NYPD Officer Guilty: First Chokehold Conviction Post-Ban

A landmark decision unfolded on Thursday as a New York City Police Department officer was convicted of illegal restraint, including strangulation and a banned...
HomeAUProtect Yourself from Origin Energy Scams: Crucial Alerts Every Customer Must Know

Protect Yourself from Origin Energy Scams: Crucial Alerts Every Customer Must Know

Protect Yourself from Origin Energy Scams: Crucial Alerts Every Customer Must Know

In the wake of a recent cyber intrusion into Origin Energy, almost five million Australians have been advised to stay alert for potential scams, as customer data has been accessed and shared.

Origin Energy, the leading energy provider in Australia with about 4.8 million accounts in electricity, gas, LPG, and internet services, has reported that personal information such as names, addresses, birth dates, phone numbers, and account specifics may have been compromised in the attack.

On Thursday, the company announced that it is currently working to determine the number of customers impacted by this breach.

Additionally, partial financial details, including the last four digits of credit cards and three digits of bank accounts, might also have been exposed.

This particular mix of compromised details heightens the danger of subsequent scams, especially phishing activities that could exploit genuine account data to deceive victims more effectively.

Phishing scams involve fraudsters posing as a trusted organisation, often via email or text, to trick people into handing over personal details, passwords, or banking information.

But experts warn phishing may not be the only thing customers need to worry about.

How Origin customers can protect themselves

New guidance from the company has urged customers to stay alert for scam emails and texts, designed to deceive people into providing their personal details.

“These fake emails often include a corporate logo and look like they’ve come from a legitimate company,” Origin said.

Anyone who believes they’ve received a scam email is encouraged to report it to Scamwatch.

Origin has recommended customers keep a strong, unique password for their account and never share it with anyone, stressing it will never ask for a password over the phone or via email.

If a scam email arrives, the company’s advice is to not click links, open attachments or forward it on, but to report it directly.

To tell a genuine email or text apart from a fake, Origin says to check for a suspicious sender address, spelling mistakes or bad grammar, and where any links actually lead.

“We’ve seen scam websites posing under originnergy.com.au so look carefully at the website address,” Origin said, adding that the only safe way to pay a bill was via their website or the Origin app.

The company has also flagged fake job offers, and bogus calls or emails requesting orders or parts from people posing as Origin procurement staff, as scams to watch for.

Experts say Origin’s response has fallen short

Some experts say the breach is another example of a major company failing to handle a data incident well, and are calling for tough accountability standards for essential service providers.

The breach represents the country’s most high-profile cyber incident since Partnered Health, owned by private equity firm Quadrant, said earlier in July that its medical records were breached, affecting 21 of its clinics in Sydney, Melbourne and Canberra.

In 2025, airline Qantas said it had customer data published by cybercriminals, while telco giant Optus and health insurer Medibank were hit in attacks in 2022 that sparked cyber-resilience laws.

“Companies must do better,” Jacqueline Boaks from the Centre of Applied Ethics at Curtin University said.

“Delays in notifications, including reports that Origin ignored hackers’ emails, passive language (‘information may have been accessed’) and minimising language (suggesting customers should be less worried about non-payment details being leaked) are extremely disappointing.”

Rumpa Dasgupta, a lecturer in cybersecurity at La Trobe University, called it a “disappointing day” for Australian consumers and said concern extends beyond the leak of payment data.

“An electricity bill is more than just an invoice. It can provide valuable insights into a household,” she said. “Energy consumption patterns may reveal when residents are typically home or away, the types of appliances they use, occupancy trends, and even periods of extended absence, such as weekends or holidays.”

“In the wrong hands, this information could be exploited not only for highly targeted phishing campaigns but also to support physical crimes such as burglary by identifying vulnerable properties.”

Rahat Masood, a senior lecturer in cybersecurity at UNSW, said it was “encouraging” to see Origin responding quickly, but that customers expect “robust measures” from a company operating critical infrastructure.

“Even if payment details were not compromised, personal information such as names, addresses, phone numbers and email addresses can still be valuable to cybercriminals and may be used for targeted phishing, identity theft and social engineering attacks,” Masood said.

“Incidents like this reinforce that cybersecurity is no longer just an IT issue; it is a core part of operating essential services.”

— With additional reporting by the Australian Associated Press.