Jason Pearce
Field CTO at Claroty
Attackers increasingly view energy and utilities companies as attractive targets because they not only offer large volumes of customer information, but they can also provide an opportunity to disrupt critical infrastructure – in this case our power grid – which can have a profound impact on the general public. While a cyber attack may start out as a breach of an organisation's IT systems, attackers can quickly migrate into operational environments if the right protocols aren't in place. This is where attackers can cause the most damage, by potentially disrupting the electricity supply for millions of Australians.
When facing an attack, energy and utility operators must ensure hackers have no viable pathways to reach their operational environments, which can be viewed as their 'crown jewels'. A data breach affects trust with your customers, but an operational technology breach can affect the whole of society by disrupting critical services which the country relies on. That’s why Australia’s Energy companies, and every other critical infrastructure operator, must prepare for both of these scenarios to protect the systems that keep these essential services running.
Michael Jackas
Director of Information and Technology at SKG Services
Until the investigation establishes the facts, it would be inappropriate to speculate about the cause, scale or information potentially affected. What the situation reinforces for Australian organisations is that preparation cannot begin after an incident occurs. Businesses need the systems, responsibilities and response procedures in place well before they are required.
Every organisation should have a documented incident-response plan, but having a plan is not enough; it must be regularly tested.
Responsibilities for containment, evidence preservation, technical investigation, privacy assessment, regulatory obligations and communication should be established in advance. When an incident is suspected, the response must move quickly without moving ahead of the evidence. Communications should clearly distinguish between confirmed facts, matters still under investigation, and any practical steps affected individuals should take.
Anthony Daniel
Managing Director ANZ & Pacific Islands at WatchGuard Technologies
In the immediate aftermath of a breach, Origin's priorities should be rapid containment, total transparency, and clear customer communication. The sooner impacted individuals are notified, the faster they can protect their identities. This incident follows other major Australian breaches, including Optus, Medibank and Qantas, where personal information was targeted. Even without financial details exposed, names, addresses, dates of birth and contact details can be enough for attackers to launch convincing phishing campaigns, which is why organisations need to assume any customer data has value to cybercriminals.
Customers should be particularly cautious of unsolicited emails, text messages, or phone calls claiming to be from Origin over the coming days and weeks, particularly those urging them to click a link, verify details, or make a payment. They should access their account directly through Origin’s official website or app and follow verified guidance.
Incidents like this also reflect a broader sustained pressure Australian organisations are under from cybercriminals. WatchGuard Threat Lab recorded more than 96,000 network attacks blocked against Australian organisations in a single quarter last year. While it's too early to know how this incident occurred, organisations holding large volumes of customer data need strong network visibility to detect suspicious activity early and respond before data is compromised.
Professor Craig Costello
Queensland University of Technology
Australia continues to be a high-value target for malicious actors because organisations hold huge amounts of customer data. Even where financial information isn't compromised, personal data can be weaponised for highly targeted phishing, identity fraud, social engineering and extortion.
Australian organisations regularly face claims of cyber compromise. Some are opportunistic attempts by criminals seeking attention or extortion payments, while others are legitimate breaches. The challenge for organisations is responding quickly and responsibly while verifying the facts, because the consequences of both underestimating and overstating a cyber incident can be significant.
Healthcare and critical infrastructure continue to be prime targets because they hold some of the most valuable data for cyber attackers. This data is deeply personal, making the impact especially serious and infinitely harmful.
Want to see more stories from trusted news sources?Make Cyber Daily a preferred news source on Google.
David Hollingworth
David Hollingworth has been writing about technology for over 20 years, and has worked for a range of print and online titles in his career. He is enjoying getting to grips with cyber security, especially when it lets him talk about Lego.