TechNewsReel
Live

Origin Energy breach linked to offshore Accenture employee in Manila

An investigation reveals a former contractor accessed customer records in a retaliatory strike against Australian offshoring.

TechNewsReel Newsroom · August 18, 2026

An investigation into a data breach at Origin Energy has identified an offshore Accenture employee based in Manila, Philippines, as the source of the leak. The incident underscores the growing security vulnerabilities associated with global outsourcing models.

According to the Australian Financial Review, the perpetrator accessed sensitive customer records and partial credit card numbers. Origin Energy has stated that the compromised credit card data is incomplete and cannot be used to access customer accounts. The individual involved has since left Accenture and claimed the breach was an act of revenge for the offshoring of Australian jobs.

The Regulatory Response

Origin Energy has notified the Australian Cyber Security Centre (ACSC) and the Australian Federal Police (AFP) regarding the incident. The company also engaged with the Office of the Australian Information Commissioner (OAIC) to manage the regulatory fallout. The AFP is currently leading the investigation into the breach.

This incident follows a series of high-profile data thefts in Australia, including major breaches at Optus and Medibank, which have put corporate data governance under intense scrutiny. Origin utilizes the cloud-based Kraken platform for its customer management, while Accenture, the consulting firm employing the perpetrator, has previously faced security-related litigation, including a 2019 suit from Marriott International customers concerning security controls.

The Cost of Outsourcing

The breach highlights the significant "insider risk" inherent in global outsourcing. While offshoring is often driven by cost-saving strategies, this event illustrates the resulting security gaps and the potential for disgruntled employees to weaponize their access.

Mohit Sharma, managing director of Mindfields Global, noted that this risk is inherent in processes outsourced to any location, including those within Australia. For energy providers, such breaches carry heavy reputational and regulatory risks, as noted by Moody's, particularly when customer trust is compromised in a critical infrastructure sector.

Looking Ahead

Origin CEO Frank Calabria stated that the company treats all threats seriously, though he noted that initial information had not led the company to conclude the threat was credible. As the AFP investigation continues, the industry will be watching for further evidence of how the access was granted and whether other outsourced partners are vulnerable to similar retaliatory insider attacks. It remains to be seen if the OAIC will levy fines or mandate specific changes to Origin's third-party vendor management protocols.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.