Origin confirmed on 22 July that a breach had occurred. Its later updates put the number of current and former customers affected at around 900,000, with combinations of name, address, date of birth, contact details and partial payment card details exposed. About 60 customers had full bank account numbers exposed, about 100 had ID document numbers exposed and about 15,000 had concession numbers exposed. The breach was traced to a former Accenture employee at Origin’s Manila call centre, and the AFP and ACSC are involved.

On 17 August Quest Apartment Hotels detected unauthorised access to a database through what it called “a vulnerability through our third-party service provider”. Names, email addresses and contact details were exposed, along with dates of birth for a small number of records, all from before June 2025. Quest didn’t say how many guests were affected.

Different sectors, same pattern: the data left through someone the company trusted. For a small business that’s the bookkeeper, the payroll provider, the CRM, the marketing agency — and the IT provider. Keep a list of who can access what, give each the least access that works, remove it when the engagement ends, and ask each provider what they’d tell you, and how quickly, if they were breached.

What it means for your businessYour security includes every supplier who can see your data. List them, cut their access back to what they need, and put breach notification into the contract.
Source & referenceABC News — Origin Energy data breach impacts 900,000 customers ↑ABC News — Origin Energy hack update ↑The Register — Australian hotel chain leaks guest data after third-party breach ↑