← All posts

The Breach That Was “Not Credible” — Until It Was

In early July, someone flagged a potential security threat to Origin Energy, the Australian utility that serves millions of households. The company looked into it. They assessed it. They decided it wasn't credible.

Three weeks later, on July 22, new information arrived. This time it was real. By July 28, CEO Frank Calabria was telling the public that roughly 900,000 current and former customers had their personal information accessed — names, addresses, dates of birth, phone numbers, account details, and partial credit card or bank information.

I want to sit on that first paragraph for a second, because it's the part boards tend to skip past on their way to the breach headline. Origin didn't miss a signal. They caught one, looked at it, and called it wrong. That's a different failure than "we had no idea," and it's a more useful one to study, because it's the failure most organizations are actually exposed to.

The gap between “not credible” and “not yet confirmed”

Every security team fields a steady stream of alerts, tips, and dark-web chatter. Most of it is noise. Triage exists for a reason — you can't chase every shadow. But "not credible" is a conclusion, and conclusions carry weight in a way that "we don't have enough to act on yet" doesn't.

Origin's own account (posted on their incident update page) is careful on this point: they say they "worked to confirm its credibility and potential impact," and based on the information available at the time, it wasn't assessed as credible. That's a defensible process. It's also exactly the kind of process a board needs to understand before the next ambiguous signal comes in, not after.

This is the third of the Three Questions I walk executives through in Cyber Risk Is Business Risk: not "are we secure," not even "are we compliant," but "how would we know if we were wrong?" Origin's board should be asking that now, retroactively. Yours should be asking it before you need to.

What we don't know — and shouldn't pretend to

Several outlets have reported that the breach traces back to a terminated employee's credentials that weren't revoked on a vendor system, and that a hacker initially claimed closer to two million customer records. I'm not going to repeat either of those as fact here. Origin has not confirmed a root cause, has not named a vendor, and has not confirmed a number beyond the 900,000 figure Calabria gave on July 28. The gap between an attacker's claim and a company's confirmed number is often wide, and reporting on breaches in progress moves faster than the facts do. What's confirmed: unauthorized access, roughly 900,000 people affected, an active criminal investigation, and three Australian regulators involved.

That distinction matters for how you talk about this in your own boardroom. If a director asks "could this happen to us," the honest answer starts with "we don't know exactly what happened to them yet" — and that's fine. What you can discuss is the pattern, which shows up in breach after breach: identity and access sitting somewhere in the seams between a company and its vendors, unmonitored long enough to matter.

The parts of this Origin got right

It's worth naming, because boards rarely get credit-worthy examples in real time. Calabria's public statements are direct — "I am sorry," not "we regret any inconvenience." Origin set up a dedicated support line, partnered with IDCARE for identity support, and is offering a year of credit monitoring through Equifax Protect. They notified the Australian Cyber Security Centre, the Australian Federal Police, and the Office of the Australian Information Commissioner without apparent delay once the incident was confirmed. None of that undoes the exposure. All of it is the difference between a company that looks prepared and one that looks like it's improvising in public.

What to ask your CISO this week

Three questions, drawn straight from this incident:

First, walk me through our last "not credible" call. Pull the most recent security alert your team triaged and dismissed. Not to second-guess it — to understand the reasoning, and whether that reasoning would hold up if you had to explain it to a regulator three weeks later.

Second, who still has access that they shouldn't? Ask specifically about offboarded employees and contractors on third-party systems — the exact seam that keeps showing up in these incidents, confirmed or not.

Third, if we had to notify 900,000 people tomorrow, what would that look like? Not the technical response — the customer-facing one. Support line, monitoring service, executive statement, regulatory notifications. If your organization hasn't rehearsed that, you're planning to write it under pressure, which is the worst possible time to write anything.

None of this requires a bigger security budget to start. It requires fifteen minutes on your next board or leadership agenda and a willingness to ask the uncomfortable version of the question.