

The OAIC highlighted the following key findings in its July – December 2022 Data Breach Report:
Almost half (45%) of the data breaches between July – December 2022 resulted from cyber security incidents. They were also the cause of most of the large-scale breaches we saw during this period.
The most common causes of breaches resulting from malicious or criminal attacks are:
Digging deeper into the source of cyber incidents, the OAIC revealed the most common causes of cyber incidents:

One of the most effective ways to manage your organisational cyber security risk is to collect the minimum amount of information and to ensure it is deleted when it is no longer required.
The Optus and Medibank breaches together impacted tens of millions of Australians. However, these were not the only large data breaches that were notified between July – December 2022. There was actually 67% increase in the number of breaches that impacted 5,000 or more Australians during this period.
It’s worth noting that there was also an increase in the number of large-scale breaches in the January – June 2022 period. If we look at the figures on a year-over-year basis, there has been a 100% increase in large-scale data breaches since 2021.
| Number of Australians affected by breaches | Jul-Dec 2021 | Jul–Dec 2022 |
| 5,001–10,000 | 8 | 12 |
| 10,001–25,000 | 7 | 8 |
| 25,001–50,000 | 2 | 6 |
| 50,001–100,000 | 2 | 4 |
| 100,001–250,000 | 0 | 2 |
| 250,001–500,000 | 0 | 2 |
| 500,001–1,000,000 | 0 | 1 |
| 1,000,001–10,000,000 | 1 | 5 |
| 10,000,000+ | 0 | 1 |
| Total number of breaches affecting over 5,000 Australians | 20 | 40 |
We all noted the reputational harm that came from Optus’ slow and poor communications about the large-scale data breach. However, as both the incidence of breaches and the sensitivity of the data being breached increase, timely notifications are expected by individuals – as well as the OAIC.
The OAIC was given increased powers under the Privacy Legislation Amendment (Enforcement and Other Measures) Bill in 2022 – including a new power to obtain information and documents relevant to an actual or suspected eligible breach. The OAIC may now enforce significantly higher penalties for serious breaches, too. So, from a regulatory risk perspective, Australian organisations now have a greater incentive to identify breaches and engage in timely notifications.
It’s worth noting that system fault breaches are generally detected more slowly than human error breaches or malicious/criminal attacks. In fact, one-third of system fault breaches were not identified for over one year (compared to 3% for malicious/criminal attacks and 4% for human error breaches).
Organisations should conduct a privacy impact assessment and an information security risk assessment to reduce the risk in this regard. It’s also important to implement technical measures to monitor and detect these breaches.
When more than one entity holds personal information that is breached, all the entities that hold the information have obligations under Australia’s Notifiable Data Breach scheme. And the number of organisations being affected by third-party vendor breaches is increasing.
There was a 91% increase in secondary notifications in July – December 2022.
We discussed third-party risk in a detailed blog post, but some quick takeaways are:
Our data breach management services include:
For assistance managing and securing your organisation’s data, reach out. Our privacy team would love to assist.
"*" indicates required fields
"*" indicates required fields
Privacy 108 collects your name and email to send you our newsletter. If you do not provide this information, we will be unable to send it to you. We may use third-party service providers (such as email marketing platforms) to distribute our communications. Some providers may store information overseas, including in the United States. For more information about how we handle your personal information, including how to access or correct it or make a complaint, please see our Privacy Policy or contact us at hello@privacy108.com.au. You can unsubscribe at any time using the link in our emails or by contacting hello@privacy108.com.au.