Origin Energy's 48-Hour Walk-Back

July 23, 2026 · 7 min read

Origin Energy's 48-Hour Walk-Back

TL;DR - On Wednesday Origin told the ASX they did not believe bank details were in the stolen data. By Thursday morning the CEO was confirming incomplete card and bank account information had been taken. The gap between those two statements is the lesson, not the breach itself. What you need to do: verify any inbound Origin contact against the number on your last bill, rotate any password you've reused, and warn the less technical people in your orbit.


Phishing awareness at home or at work? Most breaches end with a phishing wave, not a card fraud wave. The Origin one will too.

Get my Personal Security Quick-Start Guide - the practical handbook for spotting the email, SMS, or call that lands because it knows your name and your address. 193 pages, no jargon.

Plus: Join 158+ Australians getting one 5-minute security briefing every Friday.

Get The Free Guide →


The 24 hours that mattered

I read three headlines on Wednesday about the Origin Energy story, in the order most Australians would have read them.

The first one came mid-afternoon. Origin had told the ASX it was "urgently" investigating a possible cyber breach after a threat actor sent The Australian newspaper a sample of 50 customer records and claimed Origin was sitting on two million more. Origin's ASX statement said the words a lot of readers would have latched onto: "We do not believe the impacted data includes customer credit card or bank details."

The second one came Thursday morning. Origin's CEO Frank Calabria was on the record confirming something quieter and a lot more honest. Incomplete card and bank account information had, in fact, been taken. Last four digits of a credit card, or last three of a bank account, plus name, address, date of birth, phone, account information, and bill history.

The third headline is the one that should worry you: Origin still cannot confirm the 2 million figure.

Two statements, 24 hours apart, both technically true at the moment they were made. That's the part nobody puts in a headline.


Why the walk-back is the actual story

I've worked through enough breach disclosures to recognise the script. Day one, the company tells the market what its legal team has had time to confirm. Day two, the picture fills in, the wording softens, and the original statement starts to look like it was written for the lawyers rather than the customers.

That gap between Wednesday's "we do not believe" and Thursday's "incomplete" is exactly the gap to watch in any breach, not because the company is being dishonest, but because at 2pm on a Wednesday they probably genuinely did not know. By 9am Thursday they did.

Both statements can be true at the same time. That's the uncomfortable part of being on the receiving end of one of these.

What it tells you, as a customer or as the person advising one, is that any single breach statement is a snapshot, not the final picture. The useful habit is to assume the picture will keep filling in for at least a week, and act on the worst version you can justify in the meantime, not the most reassuring one.


What we know is in the data

Per Origin's own update, for affected customers the data set may include:

  • Name, address, date of birth, contact phone number
  • Account information and bill history with Origin
  • The last four digits of a credit card, or the last three digits of a bank account

Origin emphasised that incomplete card or bank information on its own cannot be used to make purchases or access accounts. That's true, and it's also a smaller comfort than it sounds.

The piece the security press keeps pointing at is the combination. Last four digits of a card, plus date of birth, plus address, plus bill history, plus a working phone number, is a kit. Not a kit for charging your card, a kit for sounding like Origin on the phone. Steve Hunter from Arctic Wolf put it the way I'd put it: any attacker with that bundle can build a convincing "Hi, it's Frank from Origin, we've detected an overdue bill on your account, can you confirm your card number" conversation that lands because every detail in it checks out.

The CVV on the back of the card is almost a distraction here. The product the thieves have is not a card to charge. It is a person to impersonate, believably, to whoever that person banks with, insures with, or bills through Origin.


What this means if you are an Origin customer

Three things, all under an hour, all doable this week:

  1. Treat any inbound Origin contact as hostile until you have verified it yourself. If you get a call, SMS, or email about an overdue bill, a refund, an account verification, or a password reset, hang up and call Origin back on the number printed on your last bill, not the number in the message. Origin has set up a dedicated contact line for affected customers and that is the only Origin number worth trusting for the next few weeks.

  2. Assume any password you have ever reused is on borrowed time. If your Origin portal password, or anything close to it, is the same as your email, your bank, or anything else important, rotate those this week. The threat actor doesn't have your Origin password from this breach. They have a lot of the personal context that gets used to phish one, and reusing credentials is what turns a partial breach into a takeover.

  3. Tell the less technical people in your household what is coming. The realistic follow-on wave is bill-themed phishing that lands because it knows your address, your provider, and roughly how much you pay. Parents, partners, the family member who still clicks the link, this is the one to warn them about, in those words.


What this means if you ever have to write a breach statement yourself

This is the corporate-comms-as-a-security-control angle that most IT-pro readers of this newsletter will care about more than the consumer checklist above.

A few rules I think most breach statements violate, and Origin's Wednesday statement violated all of them:

Don't deny the worst case in the first statement. "We do not believe bank details were taken" reads as confident. By Thursday it read as wrong. If you don't know, say so. "We are still determining whether card data was included" is a worse sentence legally and a better one operationally.

Don't anchor to the threat actor's claims. Origin still can't confirm the 2 million figure, which is correct, but the absence of confirmation got used as "could be smaller" in the press cycle. Anchor to what you have confirmed, not what they claim. "We have confirmed approximately X records; we are still determining the full scope" is harder to spin against you.

Commit to a re-statement timeline in the first statement. "We will provide a further update within 72 hours" is the kind of sentence that buys you time and credibility. Origin's Thursday update landed less than 24 hours after the first one, which was good. But the absence of an explicit timeline in the first statement meant the press cycle wrote its own.

None of this is exciting. But it works.


My Take

The Origin breach will get worse before it gets better, in the sense that the affected-customer count, the exact data set, and the attack vector will all surface over the next week or two. By the time you read this, more will be known.

The thing I keep thinking about is not the breach itself. It's the disclosure hygiene. Most Australian breach disclosures I've read in the last two years, Optus, Medibank, Latitude, the super funds, all of them had this same 48-hour walk-back pattern. Not because the companies are dishonest, but because they don't have a template that holds up under pressure.

That template is a solvable problem. It's a tabletop exercise, three or four approved statements, a 72-hour re-statement commitment, and a single named comms owner with the authority to publish. It costs almost nothing to set up before an incident and saves a lot of reputation afterwards.

If you run a security or IT function in Australia and you don't have this template on a shelf, this is the week to write it. The Origin story is the latest proof you need it.


Key Takeaways

  • Breach statements move. The first official statement is rarely the final picture. Treat it as a snapshot, not a verdict.
  • Incomplete card data is a phishing kit. Last four of PAN + DOB + bill history + working phone = believable impersonation, not a card to charge.
  • Verify inbound contact via the number on your last bill, not the number in the message. This week, for Origin, that is non-negotiable.
  • Rotate reused credentials this week. Not because Origin lost them, but because the personal context to phish them is now in circulation.
  • Build a breach-comms template before you need one. Three approved statements, a re-statement timeline, one named comms owner. Tabletop it.

Mathew Clark Founder, SecureInSeconds Currently: refreshing my own DNS records out of paranoia, because nothing in this industry stays simple for long.


Further Reading

Share:

You might also like