Local Melbourne technicians available

Careers•Remote support•Contact
All newsroom

Newsroom · Cyber Security

Origin’s data incident: practical supplier and response checks

Origin’s July 2026 notices confirm unauthorised customer-data access. Practical checks for supplier notifications, incident ownership and healthcare continuity.

Origin Energy confirmed unauthorised access and disclosure of some customer information on 23 July 2026. Its subsequent notice provides a firmer basis for practical planning than broad claims that every recent security headline describes the same kind of attack.

What Origin confirmed

Origin’s 23 July notice said it was investigating the extent of the incident and contacting affected customers. It listed possible affected information including contact and account details, with partial payment-account information.

On 28 July, Origin said its initial review indicated information relating to approximately 900,000 current and former customers had been accessed. It described customer support arrangements and work with cyber security and forensic specialists. These are Origin’s statements at those dates; affected customers should use its incident update page for current instructions.

The notices do not establish that a particular Melbourne business or healthcare practice was compromised. They also do not provide a basis for guessing an attack method or claiming a particular security product would have prevented it.

Turn the headline into a supplier review

Podium IT’s practical recommendation is to identify which suppliers hold information about your organisation and how a security notice would reach the right person. A supplier incident can require administrative follow-up even when your own systems remain available.

  • Keep an up-to-date owner and escalation contact for important supplier accounts.
  • Check that incident notifications go to a monitored business address rather than only to a former employee.
  • Verify unexpected requests through a previously known contact route before changing payment details or sharing additional information.
  • Record what the supplier has confirmed, which questions remain open and when the next review is due.

Healthcare procurement provides a second useful lesson

ENISA published updated procurement guidance for hospitals and healthcare providers on 22 July 2026 as part of its work under the EU Health Action Plan. That is a European initiative, not a new Australian compliance requirement.

For an Australian practice, the useful planning question is whether security and continuity are discussed before a service is purchased. Ask who manages access, how incidents are escalated, what support is available during disruption and what evidence supports recovery arrangements. Put responsibilities into the relevant agreements rather than relying on assumptions.

A short response exercise for your practice

Consider this illustrative scenario: a supplier reports unauthorised access to customer records, but your practice software still works. Who verifies the notice, establishes whether your account is affected, preserves correspondence and coordinates the response? Which staff need instructions, and who approves any communication?

Record the decisions and outstanding facts. If evidence suggests your own accounts or systems may be affected, involve your IT provider promptly and follow the agreed incident response process. Decisions about notification obligations should be assessed on the actual circumstances with appropriate advice.

Use the Healthcare IT Readiness Standard to review ownership and recovery evidence, and the dental continuity checklist where an interruption could affect appointments, imaging or payments. These planning tools support preparation; they cannot predict or guarantee protection against a particular incident.

Correction and review

Reviewed and corrected on 11 September 2026. An earlier version referred to an OpenAI cybersecurity incident without distinguishing a security evaluation from a reported attack. That wording has been removed. This article now uses Origin’s own notices and ENISA’s publication, with later information clearly dated. The original URL and publication date have been retained.

Talk to Podium IT

Need a clear next step?

Send a secure enquiry and tell us what you are planning. Please do not include passwords, patient information or other sensitive data.

Encrypted in transit Securely stored

This form uses server-side validation, bot protection and rate limiting. For urgent support, call us directly.

General information only. It is not legal, privacy or compliance advice; requirements should be assessed for your organisation.