This week, customers of Origin Energy learned their personal details have been stolen in a data breach. They joined the customers of other major companies, including Qantas, Optus and Medicare, who have been hacked in recent years.Origin has some 4.8 million customers, making it the nation’s largest electricity and gas retailer, but the company has not confirmed how many people were affected. On Friday, a media outlet contacted by the alleged hacker reported he had agreed not to leak customer data after reaching an agreement with Origin.While Origin has yet to confirm any such agreement, customers should still be on guard for any suspicious calls, texts or emails. In the age of artificial intelligence (AI), these scams can look ever more convincing.What we know about the Origin ‘hack’ so farThe breach came to light earlier this week after the alleged hacker contacted The Australian newspaper, claiming to have accessed the records of two million Origin customers.Origin confirmed the data “may include name, address, date of birth, contact phone number and account information, as well as the last four digits of a credit card, or the last three digits of a bank account”. Some of those details, such as the last four digits of a credit card, may go further than previous breaches at Optus and Qantas, leading to hyper-targeted phishing campaigns. An example might be like this: “Your Credit Card ending in 1234 has been suspended due to suspicious activity. Click here (a malicious link) to verify.”How criminals can do more than before with AIThat extra personal information – beyond address, email and phone number – means criminals can build a more complete profile of potential victims.And with rapid advances in generative AI, scammers have access to more sophisticated tools and analysis to target individuals with highly personalised approaches.For instance, before ChatGPT or any of the other large language models, a hacker with access to two million records would have to spend a substantial amount of time analysing the data to come up with a phishing campaign.Now, they can instantly scan the records to find demographic data, for instance, targeting wealthy suburbs by postcodes to find clusters of people or particular individuals. Personal details could be combined with AI searches of social media posts to identify targets to gain the maximum benefit. Connecting the dots among victims’ names, mailing and email addresses, phone numbers and social media footprints help the hackers to narrow down their targets. Hackers are using AI to create fake documents that have even fooled the banks. Milan Jovic/Getty Images Hackers can also use leaked personal details to quickly build fake documents using AI. This could mean fake electricity bills demanding payments, or more sophisticated fake documents that have even fooled the major banks.Both Commonwealth Bank and National Australia Bank have said a flood of fraudulent home loan applications have used artificial intelligence tools to create fake payslips and other documents. Industry estimates put the total value of fraudulent mortgages across the four major banks above A$4 billion.The federal government passed legislation in February 2025 enforcing strict anti-scam obligations on banks, telcos and social media platforms. The scam prevention framework seeks to encourage organisations to stop scams before they happen. Those obligations, however, aren’t yet in force. Read more: Australia’s new scam prevention draft is welcome – but it needs to be broader in scope How to protect yourselfThe best advice, as after any hacking incident, is to be extra cautious.If you have direct debits set up with utilities, consider removing the bank details for now and paying bills manually each time.Be extra vigilant about any unexpected emails, texts or phone calls pretending to be from Origin, your bank or the government. Take your time in responding; scammers often bring a sense of urgency to their demands. If you receive a message claiming to be from Origin, don’t click any links or call the phone numbers provided. Instead, visit Origin’s official website or contact the company using details you already know are genuine.As of July 1, all text messages from government agencies and legitimate businesses will have a “Verified” note at the top of the message. This means scam text messages will show up under an “unverified” message thread, so always double check before you respond.Monitor your accounts and check for any unusual transactions. Larger transactions may be flagged or blocked by your financial institution.If you used the same password for your Origin account and any other online service, change those passwords immediately. Using a unique password for every account greatly reduces the impact of a data breach.Ensure you have multi-factor authentication on your financial accounts. While the extra step to receive a confirmation code may seem a hassle, it is also critical to preventing a hacker with some of your personal details accessing an account.We have to accept the fact we live in a world where these types of hacking, scamming and phishing incidents are going to be very common. It’s a trillion dollar industry for criminals that has been supercharged by AI. We all need to be more cautious than ever before.Abu Barkat Ullah received research funding from the Australian Government through the Cooperative Research Centres Projects (CRC-P) program for collaborative cyber security research.Mohiuddin Ahmed does not work for, consult, own shares in or receive funding from any company or organisation that would benefit from this article, and has disclosed no relevant affiliations beyond their academic appointment.