Australian Cyber Security & Data Breach Statistics (2025)

The latest official data from the OAIC and the Australian Signals Directorate sourced, current, and explained in plain English.

Data breach notifications hit a record high

Australia recorded 1,205 notifiable data breach notifications in the 2025 calendar year a record since the Notifiable Data Breaches scheme began in 2018, and up 8% on 2024's 1,112 notifications. Most 59.4%, or 716 notifications were attributed to malicious or criminal activity rather than accidental causes.

Source: OAIC Notifiable Data Breaches Report, published 6 July 2026.

Which sectors reported the most breaches in 2025

  • Health service providers: 225 notifications (nearly 1 in 5 of all notifications the most reported sector)
  • Financial services: 157 notifications
  • Australian Government agencies: 118 notifications
  • Business and professional associations: 103 notifications
  • Education: 81 notifications
  • Legal, accounting and management services: 81 notifications

Note: these figures describe notification volume by sector, not the share of businesses in each sector that were attacked.

What's driving these breaches

In the most recent half-year reporting period (January–June 2025), 59% of breaches were attributed to malicious or criminal attacks and 37% to human error, with the average cyber incident during that period affecting just over 10,000 people. Contact information remains the leading type of personal data involved in breaches, ahead of identity, financial and health information.

The cost to Australian businesses

According to the ASD/ACSC Annual Cyber Threat Report 2024–25, Australian businesses reported an average cybercrime cost of $80,850 per report. Broken down by business size: small businesses averaged $56,600, medium businesses $97,200, and large businesses $202,700 per report. A cybercrime report is made in Australia about every 6 minutes, with 84,700 cybercrime reports received in FY2024–25.

What this means for your business

Every named sector in this data healthcare, finance, government, professional services, education, legal and accounting overlaps directly with the industries MicroCyber serves. The trend is upward, and the cost of a single incident regularly exceeds what most SMBs spend on prevention in a year.

Sources: OAIC Notifiable Data Breaches Report (oaic.gov.au); ASD/ACSC Annual Cyber Threat Report 2024–25 (cyber.gov.au). Last updated to reflect the 2025 calendar-year report published 6 July 2026.

See how MicroCyber protects businesses in these sectors