On 22 July 2026, Origin Energy Limited — one of Australia’s largest electricity and gas retailers — launched an investigation into a cybersecurity incident involving access to customer information. The trigger was a threat actor’s claim to have obtained records on two million individuals, coupled with a threat to leak the lot unless a ransom was paid.

By 28 July, Origin had confirmed a materially different number: approximately 900,000 current and former customers affected. The data involved includes names, dates of birth, phone numbers, addresses, account information, and partial payment card or bank account numbers.

Origin engaged the Australian Cyber Security Centre (ACSC), the Australian Federal Police, and independent specialists.

Six days from claim to confirmed figure, with a 55% reduction against the attacker’s number. That sequence is the whole compliance story, and it runs directly into the specific mechanics of Australia’s Notifiable Data Breaches scheme.

The NDB scheme’s 30-day assessment window

Part IIIC of the Privacy Act 1988 (Cth) establishes the Notifiable Data Breaches (NDB) scheme. Its structure is different from GDPR’s and the difference matters here.

Section 26WH — the suspicion trigger. Where an entity is aware that there are reasonable grounds to suspect that there may have been an eligible data breach, but does not have reasonable grounds to believe one has occurred, it must carry out a reasonable and expeditious assessment of whether there are reasonable grounds to believe the incident is an eligible data breach — and take all reasonable steps to complete that assessment within 30 days.

Section 26WK — the notification obligation. Where the entity has reasonable grounds to believe an eligible data breach has occurred, it must prepare a statement and give a copy to the Commissioner as soon as practicable, and notify affected individuals.

An eligible data breach under s 26WE requires both unauthorised access, disclosure, or loss of personal information and a likelihood of serious harm to any of the individuals to whom the information relates.

Applied to Origin: the attacker’s claim on or around 22 July established reasonable grounds to suspect, starting the 30-day assessment clock. The confirmation on 28 July — six days in — represents the entity reaching reasonable grounds to believe, which switches the obligation from assessment to notification “as soon as practicable.”

Six days is fast for a population of this size. The temptation for other entities to read that as the standard should be resisted; what it actually demonstrates is that Origin had the logging and data-mapping capability to answer the question quickly. Most entities do not, and their honest position is a longer assessment inside the 30-day cap.

Do not notify on the attacker’s number

The Origin sequence illustrates a discipline that is easy to state and hard to hold under media pressure.

Threat actors routinely inflate. The reasons are commercial: a larger claimed set increases perceived leverage in negotiation and increases the sale price if negotiation fails. Inflation is achieved through predictable methods — counting rows rather than unique individuals, including test and staging records, including records from unrelated prior breaches, and counting every table in an exfiltrated database dump as if each represented distinct people.

The deduplication that took Origin from a claimed two million to a confirmed 900,000 is the same arithmetic that operates in most of these incidents — and it operates in the other direction too, as the DentaQuest scope expansion from 2.6 million to over 23 million demonstrates. The point is not that attackers always exaggerate. It is that the attacker’s number is evidence, not a finding, and an entity that notifies on it has outsourced its regulatory determination to an extortionist.

The corresponding obligations:

  • Notify on your own verified analysis, with the methodology documented.
  • Say publicly what you have verified and what remains under assessment, with a date for the update.
  • Do not under-notify to manage the headline. The OAIC’s guidance and enforcement practice treat under-notification as a distinct and more serious failure than a revised-upward figure.
  • Preserve the evidence base for the deduplication, because if the figure is later challenged you will need to show the work.

The penalty exposure is no longer theoretical

Australian entities that still treat the Privacy Act as a low-consequence regime are working from an out-of-date model.

The Privacy Legislation Amendment (Enforcing Privacy and Other Measures) Act 2022 raised the maximum penalty for serious or repeated interferences with privacy under s 13G to the greater of:

  • AU$50 million;
  • three times the value of any benefit obtained through the misuse of information; or
  • 30% of the entity’s adjusted turnover for the relevant period.

That is GDPR-scale, and the OAIC has demonstrated willingness to use it. On 8 August 2025 the Australian Information Commissioner commenced civil penalty proceedings in the Federal Court against Singtel Optus Pty Limited and Optus Systems Pty Limited over the September 2022 breach. The allegation is that from around 17 October 2019 to 20 September 2022, Optus seriously interfered with the privacy of approximately 9.5 million Australians by failing to take reasonable steps under Australian Privacy Principle 11 to protect personal information from misuse, interference, loss, and unauthorised access.

The Commissioner has indicated it will pursue a contravention per affected individual, which under the pre-amendment penalty of AU$2.22 million per serious interference produces a theoretical maximum in the trillions. No court will award that. But the pleading establishes the structural point that matters for every Australian entity: the Commissioner’s position is that a systemic security failure can be characterised as many contraventions, not one.

Origin’s exposure will turn on the same question the Optus proceeding turns on: not whether it was breached, but whether it took reasonable steps under APP 11 to protect the information, having regard to the sensitivity of the data, the risk of harm, the entity’s size and resources, and the practicability and cost of the available measures.

Our guide to the Australian Privacy Principles covers the APP framework in detail.

The reforms that raise the stakes further

Two developments make the Australian environment materially harsher than it was during the 2022 Optus and Medibank incidents.

The statutory tort for serious invasions of privacy, introduced by the Privacy and Other Legislation Amendment Act 2024, commenced in June 2025. It creates a direct cause of action for individuals — separate from any OAIC proceeding — for serious invasions of privacy, including by misuse of information, where the invasion was intentional or reckless. Damages are available, including for emotional distress, capped at the greater of AU$478,550 or the cap applicable to non-economic loss in defamation.

The practical effect is that a large Australian breach now carries class action risk on top of regulatory risk, and the plaintiff firms are organised. The recklessness threshold is the live question in security-failure cases: an entity that was on notice of a control deficiency and did not remediate it faces an arguable case.

Recurring-data and retention scrutiny. The Origin data set includes former customers. The presence of former-customer records in a breached environment invites the question the OAIC asks in every major matter: why was this data still held? APP 11.2 requires an entity to take reasonable steps to destroy or de-identify personal information it no longer needs for any purpose for which it may be used or disclosed under the APPs, subject to other legal retention obligations.

In the energy retail context there are genuine retention drivers — the National Energy Retail Rules, tax record-keeping, and dispute-resolution requirements — but they are finite and specific. “We keep everything” is not a retention policy, and an entity that cannot articulate the legal basis for each retention period will find the OAIC treating the excess data as an unnecessary contribution to the harm.

The critical infrastructure overlay

Origin Energy is a responsible entity for critical infrastructure assets under the Security of Critical Infrastructure Act 2018 (SOCI Act), which applies to the electricity and gas sectors.

This produces a second, faster reporting obligation running in parallel with the NDB scheme. Under Part 2B, responsible entities must report cyber security incidents to the ACSC:

  • 12 hours for a critical cyber security incident that has had, or is having, a significant impact on the availability of the asset;
  • 72 hours for other cyber security incidents that have had, are having, or are likely to have a relevant impact.

The two regimes measure different things. SOCI is oriented to availability and operational impact on the asset. The NDB scheme is oriented to harm to individuals from personal information exposure. A customer-data breach with no operational impact triggers the 72-hour SOCI obligation and the NDB assessment obligation, and neither satisfies the other.

Australia also introduced the Cyber Security Act 2024, which imposes a mandatory ransomware payment reporting obligation on entities above a turnover threshold — payments must be reported within 72 hours. Origin’s engagement of the AFP and ACSC and its apparent non-payment posture keeps it clear of that obligation, but any Australian entity that pays now has a filing to make. See our coverage of Australia’s standalone cybersecurity law.

Entities operating in both regimes need a single incident-classification step that evaluates all clocks simultaneously — SOCI 12 hours, SOCI 72 hours, ransomware payment 72 hours, NDB assessment 30 days, NDB notification as soon as practicable — because sequencing them serially guarantees a miss on the shortest one.

What the exposed fields mean for harm assessment

The serious harm test under s 26WE(2) requires an assessment against listed factors, including the kind and sensitivity of the information, whether it is protected by security measures, the persons who have obtained or could obtain it, and the nature of the harm.

Origin’s set — name, date of birth, phone number, address, account information, partial card or bank account numbers — is a classic identity-fraud and social-engineering package:

  • Name plus date of birth plus address is the core of Australia’s 100-point identity verification framework and supports account takeover across financial and telecommunications providers.
  • Partial card and bank account numbers do not enable direct transactions, but they are extremely effective in verification-based social engineering: an attacker who can recite the last four digits of a victim’s account establishes credibility immediately.
  • Energy account information plus contact details enables highly targeted fraud, particularly billing and rebate scams, in a period of acute consumer sensitivity to energy costs.

The predictable second wave is impersonation of Origin itself, contacting affected customers about the breach. Entities in this position should tell customers, prominently and early, exactly what channels they will and will not use — and then hold to it.

Actions for Australian entities

  1. Start the 30-day assessment clock at suspicion, and record the date. The clock does not begin when you finish the forensics.
  2. Never notify on the attacker’s figure. Deduplicate to unique individuals, document the methodology, and preserve the evidence.
  3. Run SOCI and NDB classification in one step, at first triage, against all applicable clocks.
  4. Audit retention against a documented legal basis per data category. Former-customer records in a breached environment are the OAIC’s first question.
  5. Assess your s 13G exposure as a per-individual count, not a single contravention. That is the Commissioner’s pleaded position in the Optus proceeding.
  6. Assume class action follows regulatory action. The statutory tort makes the recklessness question — were you on notice of the deficiency? — the central factual issue. Your risk register is discoverable.
  7. Publish the channel policy for breach communications before the impersonation wave starts.

Conclusion

Origin Energy did the difficult thing correctly: it refused to accept an extortionist’s arithmetic as its regulatory determination, and it produced a verified number in six days. That is a good outcome and a legitimately hard one to achieve.

What follows is harder. The OAIC’s Optus proceeding has established that a systemic APP 11 failure will be pleaded as millions of contraventions, the statutory tort has opened a parallel private route with a recklessness threshold, and the penalty ceiling now reaches 30% of adjusted turnover. Australian entities that have not revisited their security posture since 2022 are operating under a materially different risk model than the one they built for.

The question the regulator will ask is not how quickly Origin counted. It is what reasonable steps were in place before 22 July, and whether the 900,000 records — including those of former customers — needed to be there at all.

This article is provided for informational purposes only and does not constitute legal advice.