
The OAIC highlighted the following key findings in their January – June 2022 Data Breach Report:
The OAIC’s highlights revealed that 65% of breaches impacted fewer than 100 people – which is good news. However, we found their findings about the breaches impacting 5,000 or more people to be equally, if not more, significant.
There were 24 breaches that impacted the data of more than 5,000 Australians, up from 18 in July – December 2021. Of those 24 breaches:
These figures do not include the figures from the recent Optus and Medibank breaches. Those will be recorded in the OAIC’s July-December 2022 reporting, which will be released next year. (As an aside, we note that this report took much longer to publish than in the past. We query whether this shows that the OAIC is facing issues responding to the increasing sizes of data breaches in Australia.)
“23 of the 24 breaches that affected more than 5,000 Australians were caused by cyber incidents… Nine were ransomware incidents, 9 were due to compromised credentials, 3 were due to hacking and 2 were malware incidents.”
In other words, we had a higher number of breaches impacting a larger number of people. This is not a trend we want to see continue in Australia.
Organisations should be doing more to protect the personal information they hold against ransomware attacks, compromised credentials, and other cybersecurity incidents. While the exact steps each organisation should take to protect the data will vary depending on the volume and volatility of the data collected and stored, the measures implemented should be proportionate to the risk.
The OAIC noted that it received 100% more notifications of data breaches where more than one entity holds personal information subject to a breach. When organisations share data, the responsibility to keep that data safe is also shared.
It is crucial that organisations only share data with third parties they can trust. Read more about this in our previous coverage discussing questions to ask before sharing data with a third party.
In the OAIC’s press release about the report, Commissioner Falk stressed the importance of Australian organisations implementing data minimisation. She noted that the rising number of breaches impacting larger number of Australians indicated that organisations should reconsider the amount of data they collect, as well as how long they retain it for.

“I urge all organisations to review their personal information handling practices and areas of ongoing risk identified in our report. Only collect necessary personal information and delete it when it is no longer required.” – OAIC Commissioner Falk
For assistance managing and securing your organisation’s data, reach out. Our privacy team would love to assist.
"*" indicates required fields
"*" indicates required fields
"*" indicates required fields
Privacy 108 collects your name and email to send you our newsletter. If you do not provide this information, we will be unable to send it to you. We may use third-party service providers (such as email marketing platforms) to distribute our communications. Some providers may store information overseas, including in the United States. For more information about how we handle your personal information, including how to access or correct it or make a complaint, please see our Privacy Policy or contact us at hello@privacy108.com.au. You can unsubscribe at any time using the link in our emails or by contacting hello@privacy108.com.au.