Origin Energy is a top-tier Australian energy retailer with a dedicated security team, so the size of this breach naturally makes headlines. But the detail worth sitting with isn't the scale — it's the reported mechanism. Multiple outlets, citing sources close to the investigation, report that a former Origin employee's login credentials remained active on a third-party customer-management platform well after they'd left the business, and that this account was the way in. Origin has not publicly confirmed the cause and the Australian Federal Police, the Australian Cyber Security Centre (ACSC) and the OAIC are all still involved, so treat the "how" as reported rather than settled. What is confirmed is the scale: about 900,000 current and former customers had data accessed, including names, addresses, dates of birth, phone numbers, account details, and partial credit-card or bank-account digits.
The rule that applies to your business too
It's tempting to read a story this size as someone else's problem. It isn't. Australia's Notifiable Data Breaches (NDB) scheme, run by the Office of the Australian Information Commissioner (OAIC), applies to any organisation the Privacy Act covers — and the same duty Origin is working through applies at your scale if your business is caught by the Act.
What counts as a notifiable breach. The OAIC defines an "eligible data breach" as unauthorised access to, or disclosure of, personal information you hold (or a loss of it) that is likely to result in serious harm to someone, where you haven't been able to prevent that harm with quick remedial action. A former staffer's login being used to pull customer records is a textbook example.
What you have to do. If you suspect a breach, you must assess it "quickly" — the OAIC treats 30 days as a maximum, not a grace period, and expects businesses to move faster where they can. If the assessment confirms serious harm is likely, you must notify both the affected individuals and the OAIC.
Who it applies to. The Privacy Act generally covers businesses with annual turnover above $3 million, plus all health service providers regardless of size, and — since 1 July 2026 — real estate agents, conveyancers, lawyers, accountants and precious-metals dealers for the personal information they handle under the new anti-money-laundering rules, whatever their turnover. If none of that describes you, the general small-business exemption still applies today — though the Government has flagged removing it in a future "tranche 2" of privacy reform that has not yet been introduced as a Bill, let alone passed. Don't let anyone tell you it's already gone; it isn't, for most small businesses, yet.
The 15-minute offboarding check
You can't control whether a determined attacker eventually gets in. You can control whether an account that shouldn't exist anymore is sitting there waiting to be used — by an ex-staffer, an ex-contractor, or nobody at all. This is the check the Origin story points straight at, and it takes about fifteen minutes.
List every login tied to a person, not a role. Your website/CMS admin panel, your hosting account, your domain registrar, your business email, your social accounts, your payment dashboard (Stripe, PayPal, Square), and any third-party app connected to your site or customer data.
Check who's actually still on each one. Open the admin/user list for each system above and read every name. If someone left the business — staff, contractor, or agency — months ago and their account is still active, that's the exact gap this guide is about.
Remove access the day someone leaves, not "when you get to it." Build a simple offboarding step into how you end any working relationship: revoke website/CMS admin, hosting, domain, email and payment-dashboard access on their last day, not whenever it's convenient.
Get rid of shared or generic logins. A single "admin" account used by three people can't be individually revoked when one of them leaves — you either lock everyone out or leave the door open. Give each person their own login instead.
Turn on multi-factor authentication everywhere it's offered. It won't stop a credential that's still technically valid from being used, but it makes a stale or shared login far harder to exploit if it does leak.
What this doesn't cover
A website scan — ours included — can't see your internal staff list or tell you whether an ex-employee still has a valid login to your CMS. That's a business-process fix, not a technical one, and it's on you and whoever manages your accounts to do the audit above. What a scan can do is flag the things that make an old or forgotten login more dangerous if it is ever misused: out-of-date software that's easier to compromise, exposed admin panels and backup files that widen what an attacker can reach, and weak email authentication that lets someone impersonate you once they're in. And whether a specific incident meets the legal threshold of an "eligible data breach" is a judgement call for the business and, where it matters, a privacy professional — we're not making that determination for you here.
If you want to see where your own site stands on the checkable side of this — outdated software, exposed admin endpoints, email spoofing protection — our free Scorecard runs those checks in a couple of minutes.
Sources
- Insurance Business Australia — Origin silent on settlement as alleged fired-employee breach detail emerges
- SecurityWeek — Data breach confirmed after Australian energy giant Origin is hacked
- Origin Energy — Update, July 2026 (official incident page)
- OAIC — About the Notifiable Data Breaches scheme (who it covers, what triggers it)
- OAIC — When to report a data breach (the 30-day assessment window, eligible data breach test)
- OAIC — Small business and the Privacy Act ($3 million turnover threshold)
- AegorIQ — The Privacy Act just started applying to businesses that were always exempt (AML/CTF tranche 2, in force 1 July 2026)