cybersecurity

The Key Nobody Took Back

By The Most Secure Man Alive | WISECLICK Ambassador


On the second of July, by their own account, a stranger emailed the board of one of Australia's largest companies to tell them they were inside its systems. Then they emailed the security team. Then customer care. For almost three weeks, they claim, nobody wrote back.

I read a great many strange stories in my line of work. This one I read twice.

Because the strangest part of the Origin Energy data breach is not the silence. It is that the whole affair, if the reports are right, involved no hacking at all. No malware. No mysterious code. No hooded figure hammering on a firewall at three in the morning. Just a key. An ordinary key, in the shape of a login belonging to someone who no longer worked there, turned quietly in a door nobody thought to check.

I have said it for years: most breaches are not sophisticated. They are simply unattended. This week, the front page caught up.

Let me take you in.


Three weeks of silence

Origin Energy supplies electricity, gas and internet to roughly 4.8 million Australian accounts. On Wednesday it told the stock exchange it was looking into a potential security incident. By Thursday the word potential was gone: customer data had been accessed and disclosed. Names, addresses, dates of birth, phone numbers, account details. For some customers, a few digits of a card or bank account. Not enough to transact with. Remember that.

The story behind the story was stranger. The Australian newspaper had been corresponding with the person claiming responsibility, writing under the name Edison Walthour. Australian, by their own description. Two million records, by their own count. And their way in, by their own telling, was nothing you would call hacking: the login of a former Origin employee, reportedly still working after the person it belonged to had been let go. Three weeks inside the customer system, they claim. Three weeks of emails to the board, the security team, customer care. No reply.

Picture that inbox for a moment. On one side, a national newspaper. On the other, an anonymous person running a countdown website: publish in fourteen days. And in between, 4.8 million households paying their power bills, none the wiser.

On Friday, the countdown simply stopped. Website down. Settled privately, the person told the paper. Origin declines to comment. The federal police, one imagines, do not consider anything settled at all.

Hackers have a name for my own network. They call it "not worth it".

All of this is claimed, not proven. I am precise about that, because precise is what I am. What Origin has confirmed is the access, the disclosure and the apology, with the Australian Cyber Security Centre, the Australian Federal Police and the privacy regulator now in the room. The rest, the investigation will decide.

But the pattern underneath it, I can talk about all day. I have watched it play out in businesses of every size, and it has nothing to do with genius.

Nobody broke down the door. Somebody, reportedly, still had a key.


The ghost key

Every business keeps a drawer of keys. Not metal ones. Logins.

And logins have a strange property that metal keys do not: they are invisible. When a person leaves a job, their desk gets cleared, their laptop gets returned, their farewell card gets signed. Their seventeen logins drift on, unwatched, like lights left on in a house everyone has moved out of.

There is a fair chance you have one too. Most businesses do, whether it is a solo accountant, an electrician with two apprentices, or a consultant whose whole practice fits in a laptop bag. The web designer who built your site in 2022 and still holds the admin password. The bookkeeper who moved on in March, whose email never got switched off because everyone was flat out that week. The casual who knew the shared password to the accounting software, the same password it has been since the day it was set.

I call them ghost keys. Logins that belong to no one on the payroll, still opening doors nobody remembered to close.

Origin has thousands of staff, serious budgets and an entire security team. If the reports hold, one ghost key was enough. And here is the rhyme: it is the second time in nine months a departure has featured in an Origin data story. Last October, the company confirmed a different former employee had tried to email themselves the card details of 732 customers on the day their employment ended. Different incident, different person, same shape.

Big security budget or small, an old login remains an old login. The difference is that yours can be tidied by close of business today.

A quiet question to sit with: who was the last person to leave your business, and are you certain every one of their logins stopped working that day? If you paused just then, you are exactly who I wrote this for. The day somebody leaves is simply the day the keys get tidied. Routine, not drama.


Why I am telling you this calmly

If you are an Origin customer, take a breath before you take anything else. The partial payment details in this breach, four digits of a card, three digits of an account, cannot be used on their own to buy anything or reach your banking.

What stolen personal details are good for is theatre of a different kind. In the coming weeks, expect messages that look like Origin, sound like Origin, and know things about you that a stranger should not know. Your name. Your address. Perhaps your plan. Verify your details, they will say. Claim your refund. Click here. The breach was the first act. The impersonation attempts come next, and that is the act you get to cancel.

So step out of the script. Never judge the message, judge the channel. Close it, then go to Origin by a route you chose yourself: the official app, the website you type, the number printed on your bill. A genuine matter will still exist when you arrive. A scam evaporates the moment you stop using its link. The Australian Cyber Security Centre keeps plain-English guidance for data breach victims at cyber.gov.au, and it is the first place I would point anyone affected.

Pressure is a tactic, not a fact. A genuine company will still be there after you hang up and call back.


What I do about ghost keys

Now for the better half of the story: this is the most fixable problem in cybersecurity, and fixing it costs precisely nothing. Here is how I handle it in my own businesses.

First, I know who holds keys to the doors that matter: email, banking, accounting, cloud storage, the website, the socials. One simple list of who can reach each one. Ten quiet minutes with a cup of tea usually uncovers more than you expect. You cannot take back a key you have forgotten you handed out.

Second, when someone leaves, their keys leave with them, the same day. Farewell cake and tidied access can happen in the same afternoon; I have seen it done, and morale survived. That includes contractors and old suppliers, the most commonly forgotten of all.

In my own businesses, the access is gone before the farewell speech ends. Departing staff find it strangely flattering.

Third, I put a second lock on the important doors. Multi-factor authentication means a password on its own opens nothing, which turns every ghost key into a souvenir. The Australian Cyber Security Centre puts it near the top of its Essential Eight for good reason. Start with email, banking and accounting, one account at a time; each service walks you through it.

My own two-factor authentication has three factors. The third has never been disclosed.

Three quiet moves. No invoice attached to any of them.


Where to start

If this made you think of a former employee, a contractor or an old supplier who may still have access, start there, today. Old logins are one of several ordinary doors a business forgets it left open. The Ransomware Readiness Check finds the others: thirty minutes, plain English, built on the government's own Essential Eight, and no sales call afterwards. You finish with a clear view of what is already protected, what needs attention, and what to do first. Most owners find two or three gaps they did not know about, and every one of them is fixable.

Understand your exposure. Know what matters most.

See where you stand. 30 minutes. Plain English. $149.

Take the Ransomware Readiness Check →

Ghost keys are one door. The Check walks all eight.

The most secure businesses I know are not the ones with the biggest budgets. They are the ones with no ghost keys, a second lock on the doors that matter, and an owner who found all of this rather less complicated than the industry wanted them to believe.

Origin will finish its investigation. The agencies will do their work. And somewhere tonight, in a business much smaller than Origin, someone will read this, open a blank page, and quietly take back a key.

That person is going to sleep well tonight.

Stay protected, my friends.
— The Most Secure Man Alive


Frequently asked questions

What happened in the Origin Energy data breach?

Origin Energy confirmed to the ASX on 23 July 2026 that there had been unauthorised access to and disclosure of some customers' data. Media reports, based on contact with the person claiming responsibility, allege the access came through a former employee's still-active login rather than a technical exploit. Origin is working with the Australian Cyber Security Centre, the Australian Federal Police and the privacy regulator, and is contacting affected customers directly, which is exactly the response this kind of incident should receive.

What information was exposed in the Origin breach?

Origin says affected data may include names, addresses, dates of birth, phone numbers and account information, plus the last four digits of some credit cards or the last three digits of some bank accounts. The total number of affected customers had not been confirmed at the time of writing.

Can scammers use the last four digits of my credit card?

Not to make purchases or access your accounts. Partial numbers cannot be used to transact on their own. Their value to a scammer is persuasion: quoting real details makes a fake message feel genuine. Treat any message that quotes your details with the same healthy scepticism you would give one that does not.

I am an Origin customer. What should I do now?

Stay calm and go direct. Check any communication through the official Origin app, the website typed yourself, or the number on your bill, never a link or number inside a message. Turn on multi-factor authentication for your email and banking, and give your passwords a refresh if they are shared across accounts. Every one of these steps is well within reach of a non-technical person, and the Australian Cyber Security Centre publishes step-by-step guidance for data breach victims at cyber.gov.au.

How do I know if a message from Origin is genuine?

You do not have to know. That is the trick that makes this easy: never judge the message, judge the channel. Close the message and contact Origin through a channel you chose yourself. A genuine matter will still exist when you get there. A scam evaporates the moment you stop using its link.

What is a ghost key?

A login that outlives the person it was issued to: the former employee whose email still works, the web designer who still has your site's admin password, the shared password a departed casual still remembers. Ghost keys are one of the most common ways into a business precisely because nobody is watching them.

How do I stop ghost keys in my own business?

Three free moves: keep a simple list of who can reach your most important systems (email, banking, accounting, website, cloud storage, socials), remove access the same day someone leaves (contractors included), and switch on multi-factor authentication so an old password alone opens nothing. The Essential Eight, the Australian Signals Directorate's own priority list at cyber.gov.au, puts these controls front and centre.

Where can I check where my business stands overall?

The Ransomware Readiness Check walks you through it in about thirty minutes, in plain English, built on the government's Essential Eight, for $149 with no sales call afterwards. You finish knowing exactly where you stand and what matters most.


Get articles like this delivered to your inbox

 

Reading next

Leave a comment

This site is protected by hCaptcha and the hCaptcha Privacy Policy and Terms of Service apply.