Our Take on the Updated Data Breach Reporting from the OAIC

Published
09 Sep 2026
Read time
5 min read
Category

Well, it looks like the Office of the Australian Information Commissioner’s data breach reporting dashboard hasn’t been quite as simple to keep updated as we’d all hoped. To jog your memory, last year, the OAIC announced it would be using a dashboard to report the data breach statistics bi-yearly. So far, it hasn’t been updated with the July-December 2025 (though there’s a note that it’s coming), and the January-June 2026 data is also not yet published. 

That said, the OAIC did share the July-December 2025 data on Australia’s Open Government website. We’ve teased out some of the key statistics from their spreadsheets to make it easier to read, and shared those alongside our insights. All data referred to herein is attributable to the OAIC from this spreadsheet, unless otherwise stated or linked. 

Executive Snapshot & Key Findings

  • 670 Total Data Breach Notifications were received by the OAIC between 1 July and 31 December 2025. This means that the total number of data breach notifications in the 2025 calendar year came to 1,205, a record year and an 8% increase over 2024. 
Bar graph showing the number of notifiable data breaches by month from July to December 2025, including the cause of the data breach
  • Top 5 Sectors between July-December 2025: Health Service Providers (128), Finance including Superannuation (83), Business/Professional Associations (72), Australian Government (51), and Personal Services (47).
  • Primary Source of Breaches in the latter half of 2025: Malicious or criminal attacks accounted for 63.9% (405 notifications), Human Error accounted for 30.6% (194 notifications), and System Faults accounted for 5.5% (35 notifications).
  • Cyber Incidents this period: 253 notifications (37.8% of all breaches) resulted directly from cyber incidents.
  • Scale of Data Breaches: 61.3% of data breaches affected 100 individuals or fewer worldwide. In other words, the bulk of data breaches were small in scale.
Horizontal bar graph showing the data breaches by scale of affected individuals between July to December 2025

Sector Related Data Breach Notification Insights and Statistics

There were changes to the categories reported this period that made it challenging to compare the number of data breaches across sectors to previous periods. In previous reporting, the OAIC broke the sectors into the following categories: 

  • Australian Government 
  • Education
  • Finance (including superannuation)
  • Health service providers 
  • Legal, accounting and management services 

This period, July-December 2025, we saw these categories: 

  • Health Service Providers – 128 Notifications
  • Finance, including superannuation  – 83 
  • Business/Professional Associations – 72 (this presumably includes legal, accounting and management services) 
  • Australian Government – 51 
  • Personal Services (including employment, childcare, vets) – 41

Using the data from the OAIC’s dashboard, we can see that the number of health provider related breaches jumped from 96 to 128, the Australian Government breaches decreased from 67 to 51, and finance related breaches increased from 72 to 83.

Digging into the types of data breaches each category saw, we can see that the bulk of breaches were malicious or criminal. This makes sense since malicious or criminal attacks remained the leading cause of data breaches, accounting for 63.9% (405 breaches), followed by Human Error at 30.6% (194 breaches) and System Faults at 5.5% (35 breaches). 

Bar graph showing the top five sectors by source of data breach, covering malicious, human error, system fault and other/unknown breaches

We found the disproportionate number of human error breaches across sectors interesting. Human error breaches were prevalent in the health services sector, with 39.8% of breaches stemming from human error in that sector. Personal services also notably saw more human error breaches than criminal/malicious breaches. It was the only sector to see that trend. 

In contrast, Business/Professional Associations reported virtually no human error breaches (only 3 of 72), with 88.9% (64 breaches) driven entirely by targeted malicious or criminal attacks.

What this shows us is that these errors are able to be minimised. Training and privacy-promoting processes and technologies are effective mechanisms that can be used to reduce the risk your organisation faces when it comes to human error breaches.

“Human error isn’t inevitable. Smart technology, clear processes, and continuous training turn human error from a major vulnerability into a preventable risk.”

Causes of Data Breaches in Australia

Similar to previous periods, malicious or criminal attacks were behind the bulk of data breaches in Australia between July-December 2025. Cyber incidents were the leading cause of malicious or criminal attacks, followed by social engineering, rogue insiders, and finally theft. 

A pie graph showing major breach sources and a bar graph showing the breakdown of malicious and criminal attack sources and the volume of breaches between July to December 2025

Human error breaches were responsible for 30.6% of breaches during this period. Here’s the breakdown by type for human error breaches. 

Human error194
Failure to use BCC when sending email10
Insecure disposal2
Loss of paperwork / data storage device12
PI sent to wrong recipient (email)66
PI sent to wrong recipient (mail)12
PI sent to wrong recipient (other)8
Unauthorised disclosure (failure to redact)12
Unauthorised disclosure (unintended release or publication)59
Unauthorised disclosure (verbal)13

Interestingly, Government agencies accounted for 22.9% (8 of 35) of all system fault breaches nationwide—primarily caused by unintended system releases or access permissions. 

The Types of Data Breached This Period

Contact information remained the most commonly breached type of data this reporting period, followed by identity information and financial details. Notably, there were just 2 data breaches involving Digital IDs.

A graph showing the kinds of personal information involved in breaches and the volume of data breached in each category. Contact info was the most frequently breached type of personal information

Health information was breached in 228 instances (compared to 537 for contact information). This number remains, in our opinion, too high – and it increased from the January-June 2025 period. Given the high number of human error breaches within this sector, it seems that organisations operating in this field are in need of improved processes, more training, and better privacy-preserving technologies. 

A Trend We Noticed: Notification Friction 

Across almost all sectors, organisations are becoming proficient at discovering breaches quickly. 64.3% of all breaches were identified within 10 days of occurring. However, only 21.0% were reported to the OAIC within 10 days of identification.

Graph showing the speed of identification of data breaches by sector

The OAIC recently published a “Quick reference guide for responding to data breaches” for reporting entities. It provides a helpful framework for identifying whether your organisation needs to report a data breach to the OAIC. 

You can find it here: https://www.oaic.gov.au/privacy/notifiable-data-breaches/quick-reference-guide-for-responding-to-data-breaches 

Or, for a downloadable tool, check out: https://www.oaic.gov.au/__data/assets/pdf_file/0028/265285/NDB-Self-Assessment-tool.pdf 

Ready to turn insight into action?
Connect with Privacy 108.

"*" indicates required fields

This field is for validation purposes and should be left unchanged.
Privacy 108 collects your name and contact details to respond to your enquiry and communicate with you about it. If you do not provide this information, we may be unable to respond. We do not disclose this information to third parties. For more information about how we handle your personal information, including how to access or correct it or make a complaint, please see our Privacy Policy or contact us at hello@privacy108.com.au.
Related articles
Subscribe to our Newsletter

"*" indicates required fields

This field is for validation purposes and should be left unchanged.

Privacy 108 collects your name and email to send you our newsletter. If you do not provide this information, we will be unable to send it to you. We may use third-party service providers (such as email marketing platforms) to distribute our communications. Some providers may store information overseas, including in the United States. For more information about how we handle your personal information, including how to access or correct it or make a complaint, please see our Privacy Policy or contact us at hello@privacy108.com.au. You can unsubscribe at any time using the link in our emails or by contacting hello@privacy108.com.au.