Skip to main content

Australian government data

Real cyber incident data for Australian businesses

Every figure on this page is read live from official Australian sources — the OAIC's Notifiable Data Breaches dataset on data.gov.au, ACSC alerts and advisories, and Scamwatch reporting. No modelled counters.

Live from data.gov.au

Notifiable data breaches — 1 July 2025 to 31 Dec 2025

Six-monthly reporting period published by the OAIC under the Privacy Act 1988.

Data freshness

OAIC — Notifiable Data Breaches (data.gov.au)

Up to date

Next check scheduled.

Source last updated the dataset
29 June 2026, 16:01:16 AEST/AEDT
2026-06-29T06:01:16.291Z (UTC)
Fast Emu last fetched the data
12 Sept 2026, 07:26:56 AEST/AEDT
2026-09-11T21:26:56.639Z (UTC)
Next automatic refresh
12 Sept 2026, 07:56:56 AEST/AEDT
2026-09-11T21:56:56.639Z (UTC)
Verify at the official source

Source details and field mapping

Every number on this page is read directly from the OAIC Notifiable Data Breaches spreadsheet published on data.gov.au. Nothing is modelled or estimated.

Dataset
OAIC — Notifiable Data Breaches (NDB) scheme statistics
Reporting period
1 July 2025 to 31 Dec 2025
Dataset version in use
NDB Data 1 July 2025 to 31 Dec 2025XLSX
Version published
29 June 2026

670

Breach notifications this period

60%

Caused by malicious or criminal attack

4

Sectors reporting the most breaches

Reported volume

Breach notifications received by month

Notifications the OAIC received each month in the current reporting period.

July117
August99
September116
October122
November99
December117

Root cause

How Australian breaches actually happen

OAIC-reported causes and their specific sources for the current period.

Human error

194
  • Failure to use BCC when sending email10
  • Insecure disposal2
  • PI sent to wrong recipient (email)66
  • PI sent to wrong recipient (mail)12
  • PI sent to wrong recipient (other)8
  • Unauthorised disclosure (failure to redact)12
  • Unauthorised disclosure (unintended release or publication)59
  • Unauthorised disclosure (verbal)13

Malicious or criminal attack

405
  • Cyber incident253
  • Theft of paperwork or data storage device30

System fault

35
  • Unintended access8
  • Unintended release or publication27
  • Unintended release or publication27

Sector exposure

Sectors reporting the most breaches

Top sectors by notification volume, broken down by cause.

Health service providers

128
  • Currently unknown2
  • Human error51
  • Malicious or criminal attack64
  • Other6
  • System fault5

Finance (incl. superannuation)

83
  • Currently unknown2
  • Human error24
  • Malicious or criminal attack52
  • Other1
  • System fault4
  • Human error3
  • Malicious or criminal attack64
  • Other2
  • System fault3

Australian Government

51
  • Currently unknown1
  • Human error16
  • Malicious or criminal attack25
  • Other1
  • System fault8

Personal services (incl employment, child care, vets)

47
  • Currently unknown2
  • Human error22
  • Malicious or criminal attack19
  • Other3
  • System fault1

Data at risk

Kinds of personal information exposed

  • Contact information537
  • Identity information386
  • Financial details253
  • Health information228
  • Other sensitive information161
  • Tax File Numbers151
  • Digital ID information/documents2

Breach size

Individuals affected per breach

  • 1161
  • 2 - 1098
  • 11 - 100152
  • 101 - 1,000135
  • 1,001 - 5,00055
  • 5,001 - 10,00018
  • 10,001 - 25,00011
  • 25,001 - 50,0007
  • 50,001 - 100,0007
  • 100,001 - 250,0002
  • 250,000 - 500,0000
  • 500,001 - 1,000,0002
  • 1,000,001 - 10,000,0003
  • 10,000,001 or more1
  • Unknown18

ACSC

Latest alerts and advisories

Published by the Australian Signals Directorate's Australian Cyber Security Centre.

Data freshness

ACSC — Alerts and advisories (cyber.gov.au)

Refresh failed

Next check scheduled.

Source last updated the dataset
Not published by the source
Fast Emu last fetched the data
12 Sept 2026, 07:26:55 AEST/AEDT
2026-09-11T21:26:55.747Z (UTC)
Next automatic refresh
12 Sept 2026, 07:56:55 AEST/AEDT
2026-09-11T21:56:55.747Z (UTC)

Last error from the source: cyber.gov.au responded 520

Verify at the official source
Feed unavailable

cyber.gov.au is currently refusing automated requests, so we can't mirror the advisories here. Read them directly at the source — the list is updated daily.

ACSC alerts and advisories

Turn national breach data into your own risk picture

We map your exposure against the causes driving Australian breach notifications and build the detection and response cover to match.