One of Australia's largest energy companies, Origin Energy, is investigating a potential security breach that may have affected customer data. An RMIT expert says the incident poses longer-term scam risks and highlights a growing need for quantum-safe encryption.
Associate Professor Nalin Arachchilage, School of Computing Technologies:
"Origin Energy says financial details weren't taken, but that shouldn't be read as 'nothing to worry about'. Names, addresses, account numbers and usage data are exactly the kind of information attackers use to build convincing scams - and increasingly, to profile a household for years to come, not just for the next billing cycle.
"With incidents like these, it isn't just what can be done with the data today - it's what can be done with it in ten years' time. We're seeing a growing pattern of 'harvest now, decrypt later' attacks, where adversaries steal encrypted data now simply to sit on it, betting that quantum computing will eventually be powerful enough to break the encryption protecting it.
"It's a bit like someone secretly recording every phone call you've ever made, even though they can't understand a word of it yet. They're not listening for what you're saying today - they're banking on inventing the ability to decode it later. When that day comes, years-old 'unreadable' data can suddenly become very readable.
"Critical industries like energy retailers hold exactly the kind of long-shelf-life data that makes 'harvest now, decrypt later' worthwhile for attackers - identity details, account histories, household patterns - that don't expire the way a stolen password does. Critical infrastructure and essential services need to be considered for post-quantum cryptography, not an afterthought.
"Australian organisations don't need to panic about quantum computers arriving tomorrow - but they do need to start planning today. Migrating to quantum-safe encryption takes years, and any sensitive customer data being stolen right now could still be sitting in an attacker's archive, when that migration should have already happened."
Associate Professor Nalin Arachchilage is a cyber security researcher at RMIT University.
***