Origin Energy data leak cybersecurity lessons have experts worried | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


Three weeks ago, Origin Energy told 900,000 former and current customers that their information had been exposed in a data breach.

The major cybersecurity data leak made headlines and raised the alarm that the threats were becoming more prevalent.

It also showed that anyone with their information online could be vulnerable, according to Curtin University Associate Professor in AI and Cybersecurity, Mihai Lazarescu.

“There is no such thing as 100 per cent security,”

he said.

Associate Professor Lazarescu, who has worked in cybersecurity for over 16 years, said whenever anyone put information online, there was a chance it could be compromised. 

That included commonly used details, such as email addresses and first and last names.

“Never give your full name and date of birth because that is identifiable evidence,” he said.

How did Origin Energy compare to Australia’s biggest data breaches?

Origin’s breach affected hundreds of thousands of customers, but it wasn’t technically the largest. 

Australian companies such as Canva, Optus, and Qantas had data breaches that affected millions of customers. 

What does the Origin breach reveal about cybersecurity?

Associate Professor Lazarescu said the fact that a power company was potentially breached should have been expected, given how easy data could be accessed online.

“It will get worse,” he said.

“99 per cent of people have no understanding of how difficult it is to protect data.

“It requires both the technical and administrative aspects of security to be perfect.”

He said the only way to be fully protected online was to be “checking all the time”, from bank statements to which information was given online.

Recent data from the Office of the Australian Information Commissioner (OAIC) showed most of the leaked customer information in data breaches included contact details, financial details and identity information.

Associate Professor Lazarescu said social media was also one of the easiest ways for criminals to access data.

“You see people posting online with photos with specific locations, timing. These are not secure,” he said.

“When you have criminal groups that are very well organised and make a lot of money out of what they do, these are not beginners. 

“I’ve seen groups that were based in Europe where there were 11-year-olds coding.“

Associate Professor Lazarescu said having data leaked could not only put people at risk of being hacked but, in worst-case scenarios, their data could be sold on the dark web to criminal groups. 

“It could create a situation that’s expensive and complicated to fix,” he said.

He said serious discussion should be taking place that outlined to customers what the risks of data leaking could entail and the potential consequences if security measures failed.

Hidden costs of data leaks 

The severity of a data breach depends on the sensitivity of the data and the nature of the exposure, rather than just the total number of people affected.

Charles Sturt University computing professor Yeslam Al-Saggaf said the Origin data breach was “more concerning” than the Canva breach, despite fewer customers being affected.

“The value of data is low as these students don’t have credit cards, don’t have car loans, mortgages, and don’t have driver’s licences,” Professor Al-Saggaf said.

“Whereas in the Origin data breach financial details of individuals and businesses have been compromised.”

He said when individuals’ and businesses’ financial details were published online, it exposed them to a range of risks, such as losing money through payment redirection attacks and identity theft. 

He said businesses and individuals could also face a situation with additional costs and an increase in insurance premiums.

Cyber insurance providers have noted the increase in cyber attacks and, in turn, are raising premiums.

  • According to a 2025 report by the Australian Signals Directorate’s Australian Cyber Security Centre, the Australian Cyber Security Centre responded to 1,200 cybersecurity incidents in the last financial year, an 11 per cent increase.
  • The average self-reported cost of a cyber incident for a small business had risen to 14 per cent, while medium businesses have seen a 55 per cent increase.

Cyber-hacking number one cause of data breaches

The Office of the Australian Information Commissioner (OAIC) received 1,205 data breach notifications in the 2025 calendar year, representing an 8 per cent increase from 2024, according to OAIC data. 

Cyber hacking remains the primary cause of data breaches reported to the OAIC. 

Of the data breaches notified in 2025, the majority were attributable to malicious or criminal activity. 

Health service providers were the most commonly affected, accounting for 19 per cent of the total. 

How can we protect our data from being leaked?

The Australian government said it had revised its cybersecurity policies to strengthen resilience against nation-state threat actors amid the rise in cyber attacks.

In 2025, the OAIC launched a new Notifiable Data Breaches (NDB) statistics dashboard to keep the public informed on the volume and type of data breaches occurring.

Professor Al-Saggaf said “people are becoming numb to the drama of data breaches”, and people who remained naive to cybersecurity were most at risk.

“They happen every day in Australia because Australians are trusting, affluent, speak English, and some are not technically savvy,” he said.

“We need to improve our literacy with respect to cybersecurity hygiene practices.” 

He advised using a strong, unique password that differed for each account, or using a password manager, to help protect individuals.

He said enabling multi-factor authentication could provide an additional layer of verification, and using secure payment methods on secure websites could also help avoid potential security risks. 

But as scammers started to integrate artificial intelligence into their operations, he warned regular security measures would need to be strengthened. 

“AI is going to make impersonation more sophisticated, so use more than one method to communicate with your close contacts if they ask for financial assistance, and keep an eye on bank balances and credit card statements,” he said.

——————————————————-


Click Here For The Original Source.

National Cyber Security

FREE
VIEW