Guides · Security & privacy

900,000 records, one login nobody switched off

Origin Energy confirmed on 28 July 2026 that around 900,000 current and former customers had their data accessed. As the investigation has gone on, reporting has pointed to a strikingly ordinary cause: a former employee's login into a customer platform that was never deactivated after they left. No sophisticated hack — just an old account nobody remembered to remove. That exact failure is one of the most common, and most preventable, ways a small-business website gets breached too.

Origin Energy is a top-tier Australian energy retailer with a dedicated security team, so the size of this breach naturally makes headlines. But the detail worth sitting with isn't the scale — it's the reported mechanism. Multiple outlets, citing sources close to the investigation, report that a former Origin employee's login credentials remained active on a third-party customer-management platform well after they'd left the business, and that this account was the way in. Origin has not publicly confirmed the cause and the Australian Federal Police, the Australian Cyber Security Centre (ACSC) and the OAIC are all still involved, so treat the "how" as reported rather than settled. What is confirmed is the scale: about 900,000 current and former customers had data accessed, including names, addresses, dates of birth, phone numbers, account details, and partial credit-card or bank-account digits.

900,000
Customers affected
Confirmed by Origin on 28 July 2026, after the incident was identified in late July.
30 days
Max time to assess a suspected breach
Under the Privacy Act's Notifiable Data Breaches scheme — a ceiling, not a target.
1
Login, reportedly
The reported cause: one ex-employee's account, on a vendor platform, never switched off.
The lesson isn't "you'll be fined like a national energy retailer." It's that the same gap — an old login nobody remembered to remove — sits in plenty of small-business websites right now.

The rule that applies to your business too

It's tempting to read a story this size as someone else's problem. It isn't. Australia's Notifiable Data Breaches (NDB) scheme, run by the Office of the Australian Information Commissioner (OAIC), applies to any organisation the Privacy Act covers — and the same duty Origin is working through applies at your scale if your business is caught by the Act.

What counts as a notifiable breach. The OAIC defines an "eligible data breach" as unauthorised access to, or disclosure of, personal information you hold (or a loss of it) that is likely to result in serious harm to someone, where you haven't been able to prevent that harm with quick remedial action. A former staffer's login being used to pull customer records is a textbook example.

What you have to do. If you suspect a breach, you must assess it "quickly" — the OAIC treats 30 days as a maximum, not a grace period, and expects businesses to move faster where they can. If the assessment confirms serious harm is likely, you must notify both the affected individuals and the OAIC.

Who it applies to. The Privacy Act generally covers businesses with annual turnover above $3 million, plus all health service providers regardless of size, and — since 1 July 2026 — real estate agents, conveyancers, lawyers, accountants and precious-metals dealers for the personal information they handle under the new anti-money-laundering rules, whatever their turnover. If none of that describes you, the general small-business exemption still applies today — though the Government has flagged removing it in a future "tranche 2" of privacy reform that has not yet been introduced as a Bill, let alone passed. Don't let anyone tell you it's already gone; it isn't, for most small businesses, yet.

The 15-minute offboarding check

You can't control whether a determined attacker eventually gets in. You can control whether an account that shouldn't exist anymore is sitting there waiting to be used — by an ex-staffer, an ex-contractor, or nobody at all. This is the check the Origin story points straight at, and it takes about fifteen minutes.

01

List every login tied to a person, not a role. Your website/CMS admin panel, your hosting account, your domain registrar, your business email, your social accounts, your payment dashboard (Stripe, PayPal, Square), and any third-party app connected to your site or customer data.

02

Check who's actually still on each one. Open the admin/user list for each system above and read every name. If someone left the business — staff, contractor, or agency — months ago and their account is still active, that's the exact gap this guide is about.

03

Remove access the day someone leaves, not "when you get to it." Build a simple offboarding step into how you end any working relationship: revoke website/CMS admin, hosting, domain, email and payment-dashboard access on their last day, not whenever it's convenient.

04

Get rid of shared or generic logins. A single "admin" account used by three people can't be individually revoked when one of them leaves — you either lock everyone out or leave the door open. Give each person their own login instead.

05

Turn on multi-factor authentication everywhere it's offered. It won't stop a credential that's still technically valid from being used, but it makes a stale or shared login far harder to exploit if it does leak.

What this doesn't cover

A website scan — ours included — can't see your internal staff list or tell you whether an ex-employee still has a valid login to your CMS. That's a business-process fix, not a technical one, and it's on you and whoever manages your accounts to do the audit above. What a scan can do is flag the things that make an old or forgotten login more dangerous if it is ever misused: out-of-date software that's easier to compromise, exposed admin panels and backup files that widen what an attacker can reach, and weak email authentication that lets someone impersonate you once they're in. And whether a specific incident meets the legal threshold of an "eligible data breach" is a judgement call for the business and, where it matters, a privacy professional — we're not making that determination for you here.

If you want to see where your own site stands on the checkable side of this — outdated software, exposed admin endpoints, email spoofing protection — our free Scorecard runs those checks in a couple of minutes.

Two-minute check

See what your site shows an attacker before you even know they're looking.

Run a free Scorecard and we'll email you how your website scores on security, privacy and consumer-law basics — no payment, no cold calls.