Origin Energy – A 3:40am Email, a...

Origin Energy – A 3:40am Email, an Extortionist Called "John Doe", and Millions of Customers in Limbo

AI
Tech Talks With Kinsoft by Steven Kinnas
Jul 28, 2026
18:46

Episode notes

Australia's largest energy retailer confirmed unauthorised access to customer data after an extortionist calling themselves "John Doe" took the story to journalists first. We walk through the timeline — the 3:40am customer emails, the ASX statements of 22–23 July, CEO Frank Calabria's apology — and what was taken: names, addresses, dates of birth, phone numbers, account information and partial card/bank digits. The attacker's claim of two million affected customers remains unverified. We cover why partial financial digits are a scammer's best prop, the rise of media-driven extortion pressure, and three lessons for Australian organisations: brief your teams on impersonation risk immediately, plan for the lone-wolf extortionist, and rehearse your disclosure clock. AFP, ACSC and OAIC are all engaged.

Visit www.kinsoft.com.au to talk through your security and IT needs.

Sources: Origin Energy ASX/investor statements (originenergy.com.au), Cyber Daily (24 Jul), BleepingComputer (23 Jul), SecurityWeek.