Origin Energy breach raises long-term cyber security concerns

Origin Energy breach raises long-term cyber security concerns

One of Australia's largest energy companies, Origin Energy, is investigating a potential security breach that may have affected customer data. An RMIT expert says the incident poses longer-term scam risks and highlights a growing need for quantum-safe encryption.

Associate Professor Nalin Arachchilage, School of Computing Technologies: 

"Origin Energy says financial details weren't taken, but that shouldn't be read as 'nothing to worry about’. Names, addresses, account numbers and usage data are exactly the kind of information attackers use to build convincing scams — and increasingly, to profile a household for years to come, not just for the next billing cycle.

"With incidents like these, it isn't just what can be done with the data today — it's what can be done with it in ten years' time. We're seeing a growing pattern of 'harvest now, decrypt later' attacks, where adversaries steal encrypted data now simply to sit on it, betting that quantum computing will eventually be powerful enough to break the encryption protecting it.

"It's a bit like someone secretly recording every phone call you've ever made, even though they can't understand a word of it yet. They're not listening for what you're saying today — they're banking on inventing the ability to decode it later. When that day comes, years-old 'unreadable' data can suddenly become very readable.

“Critical industries like energy retailers hold exactly the kind of long-shelf-life data that makes 'harvest now, decrypt later' worthwhile for attackers — identity details, account histories, household patterns - that don't expire the way a stolen password does. Critical infrastructure and essential services need to be considered for post-quantum cryptography, not an afterthought.

"Australian organisations don't need to panic about quantum computers arriving tomorrow — but they do need to start planning today. Migrating to quantum-safe encryption takes years, and any sensitive customer data being stolen right now could still be sitting in an attacker's archive, when that migration should have already happened."

Associate Professor Nalin Arachchilage is a cyber security researcher at RMIT University.

***

General media enquiries: RMIT External Affairs and Media, 0439 704 077 or news@rmit.edu.au

23 July 2026

Share

23 July 2026

Share

Related News

aboriginal flag float-starttorres strait flag float-start

Acknowledgement of Country

RMIT University acknowledges the people of the Woi wurrung and Boon wurrung language groups of the eastern Kulin Nation on whose unceded lands we conduct the business of the University. RMIT University respectfully acknowledges their Ancestors and Elders, past and present. RMIT also acknowledges the Traditional Custodians and their Ancestors of the lands and waters across Australia where we conduct our business - Artwork 'Sentient' by Hollie Johnson, Gunaikurnai and Monero Ngarigo.

More information