Origin silent on settlement as alleged fired employee breach detail emerges

The alleged access method puts identity management controls squarely in scope for insurers

Origin silent on settlement as alleged fired employee breach detail emerges

Cyber

By Roxanne Libatique

Origin Energy has declined to comment on a public claim that it privately resolved a cyber extortion threat – a posture that, as of July 24, leaves the company managing simultaneous obligations to regulators, the ASX, and an insurance market now aware that the alleged access point was a fired former employee’s credentials left active on a vendor-operated platform serving close to a third of Australian households.

The July 24 developments

The settlement claim emerged on July 24 when an individual using the alias Edison Walthour had told The Australian newspaper all stolen data would be withheld following a private arrangement with Origin. “We took our site down, we already settled everything with Origin Energy privately and no data will be leaked,” the individual was quoted as saying. That claim landed alongside new detail about the incident’s timeline. According to reporting by Information & Data Manager, the alleged hacker first contacted Origin on July 2 – approaching board members, security teams, and customer care staff – and went to the media only after nearly three weeks without response. The Australian reported the individual used the login credentials of a former Origin employee who was subsequently dismissed, and that Origin had declined to comment on the alleged termination. No ransom demand had been reported before the settlement claim was made public.

Business News Australia confirmed on July 24 that Origin, when approached directly for comment on the settlement claim, declined to address it and referred to its July 23 ASX statement. That statement confirmed unauthorised access and disclosure of some customer’s data, including the last four digits of some credit card numbers and the last three digits of some bank account numbers. Origin has approximately 4.8 million customer accounts across electricity, gas, LPG, and internet services. The total number of affected customers has not yet been confirmed. Origin chief executive Frank Calabria apologised publicly on July 23. “I’m sorry this has happened. Customers trust Origin with their information, and I apologise for the impact this may cause,” he said. The company said it continues to engage with the Australian Federal Police, the Australian Cyber Security Centre (ACSC), and the Office of the Australian Information Commissioner (OAIC).

What the fired employee detail means for insurers

According to media reports, the alleged access vector involved credentials belonging to a former Origin employee that were reportedly still active on the Kraken customer management platform. If confirmed, the reported access method is likely to be relevant to any assessment of cyber insurance coverage and claims handling. Many Australian cyber insurers now scrutinise identity and access management practices – including privileged access management and employee offboarding controls – during underwriting. Security guidance from organisations such as OWASP, the ACSC, and NIST also highlights timely revocation of credentials, including access to third-party platforms, as a critical component of secure offboarding. Whether Origin’s access controls over Kraken-platform credentials met the standard declared at policy inception is a question its insurer will need to resolve before any claim is settled.

The platform’s broader footprint

The Kraken platform is not exclusive to Origin. As of July 2024, following Energy Queensland’s (EQL) full migration of Ergon Energy Retail’s accounts, Kraken became responsible for almost a third of Australian households’ retail energy experiences. Confirmed Australian Kraken customers include Origin Energy, Ergon Energy Retail, which serves approximately 750,000 residential and business customers in Queensland, and Korean-owned retailer Nectr. Distribution network operator Essential Energy has also partnered with Kraken, becoming the first Australian electricity network business to deploy the platform. Origin holds an equity stake in Kraken Technologies after investing approximately $210 million in the company’s first external equity funding round in 2025.

Each licensee operates its own instance of the platform with its own access controls. A credential failure at one licensee does not automatically expose another licensee’s data. But the breach illustrates the exposure class shared across the platform: a single terminated employee’s credentials, unrevoked on a vendor system, proved sufficient to access two million customer records over three weeks undetected. The Australian Prudential Regulation Authority’s (APRA) November 2025 System Risk Outlook flagged precisely this risk architecture, warning that many institutions relying on the same providers creates vulnerability to “a single point of failure” and that “third parties can be used as a ‘backdoor’ to execute a cyberattack.” While that observation was directed at APRA-regulated financial entities, the concentration dynamic it describes is structurally identical to the one the Origin incident has now made visible in the energy retail sector.

Reporting obligations and the settlement question

Origin’s silence on the settlement claim creates unresolved questions under two concurrent regulatory frameworks. Under the Cyber Security Act 2024, any ransomware or cyber extortion payment – including payments made through a third party such as an insurer or incident response firm – must be reported to the Australian Signals Directorate (ASD) within 72 hours. The definition of payment extends beyond money: giving a product, service, or any other thing of value in exchange for a threat actor ceasing extortion constitutes a reportable payment.

A qualifying payment now triggers two concurrent obligations: the 72-hour notification to the ASD under the Cyber Security Act and a potential notifiable data breach report to the OAIC under the Privacy Act. Origin has not confirmed whether any such payment or arrangement was made. The Australian Federal Police and relevant cyber security authorities remain engaged. The regulatory stakes are not hypothetical. In October 2025, the Federal Court ordered Australian Clinical Labs to pay $5.8 million – the first civil penalty imposed under the Privacy Act 1988 – following a 2022 data breach affecting more than 223,000 individuals. Under the current penalty regime, maximum penalties for serious breaches can reach $50 million, three times the benefit derived from the conduct, or 30% of annual turnover. Origin reported revenue of approximately $8 billion in the six months to December 31, 2025.

What brokers and underwriters should be doing now

The Origin incident is a live case across three lines simultaneously: cyber liability, for the access control and notification questions; D&O, for the ASX disclosure timeline and the three-week detection gap; and potentially management liability, depending on how the settlement question resolves. Brokers with energy sector clients on shared vendor platforms should confirm, before the next renewal, whether their client’s incident response plan explicitly addresses credential revocation for departed employees on third-party systems, and whether policy notification clauses account for the dual reporting timeline now in force under Australian law.

Related Stories

Keep up with the latest news and events

Join our mailing list, it’s free!