Australia’s Data Breach Risk Has Moved From Cyber Issue to Operating Risk

Australia’s latest Notifiable Data Breaches data should make boards and executives look beyond the usual cyber dashboard.

The Office of the Australian Information Commissioner reported that 2025 produced the highest annual number of data breach notifications since the NDB scheme began, with 1,205 notifications across the year — an 8% increase on 2024. OAIC also reported that malicious or criminal activity remained the dominant source of notifications, accounting for 716 breaches across the full year.

The OAIC’s latest data highlights that breach management remains a key governance and operational risk, not a background compliance task. Published on 6 July 2026, the OAIC release covers 2025 notifiable data breach statistics and provides a new quick reference guide and online checklist for entities covered by the Privacy Act.

It is relevant to businesses and Commonwealth government agencies with NDB obligations, especially where cyber incidents, customer data and operational disruption intersect. The release does not change the law, but it does sharpen the regulator’s expectations around how quickly and consistently organisations assess, notify and respond.

Board-Level Take

Across the second half of 2025, the uploaded OAIC dataset records 670 data breach notifications.

The volume was persistent, not episodic: July recorded 117 notifications, September 116, October 122, and December 117. August and November were lower, but still high at 99 notifications each.

The immediate signal is simple: the volume of breaches is rising, cyber hacking remains the main driver, and the OAIC is trying to make the response process easier to navigate under pressure.

For boards and executives, that means incident response should be treated as a core control environment issue, not just a privacy team workflow.

The second signal is reputational. The OAIC is publishing a practical guide at the same time as it highlights record notification numbers. That combination tells organisations the regulator is focused on both volume and execution quality.

Malicious attacks dominate, but this is not just a cyber story

In the July to December dataset, malicious or criminal attacks accounted for 405 notifications, or around 60% of the total. Human error accounted for 194 notifications, or around 29%.

That matters because too many organisations still frame breach readiness as a technical cyber control issue. The data says otherwise.

Cyber incidents are clearly central. The workbook records 253 cyber incidents as a specific source of breach. But it also records 88 social engineering or impersonation incidents, 66 cases where personal information was sent to the wrong email recipient, 59 cases of unintended release or publication, and 34 rogue employee or insider threat incidents.

That is a broader control story. It involves identity, access, email discipline, workflow design, vendor management, staff training, supervision, escalation and decision-making under pressure.

What the OAIC Is Really Signalling

Higher breach volume means higher governance pressure

The statistics show 1,205 notifications in 2025, up from 1,112 in 2024. The point for leaders is not the number alone, but what it says about operating conditions: more incidents, more assessments, more customer impact decisions and more board oversight required.

Risk and Compliance teams should assume that breach management will keep attracting attention from privacy, cyber and operational risk functions at the same time. That creates a coordination challenge that needs a clear owner.

Sector mix matters for challenge and benchmarking

The release identifies health service providers as the most commonly affected sector, with financial services, government and other professional sectors also appearing in the top group. For regulated institutions, that is useful context for benchmarking internal incident frequency and testing whether current controls are proportionate to actual exposure.

Boards should be asking whether their own reporting focuses on the right leading indicators, not just the count of serious incidents after the fact.

Impact profile is mixed and that makes it harder to govern

Most reported breaches in the July to December dataset affected relatively small groups of people. The workbook records 411 notifications affecting 100 or fewer people, and 546 affecting 1,000 or fewer.

That might sound comforting, but it should not.

Small breaches can still involve highly sensitive information. They can still trigger notification obligations. They can still reveal broken controls. And they can still erode confidence if handled poorly.

At the same time, the dataset also includes large-scale Australian-impact breaches, including three notifications affecting more than 100,000 Australians.

So the operating model has to handle both ends of the spectrum: high-volume smaller incidents and lower-frequency, high-impact events.

The new quick reference guide points to response timeliness and quality

The most concerning trend in the second-half dataset is not only what caused the breaches. It is how long notification took.

For malicious or criminal attacks, 213 of 382 notifications with usable timing data took more than 30 days to notify the OAIC. That is around 56%.

For system faults, 18 of 35 took more than 30 days. For human error, 70 of 192 took more than 30 days.

That tells us breach readiness is not just about prevention. It is about detection, escalation, assessment and decision-making.

The OAIC quick reference guide and interactive checklist help entities decide whether an assessment is required, whether to notify, and how to do so. In practical terms, the regulator knows organisations are often under time pressure when incidents occur and wants better decision support at the point of response.

The OAIC are also flagging that they believe not all entities are ensuring they notify or not, and in a timely manner.

That is an excellent cue for all organisations to test whether internal evidence would support a decision not to notify, to notify, or to escalate further. If the answer is you don’t know, then the control environment is not as strong as it should be.

Questions Boards and Executives Should Ask Now

  • Do we have a clearly owned notifiable data breach decision process that can operate under time pressure?
  • Would we be able to evidence why an incident did or did not meet the threshold for notification?
  • Are cyber, privacy, legal, communications and operational risk reporting using the same incident picture?
  • Do our metrics show leading indicators of breach risk, or only the number of breaches after they happen?
  • Have we aligned our response playbooks to the OAIC’s new quick reference guide and checklist?
  • Are we seeing repeat incidents or control failures that require a deeper root-cause review?

This Needs Attention Now

This is the wrong time to treat breach management as a static policy topic.

The OAIC’s publication shows that breach reporting remains active, visible and increasingly operational in nature.

Boards and executives should use the latest statistics as a prompt to review whether response arrangements, escalation triggers, evidence capture and post-incident learning are fit for a higher-volume environment.

Try our enterprise and operational risk tools to help you assess your risk maturity…click here > Risk Maturity Self Assessments

More from the Reading Room

Regulator sharpens the warning on facial recognition

The OAIC has updated its facial recognition guidance for APP entities using biometric technology in high-volume, publicly accessible retail spaces. The update reflects the ART’s March 2026 Bunnings decision and reinforces that each deployment needs…

Risk Maturity in Action: Turning Customer Promises into Reliable Outcomes

Two recent ASIC matters provide a useful opportunity to think differently about risk management. They can be read as stories about compensation, penalties and compliance...

APRA grants Revolut an ADI licence — a reminder that prudential entry standards still matter

APRA has granted an authorised deposit-taking institution (ADI) licence to Revolut. This is a substantive licensing decision and a current prudential development for boards, risk teams and governance functions watching new entrants into the banking…

The Qantas privacy finding: a positive lesson in third-party oversight

A serious data breach does not automatically mean governance failed. The more important question is whether an organisation can demonstrate that it understood the risks,...