{"id":819458,"date":"2026-07-23T21:16:12","date_gmt":"2026-07-23T21:16:12","guid":{"rendered":"https:\/\/www.newsbeep.com\/au\/819458\/"},"modified":"2026-07-23T21:16:12","modified_gmt":"2026-07-23T21:16:12","slug":"origin-breach-could-fuel-wave-of-ai-powered-scams-cyber-experts-warn","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/au\/819458\/","title":{"rendered":"Origin breach could fuel wave of AI-powered scams, cyber experts warn"},"content":{"rendered":"<p class=\"paragraph_paragraph___QITb\">Personal details stolen in the Origin Energy data breach could give scammers the opportunity to launch highly targeted attacks, cyber security experts warn, with artificial intelligence (AI) making it easier to impersonate victims, clone voices and build detailed personal profiles.\u00a0<\/p>\n<p class=\"paragraph_paragraph___QITb\">They say the information could be used to create convincing phishing emails, phone calls and text messages, pass identity checks for online accounts, and help criminals impersonate victims to authorise fraudulent transactions.<\/p>\n<p class=\"paragraph_paragraph___QITb\">The warning comes after Origin confirmed on Thursday there had been <a class=\"Link_link__kR0xA Link_link__5eL5m ScreenReaderOnly_srLinkHint__OysWz Link_showVisited__C1Fea Link_showFocus__ALyv2\" href=\"https:\/\/www.abc.net.au\/news\/2026-07-23\/origin-energy-confirms-unauthorised-access-customer-data\/106948052\" data-component=\"Link\" data-uri=\"coremedia:\/\/article\/106948052\" rel=\"nofollow noopener\" target=\"_blank\">unauthorised access to and disclosure of some customers&#8217;s data<\/a>.<\/p>\n<p><a href=\"https:\/\/www.abc.net.au\/news\/2026-07-23\/origin-energy-confirms-unauthorised-access-customer-data\/106948052\" data-component=\"FullBleedLink\" class=\"RelatedCard_link__rsgR9 FullBleedLink_root__lTw_U interactive_focusContext__yRhc_ interactive_defaults__AKxUU FullBleedLink_showVisited__g3Xvz\" rel=\"nofollow noopener\" target=\"_blank\">Origin Energy confirms hack<\/a><\/p>\n<p class=\"Typography_base__sj2RP RelatedCard_synopsis__cFwMW Typography_sizeMobile14__u7TGe Typography_lineHeightMobile20___U7Vr Typography_regular__WeIG6 Typography_colourInherit__dfnUx\" data-component=\"Typography\">Energy company Origin has confirmed that there has been unauthorised access and disclosure of some customers&#8217; data, a day after it announced it was investigating a &#8220;potential&#8221; breach.<\/p>\n<p class=\"paragraph_paragraph___QITb\">The information included names, dates of birth, phone numbers, home addresses and email addresses, as well as the last four digits of some credit cards and the last three digits of some bank account numbers.<\/p>\n<p class=\"paragraph_paragraph___QITb\">Origin is Australia&#8217;s largest energy retailer with more than 4.8 million customers. The company said it was still working to determine the total number of people affected and would notify impacted customers once their details had been confirmed.<\/p>\n<p class=\"paragraph_paragraph___QITb\">While there is no indication full payment card details were compromised, experts say the stolen information remains highly valuable and are urging affected customers to remain cautious about unsolicited emails, text messages and phone calls long after the breach.<\/p>\n<p>Scams pretending to help you<\/p>\n<p class=\"paragraph_paragraph___QITb\">Professor Richard Buckler, a cyber security expert at the University of New South Wales (UNSW), said the greatest risk for most customers was not the breach itself, but opportunistic scammers exploiting anxiety surrounding the breach.<\/p>\n<p>&#8220;The secondary attacks tend to catch more people than the original attack and cause more damage,&#8221;  he said.<\/p>\n<p class=\"paragraph_paragraph___QITb\">&#8220;They can appear to be trying to help you &#8230; &#8216;Your data&#8217;s been stolen, just verify yourself to us, and we&#8217;ll fix it for you&#8217; or ask you to log into a website.&#8221;<\/p>\n<p class=\"paragraph_paragraph___QITb\">His advice was for customers to &#8220;be alert but not alarmed&#8221; and avoid clicking links in unsolicited emails or text messages.<\/p>\n<p><img decoding=\"async\" alt=\"An email from Netflix asking a user to update their payment details\" class=\"Image_image__5tFYM ContentImage_image__DQ_cq\"  src=\"https:\/\/www.newsbeep.com\/au\/wp-content\/uploads\/2026\/07\/835319e74e9f8c89d499d5b6c55f8014.jpeg\" loading=\"lazy\" data-component=\"Image\" data-lazy=\"true\"\/><\/p>\n<p class=\"Typography_base__sj2RP FigureCaption_text__zDxQ5 Typography_sizeMobile12__w_FPC Typography_lineHeightMobile20___U7Vr Typography_regular__WeIG6 Typography_colourInherit__dfnUx\" data-component=\"Typography\">This fake Netflix email is an example of a phishing scam. Experts warn criminals could use stolen Origin customer data to create even more convincing messages. (Supplied: consumer.ftc.gov)<\/p>\n<p class=\"paragraph_paragraph___QITb\">Rahat Masood, a senior lecturer in cyber security at UNSW&#8217;s School of Computer Science and Engineering, said criminals no longer needed bank details to launch convincing attacks.<\/p>\n<p class=\"paragraph_paragraph___QITb\">&#8220;People think data is only sensitive if it includes credit card details or bank details,&#8221; she said. &#8220;But that&#8217;s not the case anymore.&#8221;<\/p>\n<p><a href=\"https:\/\/www.abc.net.au\/news\/2023-08-17\/phishing-scam-explainer-cybercrime-social-engineering\/102735538\" data-component=\"FullBleedLink\" class=\"RelatedCard_link__rsgR9 FullBleedLink_root__lTw_U interactive_focusContext__yRhc_ interactive_defaults__AKxUU FullBleedLink_showVisited__g3Xvz\" rel=\"nofollow noopener\" target=\"_blank\">The anatomy of a phishing scam<\/a><\/p>\n<p class=\"Typography_base__sj2RP RelatedCard_synopsis__cFwMW Typography_sizeMobile14__u7TGe Typography_lineHeightMobile20___U7Vr Typography_regular__WeIG6 Typography_colourInherit__dfnUx\" data-component=\"Typography\">Phishing is\u00a0the most commonly reported scam in Australia, with scammers harvesting tens of millions of dollars every year from unsuspecting victims.<\/p>\n<p class=\"paragraph_paragraph___QITb\">Dr Masood said names, phone numbers, email addresses and home addresses could be combined with information from social media and other public sources to create highly personalised phishing emails, text messages and phone calls.<\/p>\n<p class=\"paragraph_paragraph___QITb\">&#8220;They can actually build a whole lot of scenarios where they &#8230; pretend to be a friend, family member or bank representative, asking you to share sensitive information, make a transaction or transfer money.&#8221;\u00a0<\/p>\n<p class=\"paragraph_paragraph___QITb\">She said AI had dramatically accelerated that process, allowing criminals to rapidly search public information, build detailed profiles of victims and generate personalised scam messages &#8220;in seconds&#8221;.<\/p>\n<p class=\"paragraph_paragraph___QITb\">&#8220;If they know your profile, they can send you a very promising job link or pretend to be someone you trust,&#8221; Dr Masood said.<\/p>\n<p class=\"paragraph_paragraph___QITb\">&#8220;And you never know what&#8217;s behind that link. It could be malware and lead to further breaches.&#8221;<\/p>\n<p>Identity theft in the AI era\u00a0<\/p>\n<p class=\"paragraph_paragraph___QITb\">Professor Daswin De Silva, director of the Centre for Data Analytics and Cognition at La Trobe University, said if the combination of personal information was exposed, then the breach could also allow criminals to impersonate customers and bypass some identity checks.<\/p>\n<p class=\"paragraph_paragraph___QITb\">&#8220;The last four digits of a credit card are often used to verify someone&#8217;s identity,&#8221; he said.<\/p>\n<p class=\"paragraph_paragraph___QITb\">&#8220;Cyber criminals can now use this information to launch impersonation attacks by pretending to be Origin customers.&#8221;<\/p>\n<p class=\"paragraph_paragraph___QITb\">Professor De Silva said many online retailers already stored customers&#8217; payment details, meaning criminals might only need enough information to satisfy identity checks before attempting purchases.<\/p>\n<p class=\"paragraph_paragraph___QITb\">&#8220;You don&#8217;t always need the full card number,&#8221; he said.\u00a0<\/p>\n<p class=\"paragraph_paragraph___QITb\">&#8220;Some organisations authenticate customers using the last four digits before allowing a transaction.&#8221;<\/p>\n<p><img decoding=\"async\" alt=\"Three A4 pages showing different energy bills and amounts owing.\" class=\"Image_image__5tFYM ContentImage_image__DQ_cq\"  src=\"https:\/\/www.newsbeep.com\/au\/wp-content\/uploads\/2026\/07\/1784841372_73_ba5144e7c7eac899f9d19c9ed295171d.jpeg\" loading=\"lazy\" data-component=\"Image\" data-lazy=\"true\"\/><\/p>\n<p class=\"Typography_base__sj2RP FigureCaption_text__zDxQ5 Typography_sizeMobile12__w_FPC Typography_lineHeightMobile20___U7Vr Typography_regular__WeIG6 Typography_colourInherit__dfnUx\" data-component=\"Typography\">Richard Buckler says fraudulent Origin utility bills could be used as proof of identity, increasing the risk of identity theft after the breach. (ABC News: Matt Roberts)<\/p>\n<p class=\"paragraph_paragraph___QITb\">He said the stolen information could also be merged with data from previous breaches,<a class=\"Link_link__kR0xA Link_link__5eL5m ScreenReaderOnly_srLinkHint__OysWz Link_showVisited__C1Fea Link_showFocus__ALyv2\" href=\"https:\/\/www.abc.net.au\/news\/2025-10-11\/hackers-release-qantas-customers-data-on-dark-web\/105881266\" data-component=\"Link\" data-uri=\"coremedia:\/\/article\/105881266\" rel=\"nofollow noopener\" target=\"_blank\"> such as the Qantas cyber attack<\/a>, allowing AI tools to rapidly build increasingly detailed profiles of victims.<\/p>\n<p class=\"paragraph_paragraph___QITb\">&#8220;Once this information is out there, it tends to stay out there,&#8221; he said.<\/p>\n<p>&#8220;What usually happens is the data ends up on the dark web, then it gets traded, and given the richness of the [Origin] data, this would probably attract a lot of interest.&#8221;<a href=\"https:\/\/www.abc.net.au\/news\/2025-10-11\/hackers-release-qantas-customers-data-on-dark-web\/105881266\" data-component=\"FullBleedLink\" class=\"RelatedCard_link__rsgR9 FullBleedLink_root__lTw_U interactive_focusContext__yRhc_ interactive_defaults__AKxUU FullBleedLink_showVisited__g3Xvz\" rel=\"nofollow noopener\" target=\"_blank\">Qantas customers&#8217; data leaked to dark web after cyber attack<\/a><\/p>\n<p class=\"Typography_base__sj2RP RelatedCard_synopsis__cFwMW Typography_sizeMobile14__u7TGe Typography_lineHeightMobile20___U7Vr Typography_regular__WeIG6 Typography_colourInherit__dfnUx\" data-component=\"Typography\">Hackers have released personal data from Qantas customers onto the dark web, following a cyber attack in July.\u00a0<\/p>\n<p class=\"paragraph_paragraph___QITb\">Professor Buckler said one aspect of the breach that concerned him was Origin&#8217;s ability to issue utility bills, which can be used as proof of identity.<\/p>\n<p class=\"paragraph_paragraph___QITb\">&#8220;If there&#8217;s enough information to make a bill look legitimate, people with disinformation could print bills that appear to come from Origin,&#8221; he said.<\/p>\n<p class=\"paragraph_paragraph___QITb\">&#8220;That counts for 20 points under Australia&#8217;s 100-point identity check, so there&#8217;s potentially slightly more risk of identity theft in this case.&#8221;<\/p>\n<p class=\"paragraph_paragraph___QITb\">Dr Masood said AI had also lowered the barrier for more sophisticated impersonation scams.<\/p>\n<p class=\"paragraph_paragraph___QITb\">&#8220;If you have a video online or you&#8217;ve spoken publicly, they can use five or 10 seconds of your voice and clone it,&#8221; she said.<\/p>\n<p class=\"paragraph_paragraph___QITb\">&#8220;They can then send a WhatsApp voice message or make a phone call pretending to be you. With AI, they can do almost anything now.&#8221;<\/p>\n<p>How to protect yourself<\/p>\n<p class=\"paragraph_paragraph___QITb\">All three cybersecurity experts say affected customers should remain cautious, warning scammers are likely to exploit public awareness of the breach.\u00a0<\/p>\n<p class=\"paragraph_paragraph___QITb\">They recommend:<\/p>\n<p>Don&#8217;t trust unexpected emails, text messages or phone calls. Scammers may pretend to be Origin, your bank or a government agency.Verify the sender independently. Contact Origin or your bank using a publicly listed phone number or official website, rather than details provided in a message.Be wary of urgency. Messages claiming your account has been suspended or demanding immediate action are common phishing tactics.Never click on unsolicited links. They could lead to fake websites or install malware on your device.Think twice before responding. If something seems unusual, discuss it with a trusted friend or family member before taking action.Monitor your accounts and credit report. Watch for unusual transactions or signs someone is trying to open credit in your name.Stay vigilant over the long term. Experts warn stolen personal information can be traded online and reused in future scams, even months or years after a breach.<\/p>\n","protected":false},"excerpt":{"rendered":"Personal details stolen in the Origin Energy data breach could give scammers the opportunity to launch highly targeted&hellip;\n","protected":false},"author":2,"featured_media":819459,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[20],"tags":[256,254,255,64,63,11452,17971,14279,354,394647,137830,53555,22864,105],"class_list":["post-819458","post","type-post","status-publish","format-standard","has-post-thumbnail","category-artificial-intelligence","tag-ai","tag-artificial-intelligence","tag-artificialintelligence","tag-au","tag-australia","tag-bank-account","tag-credit-card","tag-data-breach","tag-fraud","tag-identity-checks","tag-origin-energy","tag-phishing","tag-scam","tag-technology"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/posts\/819458","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/comments?post=819458"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/posts\/819458\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/media\/819459"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/media?parent=819458"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/categories?post=819458"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/tags?post=819458"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}