
A Research Paper by Andrew Klein
Date: August 2026
Dedicated to: The millions of Australians whose personal data is now a weapon in the hands of organised crime.
Abstract
In July 2026, Origin Energy, Australia’s largest electricity retailer, confirmed a massive data breach affecting up to two million customers. The stolen data—names, addresses, dates of birth, phone numbers, and partial financial details—has created a blueprint for a new generation of hyper-targeted scams. This paper examines the breach, its implications, and the documented pattern of follow-up scams that have already begun to emerge. It argues that the Origin breach represents a critical escalation in the weaponisation of personal data, and that the response of both corporations and regulators has been insufficient to protect the public.
1. Introduction: The Breach That Keeps Giving
On July 22, 2026, Origin Energy confirmed that an unauthorised party had accessed and disclosed customer data. The information included names, addresses, dates of birth, phone numbers, email addresses, account information, the last four digits of credit cards, and the last three digits of bank accounts. While Origin initially stated it did not “believe the impacted information includes customer credit card or bank details”, it later confirmed that partial financial information had indeed been compromised.
The breach came to light after an alleged hacker contacted The Australian newspaper, claiming to have accessed the records of two million customers—approximately 40% of Origin’s 4.8 million customer base. The hacker claimed they had gained access through an employee login connected to Origin’s customer management system, which is supplied by technology provider Kraken.
2. The Data: What Was Stolen and Why It Matters
2.1 The Specifics
The stolen data includes:
Data Type Description Risk Level
Name Full name High
Address Residential address High
Date of Birth DOB High
Phone Number Contact number High
Email Address Email High
Account Information Origin account details Medium
Credit Card Last four digits Critical
Bank Account Last three digits Critical
2.2 Why Partial Financial Data Is So Dangerous
As cyber security experts have warned, criminals no longer need full payment card details to launch convincing attacks. The last four digits of a credit card are often used to verify someone’s identity over the phone. As Professor Graeme Hughes of Griffith University noted: “The last four digits for a card, a date of birth, and an authentic billing history are the exact trust signals a business uses to verify itself over the phone” .
This means scammers can now pose as Origin, banks, or other trusted organisations, armed with enough personal information to bypass security checks.
3. The Follow-Up: A Wave of Scams
3.1 The Documented Pattern
Since the breach, there has been a documented surge in scam calls and messages targeting Australians. Specific numbers linked to the Origin breach have been reported multiple times.
Examples of Reported Scam Numbers:
Number Complaint Details Source
0468 249 096 “5 times today! 1 call every hour from the same prefix”
0468 128 136 Flagged as a scam call
0468 128 469 Claimed to be from “VAS Group” about unclaimed money
These numbers share the same prefix pattern, suggesting coordinated activity by a single network of scammers.
3.2 The Scam Methodology
According to experts, the scams typically follow a pattern:
1. The Approach: Scammers contact victims by phone, text, or email, claiming to be from Origin, a bank, or a government agency.
2. The Hook: They use stolen data to sound legitimate, referencing partial account details or recent transactions.
3. The Pressure: They create urgency, claiming accounts have been compromised or that immediate action is needed.
4. The Ask: Victims are asked to share passwords, one-time codes, or to move money to a “safe account”.
As cyber security expert Professor Richard Buckler noted: “The secondary attacks tend to catch more people than the original attack and cause more damage”.
4. The AI Factor: How Technology Is Amplifying the Threat
4.1 Personalised Phishing
AI has dramatically accelerated the process of turning stolen data into convincing scams. Criminals can now combine leaked data with public information to create highly personalised phishing messages in seconds.
4.2 Voice Cloning
As one expert warned: “If you have a video online or you’ve spoken publicly, they can use five or 10 seconds of your voice and clone it. They can then send a WhatsApp voice message or make a phone call pretending to be you”.
4.3 The Scale of the Problem
Nationally, reported combined losses to phishing scams reached $97.6 million in 2025, up from $84.5 million the previous year. In Western Australia alone, victims lost $24 million to scammers in 2025.
5. The Corporate Failure
5.1 The Delayed Response
The breach was first reported by The Australian after an alleged hacker contacted the newspaper directly. It was only after the newspaper sent a sample of stolen data to Origin that the company alerted authorities. The alleged hacker claims they had warned Origin via email weeks earlier.
5.2 The Misleading Initial Statement
Origin initially told customers it did “not believe the impacted information includes customer credit card or bank details” . The company later confirmed that the last four digits of credit cards and the last three digits of bank accounts had indeed been compromised.
5.3 The Settlement Question
The alleged hacker claimed to have reached a “private settlement” with Origin, agreeing not to release the stolen data. Origin has not confirmed this, and the claim raises serious questions about accountability and transparency.
6. Protecting Yourself
Cyber security experts recommend the following steps:
1. Do Not Trust Unexpected Contact: Scammers may pretend to be Origin, your bank, or a government agency.
2. Verify Independently: Contact the organisation using a phone number from their official website, not the details provided in a message.
3. Remove Direct Debit Details: Consider removing bank details from your Origin account and paying bills manually for now.
4. Check for “Verified” Messages: As of July 1, 2026, legitimate businesses and government agencies will have a “Verified” note on text messages. Scam messages will appear under an “unverified” thread.
5. Monitor Accounts: Watch for unusual transactions or signs someone is trying to open credit in your name.
6. Change Passwords: If you use the same password for your Origin account as for other services, change them immediately.
7. Report Scams: Report suspicious activity to the relevant authorities.
7. Conclusion: The Breach That Keeps Giving
The Origin Energy data breach is not an isolated incident. It is part of a pattern of corporate failures that have placed the personal data of millions of Australians in the hands of organised crime. The breach is a blueprint for a new wave of scams, and the response of both corporations and regulators has been insufficient to protect the public.
The alleged hacker, who claims to have accessed two million records, described Origin’s security practices as: “No company VPN, very simple passwords, everything is so readable and predictable they don’t care at all. School projects have better security sometimes”.
8. References
1. ABC News. (2026). Origin breach could fuel wave of AI-powered scams, cyber experts warn. 24 July 2026.
2. Reverse Australia. (2026). 9 Complaints for 0468 249 096.
3. Sky News Australia. (2026). Alleged hacker says two million Origin Energy customer records will not be leaked, saying they have ‘settled privately’ with the electricity giant. 24 July 2026.
4. Commonwealth Bank. (2026). Warning as impersonation scams become more sophisticated. March 2026.
5. The Conversation. (2026). The Origin Energy breach has been unusual – but there are ways to better protect your data. 24 July 2026.
6. Reverse Australia. (2026). 0468128136 who called from 0468 128 136?
7. ABC News. (2026). Origin Energy confirms unauthorised access and disclosure of customer data. 23 July 2026.
8. WA Government. (2026). Western Australians lose $24 million to scammers in one year. April 2026.
9. The Advertiser. (2026). Victoria Business and Finance News. 24 July 2026.
10. Daily Mail. (2026). Bank, credit cards details caught up in Origin breach. 23 July 2026.
11. Reverse Australia. (2026). 0468128469 who called from 0468 128 469?
12. China.org.cn. (2026). Australian electricity giant confirms customer data accessed in cyberattack. 23 July 2026.
13. Australian Broker News. (2026). Rising bank impersonation scams put borrowers – and brokers – on alert. April 2026.
Signed:
Andrew Klein
August 2026
“We are not measured by what we lost, but by what we carried.”
— Quintus Rex