OAIC statistics | Published 4 August 2026

Australian data breaches 2025 reached a record level. The Office of the Australian Information Commissioner received 1,205 notifications during the calendar year, up 8% from 1,112 in 2024.

The number matters, but the operational lesson matters more. Australian organisations need stronger identity controls, clearer data ownership, tested recovery and an incident process that works before staff are under pressure.

1,205notifications received by the OAIC during 2025
+8%increase from 1,112 notifications in 2024
716notifications attributed to malicious or criminal activity
82%of Australians concerned about data breaches in the 2026 ACAPS
Real 2026 photograph of the Leading Edge Data Centre in Wagga Wagga New South Wales
The Leading Edge Data Centre at the former CSU South Campus in Wagga Wagga, photographed in February 2026. Physical infrastructure is only one part of the identity, data and recovery chain businesses must manage. Photo: Robert Myers / Wikimedia Commons, CC BY-SA 3.0 AU. This real photograph does not depict one of the breaches reported to the OAIC.

What the OAIC's record figure actually tells us

The OAIC published the 2025 figures on 6 July 2026. Of the 1,205 notifications, 716 were attributed to malicious or criminal activity. That is about 59% of the reported total. The OAIC identified cyber hacking as the primary cause of reported breaches.

Health service providers recorded the highest volume, followed by financial services and Australian Government agencies. Professional organisations, education providers, legal firms, accountants and management services also appear prominently. These are sectors that routinely hold identity, health, financial, employment or commercially sensitive information.

The public confidence signal: the OAIC also reported that 82% of Australians were concerned about data breaches in the 2026 Australian Community Attitudes to Privacy Survey, up from 74% in 2023. Security controls now affect customer trust as well as technical risk.
Sector2025 notificationsShare or position
Health service providers22519% of all notifications; highest-volume sector
Financial services157Second-highest volume
Australian Government118Third-highest volume
Business and professional associations103Fourth-highest volume
Education81Equal fifth-highest volume
Legal, accounting and management services81Equal fifth-highest volume

A notification is not the same as every cyber incident

The 1,205 figure should be interpreted carefully. It counts notifications received under the Notifiable Data Breaches scheme. It is not a count of every phishing email, lost device, malware alert or unsuccessful attack in Australia.

Under the OAIC quick-reference guide, an eligible data breach generally involves unauthorised access, unauthorised disclosure or loss of personal information that is likely to result in serious harm, where remedial action has not removed that likely risk. Some small businesses are covered even when annual turnover is below $3 million, depending on their activities and the information they handle.

Do not read the league table as a simple measure of poor security. A higher notification count can also reflect the volume and sensitivity of data, attack pressure, better detection and stronger compliance. The useful question is whether your own organisation can detect, contain, assess and recover.
Real photograph of the NEXTDC P2 data centre in Perth Western Australia
NEXTDC's P2 data centre in Perth, photographed in March 2021. Real infrastructure still depends on correctly managed identities, applications, suppliers and recovery processes. Photo: Samuel Wiki / Wikimedia Commons, CC0 1.0. The image does not depict a reported breach.

Six changes Australian businesses should make in 2026

The response should not be another broad policy document that nobody uses. Each change below can be assigned to an owner, tested and evidenced. Together, they reduce the chance that a single stolen account, exposed device or supplier failure becomes a business-wide data event.

1. Treat identity as the front door

Email and cloud accounts hold customer information, invoices and reset links. A password alone is not a sufficient control.

  • Require strong MFA for staff and administrators
  • Separate daily and privileged accounts
  • Review dormant users, recovery methods and external access

2. Know which data deserves protection

A business cannot secure or notify accurately when nobody knows what information it keeps, where it lives or who can reach it.

  • Map customer, staff and financial information
  • Set owners and retention periods
  • Remove data that no longer has a business or legal purpose

3. Configure Microsoft 365 deliberately

Buying Microsoft 365 licences does not automatically configure Entra ID, Defender, device policies, sharing controls or audit visibility.

  • Review MFA and Conditional Access
  • Check admin roles and application consent
  • Inspect mailbox rules, external sharing and device compliance

4. Prove that recovery works

A successful backup job is not the same as a successful recovery. Test a real restore before an incident forces the question.

  • Define recovery time and recovery point expectations
  • Include cloud email and files in the plan
  • Record restore time, gaps and responsible owners

5. Prepare the NDB decision path

The OAIC guide sets out containment, assessment, notification and review. The technical team, management and privacy or legal advisers need a shared process.

  • Keep an offline incident contact list
  • Preserve logs and evidence
  • Know who assesses serious harm and approves communications

6. Test suppliers and support ownership

Cloud providers, software vendors and managed services can be part of the response. Contracts do not replace operational clarity.

  • Document who monitors and who responds
  • Confirm access removal and escalation paths
  • Test how suppliers provide logs, backups and incident updates

The Microsoft 365 gap: licences are not a security outcome

Microsoft 365 is often where Australian SMEs store email, identity, shared files, calendars and business conversations. The platform can support strong controls, but settings, licences and operational ownership still need to be reviewed.

A practical assessment should look at Entra ID sign-ins, MFA registration, legacy authentication, administrator roles, conditional access, risky application consent, Defender coverage, Intune enrolment, mailbox forwarding and SharePoint or OneDrive sharing. It should also ask how quickly a leaver loses access and whether a compromised account can be isolated without disabling the whole business.

The ASD Australian Cyber Security Centre recommends that small businesses start with MFA, software updates and backups. It also recommends an emergency plan and testing that plan. Those basics map directly to the weaknesses that turn a routine support issue into a damaging incident.

Real high resolution photograph of server racks inside a data centre
A directly photographed data-centre environment showing rack and cabling infrastructure. Photo: Carl Lender / Wikimedia Commons, CC BY 2.0. The photograph illustrates infrastructure and does not depict a breach reported to the OAIC.

Backups should be tested as a business process

Recovery is not only a storage question. A business may need to restore email, cloud files, server data, application settings, identity records and the documentation required to reconnect systems safely.

A useful recovery drill selects representative data, sets an expected recovery time, performs the restore and records what happened. It should identify missing data, slow transfers, inaccessible credentials, unclear ownership and any dependency that would delay staff returning to work.

The result is evidence: what was restored, from which backup, by whom, how long it took and what must improve. That evidence is more valuable than a dashboard showing only that last night’s job finished without an error.

A 30-day data breach readiness plan

Week 1: establish the baselineList important data, critical systems, administrators, cloud tenants, suppliers and current backup locations.
Week 2: close obvious access gapsEnforce MFA, remove stale accounts, separate administrator access and confirm offboarding responsibilities.
Week 3: run a recovery testRestore representative business data and document the time, result, problems and owner for each corrective action.
Week 4: exercise the response planWalk management, IT and advisers through containment, evidence, assessment, notification and customer communication.

The OAIC response model has four broad steps: contain the breach, assess the facts and risks, notify affected individuals and the OAIC when required, then review the incident. Organisations that only begin assigning these roles after an alert arrives lose valuable time. The ACSC incident-response guidance also recommends maintaining and testing a formal response plan.

Turn the statistics into one measurable next step

Not every business needs the same project. A 15-person professional firm may need an identity and Microsoft 365 review. A business with servers and line-of-business applications may get more value from a recovery drill. A growing organisation may need ongoing ownership across users, devices, patching, security alerts and suppliers.

Cybersecurity review

Check identity, endpoints, email, firewalls and incident ownership, then rank the work by real business risk.

Review cybersecurity posture

Microsoft 365 assessment

Review Entra ID, MFA, administrator roles, Defender, external sharing and device-management settings.

Assess Microsoft 365

Backup recovery drill

Restore representative Microsoft 365, server or business data and document recovery time, gaps and next actions.

Plan a recovery test

Managed IT consultation

Connect security work to onboarding, offboarding, devices, support tickets, patching and normal business operations.

Discuss the next practical step

Start with evidence, not assumptions

Compuloop can review the controls already in place, identify the highest-priority gaps and document a practical improvement path for an Australian business environment.

Book a data breach readiness reviewCall 1300 007 613

Sources and editorial notes

Editorial note: This article reports and explains official statistics. It does not claim that a notification proves a particular organisation had weak security, and the photographs do not depict breaches counted in the OAIC data. This is general technical information, not legal advice. Organisations should obtain legal or privacy advice for their specific obligations. AI-assisted tools were used during page production; statistics, links, captions and conclusions were checked against the cited primary sources before publication.