-
Stolen Origin Energy customer data could help criminals create targeted scams and impersonate victims.
-
Experts warn AI can combine leaked details with public information to create convincing messages and fake identities.
-
Customers should beware of unexpected calls and messages pretending to come from Origin, banks, or other trusted groups.

Personal information exposed in the Origin Energy data breach could help criminals target customers with highly convincing scams. Cybersecurity experts warn that artificial intelligence, or AI, could make these attacks easier to create and carry out. Criminals could combine stolen data with information from social media and other public sources.
They could then build detailed profiles of victims and use them for phishing emails, texts, and phone calls. The data could also help criminals pretend to be victims when trying to approve fraudulent transactions. The warning follows Origin Energy’s confirmation that some customer data was accessed and disclosed without permission.
Origin Confirms Unauthorised Access to Customer Data
Origin Energy confirmed the incident on Thursday, one day after it announced an investigation into a possible breach. The company said the exposed information included names, dates of birth, phone numbers, home addresses, and email addresses.
The data also included the last four digits of some credit cards and the last three digits of some bank accounts. Origin said it was still working to find the total number of affected customers. The company also said it would contact customers after confirming which people had their information exposed.
Origin is Australia’s largest energy retailer, serving more than 4.8 million customers. There is no indication that criminals accessed complete payment card details from the incident. However, experts said the exposed information could still have serious value for scammers.
The targeting of energy companies is a global concern. The US has warned that Iran-linked hackers are actively targeting critical infrastructure systems.
Professor Richard Buckland, a cybersecurity expert at the University of New South Wales, warned about scams linked to the breach. He said follow-up scams could affect more people than the original attack and cause greater harm.
According to Buckland, scammers could pretend to help worried customers recover their stolen information. They might ask victims to confirm their identity or sign into a fake website. He advised customers to stay alert without becoming frightened and avoid links from unexpected emails or texts.
AI could Help Criminals Build Detailed Victim Profiles
Rahat Masood, a senior cybersecurity lecturer at UNSW, said criminals do not always need bank details. She said names, phone numbers, email addresses, and home addresses can still help criminals target victims.
Criminals can combine these details with public information to create highly personal stories and believable scams. They could pretend to be friends, family members, bank workers, or other trusted people. The criminals might then ask victims to share sensitive details or transfer money.
Masood said AI has made this process much faster for criminals. According to her, AI can search public information, create victim profiles, and produce personalised scam messages within seconds. Criminals could also send fake job offers or messages that appear to come from trusted people.
Those messages could contain harmful links that install malware or lead to further data theft. Professor Daswin De Silva, director of the Centre for Data Analytics and Cognition at La Trobe University, warned about identity theft.
He said criminals could use exposed information to pretend to be customers and pass some identity checks. The last four digits of a credit card can sometimes help confirm a person’s identity. Some online businesses also use those digits when checking customers before approving transactions.
De Silva warned that criminals could combine the Origin data with information from older breaches. AI tools could then help create more detailed profiles of individual victims. Buckland also warned that stolen information could remain available for a long time. He said criminals may trade the data on the dark web or private forums.
The information could attract interest because it contains many details about affected customers. Buckland also raised concerns about fraudulent Origin utility bills. He said criminals could potentially create fake bills that look genuine enough to use as identity documents.
He noted that such a bill can contribute to identity checks under Australia’s 100-point system. Masood also warned that AI could make voice impersonation scams more convincing. She said criminals may need only a short recording of someone’s voice to create a voice clone. They could then use the fake voice in a phone call or WhatsApp message.
Experts Urge Customers to Stay Alert
The three experts urged affected customers to remain careful because scammers may use the breach to gain trust. Criminals could pretend to represent Origin, banks, government agencies, or other trusted organisations.
Customers should verify unexpected messages by contacting the organisation through its official website or phone number. They should not use contact details provided inside suspicious emails, texts, or phone calls.
Customers should also be careful with messages that create pressure or demand immediate action. Scammers often claim an account has been suspended or that urgent steps are required.
People should avoid clicking links in unexpected messages because they may lead to fake websites. Some links could also download harmful software onto a person’s device. Customers should discuss unusual requests with someone they trust before taking action.
They should also monitor bank accounts and credit reports for unusual activity. Experts recommend staying cautious in the long term because stolen information can be reused later. Criminals can trade personal data online and use it in future scams, even months or years after a breach.