1,205 Breaches, and the 59% That Were Attacks
Australia recorded 1,205 notifiable data breaches in the 2025 calendar year — an all-time high, and 8% up on the 1,112 recorded in 2024. Of those, 716 were attributed to malicious or criminal activity, which is 59% of the total.
Those are the OAIC’s own figures, from the scheme that requires organisations to notify when a breach is likely to cause serious harm. They are worth a few minutes of a business owner’s attention, mostly because the obvious conclusions drawn from them are usually the wrong ones.
What the numbers say
The headline distribution, from the regulator’s 2025 release:
| Measure | 2025 |
|---|---|
| Total notifications | 1,205 |
| Change on 2024 | up 8% (from 1,112) |
| Attributed to malicious or criminal activity | 716 (59%) |
And the sectors reporting the most:
| Sector | Notifications |
|---|---|
| Health services | 225 (19% of all) |
| Financial services | 157 |
| Australian Government | 118 |
| Business and professional associations | 103 |
| Education | 81 |
| Legal, accounting and management services | 81 |
Health has been the largest reporting sector for years running, and it is worth knowing why before drawing a conclusion from it.
Three readings these figures do not support
“Attacks are up, so the others are down.” The release gives one breakdown — malicious or criminal activity — and does not publish figures for human error and system fault alongside it. A 59% share tells you nothing on its own about whether the remaining 41% grew or shrank. If you want to say something about human error, you need the half-yearly report, not the headline.
“Health is the most attacked sector.” Health is the most reporting sector. Those are different claims, and the gap between them is regulatory: health providers hold sensitive information by definition, they are covered by the Privacy Act regardless of turnover, and their obligation to notify is triggered more readily than for many other organisations. Higher reporting can reflect a higher duty to report rather than a higher rate of being attacked.
“1,205 is the number of breaches in Australia.” It is the number notified under one scheme, by entities covered by that scheme. Small businesses under the $3 million turnover threshold are largely outside the Privacy Act, and therefore mostly outside these statistics, unless they trade in personal information, provide a health service, or are contracted to government.
That third point is the one that matters most to a small business, and it cuts in an uncomfortable direction — and for a large group of small businesses it stopped being true this year.
★ Insight ─────────────────────────────────────
If you are under the turnover threshold, you are not in this data — which means the 1,205 is not a measure of your risk, it is a measure of the risk among organisations large enough to be required to report. Your sector’s absence from the table is an artefact of who has to notify, not evidence that nobody in it is being breached. The only data about businesses your size comes from voluntary reporting, which is a floor, not a count.
─────────────────────────────────────────────────
The exemption is narrower than it was in July
The small business exemption still exists: an organisation with annual turnover of $3 million or less is generally not covered by the Privacy Act. It has been debated for years and it has not been repealed.
But the list of exceptions has grown, and one of them landed on 1 July 2026. The Privacy Act now applies to the personal information handling of entities that have become reporting entities under the anti-money-laundering regime’s second tranche — regardless of turnover.
Tranche 2 brings in a set of professions that are overwhelmingly small businesses:
- Real estate agents
- Conveyancers
- Accountants
- Lawyers
- Trust and company service providers
- Dealers in precious metals and stones
If you are in one of those, the sentence “we are under $3 million so the Privacy Act does not apply to us” is no longer correct for the work that falls under those obligations. And that brings the notifiable data breach scheme with it: the duty to assess a suspected eligible breach, and to notify if serious harm is likely.
This is worth checking rather than assuming, because the change was not framed as a privacy reform. It arrived through money-laundering legislation, so a practice watching for Privacy Act amendments would not have seen it coming.
What it does support
Three conclusions the figures genuinely carry.
The direction is up and has been for several years. An 8% year-on-year rise on an all-time high is not noise. Whatever your read on the composition, the trend across organisations that are obliged to report is not improving.
The majority of reported breaches involve someone trying. 59% attributed to malicious or criminal activity means the modal notified breach is not a misdirected email. The controls that matter against that majority — multi-factor authentication, patching, restricting who can reach what — are unglamorous and well known, and their absence is what these notifications keep describing.
The sectors at the top are the ones holding other people’s sensitive information. Health, finance, government, professional associations, education, and legal and accounting practices. The common factor is not size or industry glamour, it is custody of data about people who are not the organisation’s staff. If you hold client records, patient details, student information or financial data for other people, you are in the same category regardless of your headcount.
What a small Australian business should actually do
Not a security programme. Four things, in order of what they return.
1. Find out whether the scheme applies to you. Turnover above $3 million, a health service of any size, trading in personal information, a government contract, a credit or tax file number obligation, or reporting-entity status under the anti-money-laundering regime — any of these puts you in. If you are in, the obligation is to assess a suspected eligible breach expeditiously and within 30 days, and to notify if serious harm is likely. Finding that out during an incident is too late.
2. Turn on multi-factor authentication everywhere it exists. Email first, then anything holding customer data. The reported breaches attributed to attack are overwhelmingly reached through accounts, not exotic exploits, and this is the single control with the best ratio of effort to reduction.
3. Write down where personal information actually lives. Not a formal register — a list. Which systems hold data about your customers, who can reach each one, and what happens to it when someone leaves. Most businesses cannot answer this, and it is the first question asked in an incident.
4. Decide now who you ring. A breach at 4pm on a Friday is a decision-making problem before it is a technical one. One name, written down, that everyone knows.
The honest framing
These statistics are frequently used to sell security products, usually by implying they measure your exposure. They do not. They measure notified breaches among organisations required to notify, and the most useful thing in them for a smaller business is the sector table — because it identifies who is being targeted by the kind of data they hold, and that is a category you can check yourself against in about a minute.
If you hold sensitive information about other people, the relevant question is not whether 1,205 is a big number. It is whether you could answer, today, which systems hold that information and who can get to them.
Sources: OAIC, data breach notifications increase to all-time high in 2025 · OAIC, small business and the Privacy Act. This is general information, not legal advice — if you think the scheme may now apply to you, confirm it against the OAIC’s own guidance or with your adviser.
Cloud Geeks provides cybersecurity and managed IT for Australian small businesses. Websites come from Cosmos Web Tech, mobile apps from Awesome Apps, and the group is Ganda Tech Services.