What Australia’s latest data breach figures mean for your business

Australia recorded more notifiable data breaches in 2024 than in any year since mandatory reporting began. The Office of the Australian Information Commissioner (OAIC) received 1,113 notifications across the year, a 25% increase on 2023 and the highest annual total since the Notifiable Data Breaches (NDB) scheme commenced in February 2018. The numbers have not improved since: the first half of 2025 brought a further 532 notifications, with malicious attacks still accounting for the majority.
These figures matter for Queensland businesses of every size. The NDB scheme applies to any organisation covered by the Privacy Act 1988, and a breach notification is not simply a regulatory formality. It signals that personal information has been compromised in a way likely to cause serious harm to individuals. For the businesses we work with across Brisbane and South-East Queensland, understanding what is driving these numbers is the first step toward not becoming one of them. Our IT security assessment service is one practical way to find out where the gaps are before a breach does.
Malicious attacks remain the dominant cause
Malicious or criminal attacks continue to drive the majority of Australian data breach notifications. In the second half of 2024, they accounted for 69% of all notifications (404 incidents), with cyber security incidents, including phishing, compromised credentials, and ransomware, making up most of that group. Phishing was the single leading cause of notified cyber incidents in that period. Social engineering and impersonation attacks also rose sharply, up 46% in Australian Government alone compared to the prior six months.
The January to June 2025 period shows a slight shift in the mix. Malicious or criminal attacks remained the largest source at 59% of notifications (308 incidents), but human error rose significantly to account for 37% of all breaches, up from 29% in the prior period. That means more than one in three reported breaches now traces back to a mistake made by a person inside the organisation, not an external attacker. Both problems require attention, but they call for different responses.
The most common cyber attack methods targeting Australian organisations remain consistent:
- Phishing and credential theft, used as the initial entry point in most incidents.
- Ransomware, which is increasingly deployed after credentials are stolen rather than as the first stage of an attack.
- Social engineering and impersonation, including business email compromise (BEC) and invoice fraud.
- Brute-force attacks targeting accounts without multi-factor authentication (MFA).
For a practical breakdown of how phishing attacks reach your inbox and what to do about it, see our post on email cyber attacks and business risk. The ACSC’s Essential Eight framework sets out eight baseline controls specifically designed to reduce exposure to these attack types.
Health and finance sectors lead breach notifications
Australia’s health sector has topped the OAIC’s breach tables consistently since the NDB scheme began. In the second half of 2024, health service providers accounted for 20% of all notifications. Australian Government agencies came second at 17%, with the finance sector (including banks, superannuation funds, wealth managers, and consumer credit providers) also in the top three.
The reasons health and finance consistently rank highest are well documented. Health providers hold highly sensitive, long-lived data: Medicare numbers, diagnoses, prescriptions, and personal identifiers that cannot be changed if compromised. Many health IT environments are also fragmented, running older systems with limited security controls. Finance is a high-value target for credential stuffing, BEC, and fraud. Superannuation funds came under particular public scrutiny in early 2025 after a wave of credential-stuffing attacks targeted member accounts across the sector.
The pattern extends to professional services more broadly. Legal, accounting, and management services firms also feature regularly in OAIC breach data. These businesses hold sensitive client financial and personal information but often operate with smaller IT teams than large corporates. If your business is in any of these sectors, the risk profile is higher than the general average. Our IT support for professional services page covers how we approach security for firms in exactly this position.
Human error: the breach cause that training can fix
The jump in human error as a breach source in the first half of 2025 (up to 37% of all notifications) is worth examining separately. Misdirected emails, accidental disclosure, and misconfigured systems are not glamorous attack stories, but they account for a large share of reported incidents. The OAIC’s data consistently shows that these breaches are preventable.
The health sector, in particular, has historically shown a higher proportion of human error breaches than other industries. Staff handling large volumes of patient records under time pressure are more prone to misdirected emails, incorrect file sharing permissions, or failure to de-identify data before sending it externally. No amount of firewall investment fixes a misconfigured SharePoint folder or an email sent to the wrong recipient.
Practical steps that address human error alongside technical controls:
- Regular, scenario-based security awareness training, not just an annual video and quiz.
- Data classification and sensitivity labelling so staff understand what they are handling.
- Email security tools that flag external recipients and attachments before sending.
- Clear internal processes for reporting suspected breaches immediately.
Our post on security training that sticks covers what effective staff education looks like in practice. Technical controls matter, but behaviour is still a significant part of the picture.
What the OAIC data means for Brisbane SMEs specifically
At TTA, we see a pattern with smaller businesses across Brisbane and Queensland that the national statistics reflect but don’t always make obvious. Most of the businesses in the OAIC breach tables are not enterprise organisations with large security teams. Many are exactly the kind of 10-to-100 user businesses we support: medical practices, accounting firms, logistics companies, and professional services operations.
The majority of OAIC-reported breaches affected fewer than 100 individuals. That means the incident is unlikely to make national news, but it still carries legal reporting obligations and the potential for significant reputational and financial harm. Under Privacy Act amendments passed in recent years, penalties for serious or repeated breaches can reach $50 million or 30% of adjusted turnover, whichever is higher. The exposure is real even for a small organisation.
The practical implication: you do not need to be a large target to be breached, and you do not need a large budget to put effective controls in place. A security baseline built around multi-factor authentication, patched software, managed email filtering, and a tested backup process addresses the majority of the attack vectors that drive OAIC breach notifications. That is where we start with most clients before moving to more advanced controls. Our data security services page covers the layered approach we use.
The regulatory environment is tightening
The Cyber Security Act 2024 came into effect in late 2024, adding new obligations alongside the existing NDB scheme. Businesses with annual turnover above $3 million must now report any ransomware payment or cyber extortion payment to the Australian Signals Directorate (ASD) within 72 hours. This is separate from, and in addition to, the NDB notification obligations to the OAIC.
The OAIC has also signalled a more assertive enforcement posture. In December 2024, the regulator reached a landmark $50 million settlement with Meta over the Cambridge Analytica incident. It has accepted enforceable undertakings from Oxfam Australia and taken action over breaches at several other organisations. The expectation from the regulator is clear: prevent breaches, detect them quickly, and report them promptly. The OAIC’s Notifiable Data Breaches guidance sets out the current obligations in plain language.
A quick check for your business
Based on what the OAIC data consistently shows, here are five questions worth putting to your IT team or provider:
- Is MFA active on every account that can access sensitive data, including email and cloud applications?
- When did we last test our backup and recovery process under realistic conditions?
- Do staff know how to recognise a phishing attempt, and do they know who to call if they click one?
- Is our email security set up to flag or block unusual outbound data transfers?
- Do we have a documented process for assessing and reporting a potential data breach within 30 days?
If any of these questions draws a blank, that is the place to start. A formal IT audit can give you a structured answer across all five areas and prioritise what needs attention first.
Where do we go from here?
If the OAIC figures have raised questions about your own exposure, we are happy to walk through them with you. TTA works with businesses across Brisbane and South-East Queensland to put security fundamentals in place and build from there. A conversation costs nothing and often surfaces issues that are straightforward to fix. Get in touch with the TTA team to get started.



