Origin Energy Breach: Laundry Businesses Should Review Account Security Now
The Origin Energy breach involving unauthorised access to customer accounts has been confirmed, as reported in the Sydney Morning Herald this week. While details are still emerging, Australian laundry businesses using Origin should review account security and watch for unusual activity on bills. Updated 23 July 2026.
Laundromats and commercial laundry services carry higher-than-average electricity accounts, making them attractive targets if account credentials are compromised. Taking immediate precautions reduces the risk of unauthorised billing or account tampering.
What Origin has said
Origin has not yet disclosed the full extent of the breach, including how many accounts were affected or what specific data was accessed. The company is notifying affected customers directly and has advised all customers to monitor their accounts for unusual activity.
Energy retailer accounts hold names, addresses, contact details, and in some cases payment information or direct debit arrangements. If credentials (username and password) were compromised, attackers could alter account details, change payment methods or access billing history.
Immediate steps for laundry businesses
If your laundromat or laundry service uses Origin Energy, take these steps regardless of whether you’ve received a direct notification:
Change your password. Log into your Origin account and update your password immediately. Use a strong, unique password that you don’t use anywhere else. A password manager can generate and store this for you.
Review recent bills. Check your last three to six months of bills for any unusual charges, adjusted rates or unexplained account changes. If something looks wrong, contact Origin directly (using the number on their official website, not from an email).
Check payment methods. Verify that your linked bank account or credit card details are correct and haven’t been altered. If you use direct debit, confirm the scheduled payment amounts match your expected bills.
Enable multi-factor authentication if available. Some energy retailers now offer MFA on customer accounts. If Origin has this option, enable it to add an extra security layer.
Password reuse risk
If you used the same Origin password for other accounts (your business email, accounting software or other utility accounts), change those passwords too. Attackers routinely test breached credentials across multiple services to see what else they can access.
For small businesses, this can quickly escalate. If your Origin password matches your business email password, an attacker now has access to all email correspondence, password reset links for other accounts, and sensitive customer or financial information.
Password managers like Bitwarden, 1Password or LastPass eliminate the temptation to reuse passwords by generating unique credentials for every service.
Watching for follow-on phishing
Data breaches trigger phishing campaigns. Expect to see emails pretending to be from Origin asking you to “verify your account,” “update your details,” or “confirm your identity” by clicking a link.
Legitimate companies don’t ask for passwords via email. If you receive a suspicious email claiming to be from Origin, don’t click any links. Instead, go directly to Origin’s official website by typing the URL into your browser, then log in from there.
Laundromat operators should brief staff who have access to business email to be cautious about Origin-related messages over the coming weeks.
Bill monitoring: what to look for
Unusual billing patterns can indicate account tampering. Watch for:
- Bills significantly higher or lower than normal without a clear reason
- Changes to your tariff or pricing plan that you didn’t request
- New payment methods or altered bank account details
- Messages in your account inbox (if Origin offers one) that you didn’t send
If you spot anything suspicious, contact Origin immediately. Keep records of all correspondence in case you need to dispute charges or prove unauthorised changes were made.
Considering a switch
Some businesses may consider switching retailers after a breach. While no retailer is immune to security incidents, if Origin’s response leaves you concerned, you’re free to move to another provider.
Small business electricity contracts often have no lock-in periods or exit fees, especially if you’re on a standing offer or a contract nearing its end. Check your current contract terms before switching, and compare offers using Energy Made Easy or Victorian Energy Compare to ensure you’re getting a competitive rate.
Broader security practices
This incident highlights the importance of good credential management for all business accounts, not just energy retailers. Laundry businesses juggle multiple online accounts (utilities, suppliers, banking, equipment leasing), and each one is a potential target.
Consider a quarterly security review where you:
- Rotate passwords for critical accounts
- Remove unused or old user accounts from systems
- Review who has access to business email and financial accounts
- Check for software or firmware updates on payment terminals or booking systems
Local IT support providers can help set up password managers and security policies for small businesses if this feels overwhelming. Find laundry operators on our directory.
Frequently Asked Questions
Should I contact Origin if I wasn’t notified of the breach?
You can contact Origin to ask whether your account was affected, but they may not have complete information yet. Regardless, changing your password and reviewing recent bills is sensible as a precaution even if you weren’t directly notified.
Can attackers change my electricity tariff without my knowledge?
When they gain access to your account, yes. Retailers allow customers to switch tariffs online. While some changes require confirmation via email or phone, a compromised email account could allow attackers to approve changes. Monitor your bills for unexpected tariff shifts.
What’s the worst-case scenario for a compromised energy account?
An attacker with account access could change payment details to siphon funds, alter your tariff to a more expensive plan, or access personal information for identity theft purposes. While most breaches don’t result in direct financial theft, the risk of escalation to other accounts via password reuse is significant.
Are laundromats more at risk than residential customers?
Not necessarily, but laundromats have higher-value accounts (larger bills) and can be more attractive targets if attackers are looking for payment fraud opportunities. Business accounts also sometimes have weaker credential management because multiple staff members can share logins.
Sources: Sydney Morning Herald
By Laundry Services Near Me Team
Need a local listing?
Browse verified businesses in our directory or read more guides on the blog.
Find laundromats All guides