long before a countdown forces it.

What to take from this if you are not Origin

  • Know your blast radius today. Ask, specifically, whether one compromised account could reach your entire customer table. If nobody can answer, that is the answer.
  • Keep the logs that answer 'what did they touch': sign-ins, database and file access, exports and bulk downloads, retained for months rather than weeks, because attackers rarely act on day one.
  • Decide now who speaks if a journalist calls about a breach claim, and what the first hour looks like. Working it out live, in public, is how bad days become bad months.
  • Rehearse the extortion decision before you ever face one, including who you would call, what you would verify first, and where payment sits in the order of options.

Most Australian businesses will never be extorted on the evening news. The same attack at a smaller scale, a compromised account quietly reading a customer database, happens constantly, and the controls that decide the outcome are identical and unglamorous: who can access what, and whether you can prove it afterwards. If a claim like this landed on your desk tomorrow morning, you would want incident response on the phone and your logs already answering questions. One of those you can arrange today.

Keep reading

More from the IronSights team.