Australian government data
Real cyber incident data for Australian businesses
Every figure on this page is read live from official Australian sources — the OAIC's Notifiable Data Breaches dataset on data.gov.au, ACSC alerts and advisories, and Scamwatch reporting. No modelled counters.
Live from data.gov.au
Notifiable data breaches — 1 July 2025 to 31 Dec 2025
Six-monthly reporting period published by the OAIC under the Privacy Act 1988.
Data freshness
OAIC — Notifiable Data Breaches (data.gov.au)
Next check scheduled.
- Source last updated the dataset
- 29 June 2026, 16:01:16 AEST/AEDT
- 2026-06-29T06:01:16.291Z (UTC)
- Fast Emu last fetched the data
- 12 Sept 2026, 07:26:56 AEST/AEDT
- 2026-09-11T21:26:56.639Z (UTC)
- Next automatic refresh
- 12 Sept 2026, 07:56:56 AEST/AEDT
- 2026-09-11T21:56:56.639Z (UTC)
Source details and field mapping
Every number on this page is read directly from the OAIC Notifiable Data Breaches spreadsheet published on data.gov.au. Nothing is modelled or estimated.
- Dataset
- OAIC — Notifiable Data Breaches (NDB) scheme statistics
- Reporting period
- 1 July 2025 to 31 Dec 2025
- Dataset version in use
- NDB Data 1 July 2025 to 31 Dec 2025XLSX
- Version published
- 29 June 2026
Breach notifications this period
Caused by malicious or criminal attack
Sectors reporting the most breaches
Reported volume
Breach notifications received by month
Notifications the OAIC received each month in the current reporting period.
Root cause
How Australian breaches actually happen
OAIC-reported causes and their specific sources for the current period.
Human error
194- Failure to use BCC when sending email10
- Insecure disposal2
- PI sent to wrong recipient (email)66
- PI sent to wrong recipient (mail)12
- PI sent to wrong recipient (other)8
- Unauthorised disclosure (failure to redact)12
- Unauthorised disclosure (unintended release or publication)59
- Unauthorised disclosure (verbal)13
Malicious or criminal attack
405- Cyber incident253
- Theft of paperwork or data storage device30
System fault
35- Unintended access8
- Unintended release or publication27
- Unintended release or publication27
Sector exposure
Sectors reporting the most breaches
Top sectors by notification volume, broken down by cause.
Health service providers
128- Currently unknown2
- Human error51
- Malicious or criminal attack64
- Other6
- System fault5
Finance (incl. superannuation)
83- Currently unknown2
- Human error24
- Malicious or criminal attack52
- Other1
- System fault4
- Human error3
- Malicious or criminal attack64
- Other2
- System fault3
Australian Government
51- Currently unknown1
- Human error16
- Malicious or criminal attack25
- Other1
- System fault8
Personal services (incl employment, child care, vets)
47- Currently unknown2
- Human error22
- Malicious or criminal attack19
- Other3
- System fault1
Data at risk
Kinds of personal information exposed
- Contact information537
- Identity information386
- Financial details253
- Health information228
- Other sensitive information161
- Tax File Numbers151
- Digital ID information/documents2
Breach size
Individuals affected per breach
- 1161
- 2 - 1098
- 11 - 100152
- 101 - 1,000135
- 1,001 - 5,00055
- 5,001 - 10,00018
- 10,001 - 25,00011
- 25,001 - 50,0007
- 50,001 - 100,0007
- 100,001 - 250,0002
- 250,000 - 500,0000
- 500,001 - 1,000,0002
- 1,000,001 - 10,000,0003
- 10,000,001 or more1
- Unknown18
ACSC
Latest alerts and advisories
Published by the Australian Signals Directorate's Australian Cyber Security Centre.
Data freshness
ACSC — Alerts and advisories (cyber.gov.au)
Next check scheduled.
- Source last updated the dataset
- Not published by the source
- Fast Emu last fetched the data
- 12 Sept 2026, 07:26:55 AEST/AEDT
- 2026-09-11T21:26:55.747Z (UTC)
- Next automatic refresh
- 12 Sept 2026, 07:56:55 AEST/AEDT
- 2026-09-11T21:56:55.747Z (UTC)
Last error from the source: cyber.gov.au responded 520
Verify at the official sourcecyber.gov.au is currently refusing automated requests, so we can't mirror the advisories here. Read them directly at the source — the list is updated daily.
ACSC alerts and advisoriesOfficial sources
Where this data comes from
We only publish figures that trace back to an Australian government source you can verify yourself.
OAIC — Notifiable Data Breaches
Six-monthly breach statistics published as an open dataset on data.gov.au. Read live and parsed on our server for the charts above.
Open sourceACSC — Alerts and advisories
Australian Signals Directorate advisories on active threats, vulnerabilities and mitigations for Australian organisations.
Open sourceScamwatch — Scam statistics
National Anti-Scam Centre reported losses and scam volumes. Published as interactive dashboards and reports rather than an open API, so we link out.
Open sourceOAIC statistics cover breaches notified under the Privacy Act 1988 (Cth) and are published in six-monthly reporting periods, so they lag real time. Fast Emu does not alter the published figures.
Turn national breach data into your own risk picture
We map your exposure against the causes driving Australian breach notifications and build the detection and response cover to match.