Two Million Customers. One Ransom Note.
# Two Million Customers. One Ransom Note.
2,000,000.
That is the number of customers currently sitting in the blast radius of the Origin Energy breach. For an Australian energy giant, it's a staggering volume of exposure. But for anyone who follows the paperwork, the number is less a tragedy and more a predictable outcome of the gap between "critical infrastructure" as a policy label and critical infrastructure as a technical reality.
The details are currently thin, as is the custom with companies that prefer to let their legal teams dictate the cadence of disclosure. We know a hacker is demanding a ransom to stop the stolen data from leaking. We know account and partial financial information are in play. What we don't know is exactly which filing deadline the compliance officer is currently sweating over.
Under Australia's Notifiable Data Breaches scheme, the clock doesn't stop for a ransom negotiation. The Office of the Australian Information Commissioner (OAIC) expects notifications when a breach is likely to result in serious harm. The tension here is delicious: the company wants to pay the criminal to keep the data quiet, but the law requires them to tell the victims the data is gone. You cannot both buy a secret and satisfy a regulator.
It's a pattern. We've seen 577 data breach stories this week alone, with 95 hitting the wire today. The scale is becoming monotonous. In Seoul, a bike-sharing service leaked data for 4.6 million users and tried to smooth things over by offering a month of free rides. Meanwhile, DentaQuest is in the process of notifying north of 15 million individuals about an incident from last May.
The common thread is that the "critical" designation is often treated as a badge of honour rather than a set of requirements.
The argument from the C-suite is always the same: they've invested millions in frameworks, they've checked the boxes, and they've aligned with the latest ISO standards. They'll tell you that a breach of 2 million records is a "sophisticated attack" that no reasonable amount of preparation could have stopped.
This is nonsense. Sophistication is the excuse we use when we've failed at the basics. Most of these breaches aren't the result of a cinematic heist; they're the result of a neglected patch or a credential leaked on a forum three months prior.
Take a look at the CISA Known Exploited Vulnerabilities catalogue. Today is 2026-07-24. That is the federal patch deadline for CVE-2026-63030 in WordPress Core. If you're a government agency that hasn't hit that button by midnight, you aren't "victims of a sophisticated actor." You're just late with your homework.
The second-order effect here isn't just the identity theft risk for the 2 million Origin customers. It's the systemic fragility of the energy sector. When a primary supplier is compromised, the ripple effect hits the downstream partners—the billing aggregators, the grid maintenance contractors, and the insurers who now have to re-price the risk for the entire Australian energy market. Every single one of those entities is now wondering if their own connection to Origin is a backdoor for the ransomware gang.
I suspect the OAIC will eventually levy a fine. It will be a large number, printed in a press release that uses words like "unacceptable" and "rigorous oversight." But by the time the fine is paid, the data will have been traded across four different forums and integrated into a dozen different phishing lists. The regulation is a lagging indicator; it measures the size of the hole after the ship has already sunk.
We are seeing a shift where the "patch-and-pray" model is simply breaking. If we're seeing zero-click flaws in Zimbra being used by Russian state actors to hit government targets in the US and Ukraine simultaneously, the idea that a 30-day patch cycle is sufficient is a fantasy.
The real question is whether we'll ever move toward a regulatory model that penalises the failure to protect data in real-time, rather than rewarding the ability to write a convincing apology letter six months later. Until the fine for losing 2 million records is higher than the cost of the security talent required to prevent it, the numbers will keep climbing.
I'll be watching the OAIC filings. I expect the "sophisticated attack" narrative to hold for about three weeks before the actual entry vector—likely something mundane and embarrassing—leaks out.
◼