

Well, it looks like the Office of the Australian Information Commissioner’s data breach reporting dashboard hasn’t been quite as simple to keep updated as we’d all hoped. To jog your memory, last year, the OAIC announced it would be using a dashboard to report the data breach statistics bi-yearly. So far, it hasn’t been updated with the July-December 2025 (though there’s a note that it’s coming), and the January-June 2026 data is also not yet published.
That said, the OAIC did share the July-December 2025 data on Australia’s Open Government website. We’ve teased out some of the key statistics from their spreadsheets to make it easier to read, and shared those alongside our insights. All data referred to herein is attributable to the OAIC from this spreadsheet, unless otherwise stated or linked.


There were changes to the categories reported this period that made it challenging to compare the number of data breaches across sectors to previous periods. In previous reporting, the OAIC broke the sectors into the following categories:
This period, July-December 2025, we saw these categories:
Using the data from the OAIC’s dashboard, we can see that the number of health provider related breaches jumped from 96 to 128, the Australian Government breaches decreased from 67 to 51, and finance related breaches increased from 72 to 83.
Digging into the types of data breaches each category saw, we can see that the bulk of breaches were malicious or criminal. This makes sense since malicious or criminal attacks remained the leading cause of data breaches, accounting for 63.9% (405 breaches), followed by Human Error at 30.6% (194 breaches) and System Faults at 5.5% (35 breaches).

We found the disproportionate number of human error breaches across sectors interesting. Human error breaches were prevalent in the health services sector, with 39.8% of breaches stemming from human error in that sector. Personal services also notably saw more human error breaches than criminal/malicious breaches. It was the only sector to see that trend.
In contrast, Business/Professional Associations reported virtually no human error breaches (only 3 of 72), with 88.9% (64 breaches) driven entirely by targeted malicious or criminal attacks.
What this shows us is that these errors are able to be minimised. Training and privacy-promoting processes and technologies are effective mechanisms that can be used to reduce the risk your organisation faces when it comes to human error breaches.
“Human error isn’t inevitable. Smart technology, clear processes, and continuous training turn human error from a major vulnerability into a preventable risk.”
Similar to previous periods, malicious or criminal attacks were behind the bulk of data breaches in Australia between July-December 2025. Cyber incidents were the leading cause of malicious or criminal attacks, followed by social engineering, rogue insiders, and finally theft.

Human error breaches were responsible for 30.6% of breaches during this period. Here’s the breakdown by type for human error breaches.
| Human error | 194 |
| Failure to use BCC when sending email | 10 |
| Insecure disposal | 2 |
| Loss of paperwork / data storage device | 12 |
| PI sent to wrong recipient (email) | 66 |
| PI sent to wrong recipient (mail) | 12 |
| PI sent to wrong recipient (other) | 8 |
| Unauthorised disclosure (failure to redact) | 12 |
| Unauthorised disclosure (unintended release or publication) | 59 |
| Unauthorised disclosure (verbal) | 13 |
Interestingly, Government agencies accounted for 22.9% (8 of 35) of all system fault breaches nationwide—primarily caused by unintended system releases or access permissions.
Contact information remained the most commonly breached type of data this reporting period, followed by identity information and financial details. Notably, there were just 2 data breaches involving Digital IDs.

Health information was breached in 228 instances (compared to 537 for contact information). This number remains, in our opinion, too high – and it increased from the January-June 2025 period. Given the high number of human error breaches within this sector, it seems that organisations operating in this field are in need of improved processes, more training, and better privacy-preserving technologies.
Across almost all sectors, organisations are becoming proficient at discovering breaches quickly. 64.3% of all breaches were identified within 10 days of occurring. However, only 21.0% were reported to the OAIC within 10 days of identification.

The OAIC recently published a “Quick reference guide for responding to data breaches” for reporting entities. It provides a helpful framework for identifying whether your organisation needs to report a data breach to the OAIC.
You can find it here: https://www.oaic.gov.au/privacy/notifiable-data-breaches/quick-reference-guide-for-responding-to-data-breaches
Or, for a downloadable tool, check out: https://www.oaic.gov.au/__data/assets/pdf_file/0028/265285/NDB-Self-Assessment-tool.pdf
"*" indicates required fields
"*" indicates required fields
Privacy 108 collects your name and email to send you our newsletter. If you do not provide this information, we will be unable to send it to you. We may use third-party service providers (such as email marketing platforms) to distribute our communications. Some providers may store information overseas, including in the United States. For more information about how we handle your personal information, including how to access or correct it or make a complaint, please see our Privacy Policy or contact us at hello@privacy108.com.au. You can unsubscribe at any time using the link in our emails or by contacting hello@privacy108.com.au.