
Episode notes
Australia's largest energy retailer confirmed unauthorised access to customer data after an extortionist calling themselves "John Doe" took the story to journalists first. We walk through the timeline — the 3:40am customer emails, the ASX statements of 22–23 July, CEO Frank Calabria's apology — and what was taken: names, addresses, dates of birth, phone numbers, account information and partial card/bank digits. The attacker's claim of two million affected customers remains unverified. We cover why partial financial digits are a scammer's best prop, the rise of media-driven extortion pressure, and three lessons for Australian organisations: brief your teams on impersonation risk immediately, plan for the lone-wolf extortionist, and rehearse your disclosure clock. AFP, ACSC and OAIC are all engaged.
Visit www.kinsoft.com.au to talk through your security and IT needs.
Sources: Origin Energy ASX/investor statements (originenergy.com.au), Cyber Daily (24 Jul), BleepingComputer (23 Jul), SecurityWeek.
