GoFirm
Back to Blog
Case Studies·4 min read

Origin Energy fired an employee. Nobody switched off the login.

By GoFirm

On 22 July 2026, Origin Energy Limited, one of Australia's largest energy retailers with approximately 4.8 million electricity, gas, LPG and broadband customers, announced it was investigating a potential security incident involving unauthorised access to customer data. A day later the company confirmed the breach outright: names, addresses, dates of birth, phone numbers, account information, and partial credit card and bank account numbers had been accessed and disclosed without authorisation. The access point was not a firewall or a phishing email. It was a login that should have stopped working the day its owner left.

According to reporting in The Australian, the credentials used to reach Origin's customer systems belonged to a former employee who had been dismissed from the company. Those credentials remained active on Kraken, the third-party customer management platform Origin uses to run billing and account services for its retail customer base, and in which Origin holds an equity stake after investing approximately AU$210 million in the company in 2025. Whoever held the login used it to move through Origin's customer tools for roughly three weeks before the activity was detected, reportedly extracting records covering millions of accounts.

A hacker identifying as "John Doe" contacted Origin's board members, security teams and customer care staff on 2 July, reportedly receiving no response for nearly three weeks before approaching Australian media outlets 7News and The Australian. The individual claimed the data of two million customers had been taken and threatened to publish it within fourteen days unless Origin negotiated a resolution over Signal. On 24 July, an individual using the alias "Edison Walthour" told The Australian that a private settlement had already been reached and that no data would be leaked. Origin has declined to comment on that claim, pointing only to its 23 July statement to the ASX.

The financial and regulatory exposure is still unfolding. Origin has not confirmed how many of its 4.8 million customers are affected, whether any payment was made to the attacker, or how the former employee's credentials survived their departure. Under Australia's Cyber Security Act 2024, any extortion payment, including one routed through an insurer or incident response firm, must be reported to the Australian Signals Directorate within 72 hours, a clock that starts regardless of whether the payment is ever disclosed publicly. The Kraken platform Origin shares with Ergon Energy Retail, Nectr and Essential Energy means the same offboarding failure could recur at any licensee running on the same infrastructure, a concentration risk the Australian Prudential Regulation Authority flagged in its November 2025 System Risk Outlook.

The defences that failed here were not weak by conventional standards. Origin is an ASX-listed company with roughly AU$8 billion in half-year revenue that reports to the Australian Cyber Security Centre, the Australian Federal Police and the Office of the Australian Information Commissioner, and its access to Kraken sat behind whatever authentication the platform required. None of that mattered once the underlying account was never switched off. Offboarding is treated as a checklist item in most organisations, not as an execution event. Nobody stood between a dismissed employee's still-live credentials and three weeks of unsupervised access to customer records, because nothing was built to confirm who was actually behind that login in real time.

GoFirm closes that gap by making every high-impact data access an execution event, not a standing permission. Before a login tied to a customer records platform can pull data at scale, whether that login belongs to a current employee, a departed one, or an external party who has obtained the password, a confirmation request goes to the named authority responsible for that access, sent to their registered device over a separate channel. If the person behind the login cannot produce a live biometric confirmation from the account's rightful owner, the export is blocked before it starts, regardless of how valid the underlying credential appears on paper.

That would have mattered specifically at the three-week mark, and at every point before it. A departed employee's account that nobody remembered to revoke does not stop being dangerous just because it is still technically valid. Each attempt to pull customer records through it is a separate execution event, and each one would have triggered a real-time confirmation request to the employee still authorised for that access, or to Origin's own named security authority once that employee had left. A stale credential, however long it survives an offboarding process, cannot produce a confirmation on someone else's registered device. The execution boundary holds regardless of how old or how valid the login appears.

GoFirm is The Authority Platform. Stop unauthorised action. Every time.

In association with Osinto.ai, the collective intelligence platform for Security, Resilience & Defence.
Osinto's AI-enabled open-source network and governed collaborative operational environment help mitigate the growing security, resilience and governance obligation in seconds, not days.

1. Toulas, B. 2026. Australian energy provider Origin says data breach exposes client data. BleepingComputer, 23 July 2026.
2. Kovacs, E. 2026. Data Breach Confirmed After Australian Energy Giant Origin Is Hacked. SecurityWeek, 24 July 2026.
3. Libatique, R. 2026. Origin silent on settlement as alleged fired employee breach detail emerges. Insurance Business Australia, 24 July 2026.
4. Paganini, P. 2026. Australian energy provider Origin Energy disclosed a data breach impacting customer data. Security Affairs, 25 July 2026.
5. Schulze, H. 2026. Origin Energy Sector Data Breach Widens to 5 Million Customers. Cybersecurity Insiders, 24 July 2026.

Share this article