Australia Cybercrime Statistics 2026 | Data Breaches, Stolen Credentials & Facts

Australia Cybercrime Statistics

Cybercrime in Australia 2026

Cybercrime continues to escalate across Australia in 2026, with official government reporting confirming that data breach notifications reached an all-time high last year and cybercrime reports continue arriving at a rate of roughly one every six minutes. The Office of the Australian Information Commissioner (OAIC) confirmed on July 6, 2026 that it received 1,205 data breach notifications during 2025 — the highest annual total since Australia’s Notifiable Data Breaches scheme began in 2018, and an 8% increase on the previous year. Just this week, the incident count grew further: Australian hotel operator Quest Apartment Hotels confirmed on Monday, August 17, 2026 that a vulnerability at a third-party database provider had exposed guest personal information, while a ransomware group calling itself Storm publicly claimed a separate attack on Victorian consultancy 3-Point Australia on August 13, 2026.

This report compiles the latest verified Australian government data — sourced directly from the Australian Signals Directorate’s Cyber Security Centre (ASD’s ACSC) and the OAIC — covering data breach notifications, cybercrime reporting volumes, credential theft, ransomware, and the sectors most affected as of this week. As of today, the ongoing stream of live incidents this month underscores what the official statistics already show: Australia’s cyber threat environment did not ease in 2026, with data breach notifications, credential-driven attacks, and third-party supply chain compromises all continuing to climb even as government reporting infrastructure and public awareness of disclosure obligations have both improved substantially since the scheme’s 2018 inception.

Interesting Cybercrime Facts and Latest Statistics in Australia 2026

Cybercrime Fact Category Latest Verified Figure
OAIC Data Breach Notifications, 2025 (All-Time High) 1,205
Year-on-Year Increase in Notifications 8%
Notifications Attributed to Malicious/Criminal Activity 716 (59%)
ASD Cybercrime Reports, FY2023–24 (via ReportCyber) 87,400+ — about 1 every 6 minutes
ASD Cyber Security Incidents Responded To, FY2023–24 1,100+
ASD Cyber Security Hotline Calls, FY2023–24 36,700+
Australians Concerned About Data Breaches (OAIC Survey, 2026) 82%, up from 74% in 2023
Average Cost of Cybercrime to a Large Australian Organisation $202,691 per incident

Data source: Office of the Australian Information Commissioner, Notifiable Data Breaches Report, 2025; Australian Signals Directorate, Annual Cyber Threat Report 2024–2025

These figures confirm that Australia’s cyber threat environment reached a genuine record level in 2025, one that current 2026 incidents suggest is continuing rather than easing. The OAIC’s 1,205 data breach notifications for 2025 represent the highest total recorded since Australia’s mandatory breach-reporting scheme began in 2018, with 716 of those notifications (59%) attributed directly to malicious or criminal attacks, and cyber hacking identified as the primary cause. Separately, the Australian Signals Directorate’s ACSC recorded more than 87,400 cybercrime reports through its ReportCyber portal in the 2023–24 financial year alone — a volume the ASD itself describes as roughly one report every six minutes — alongside more than 1,100 cyber security incidents requiring direct technical incident response.

Public concern has risen in step with the reported numbers: the OAIC’s 2026 Australian Community Attitudes to Privacy Survey found that 82% of Australians now rank data breaches as their top perceived privacy risk, up sharply from 74% in 2023. On the financial side, the ASD’s own Annual Cyber Threat Report pegs the average cost of a cybercrime incident to a large Australian organisation at $202,691, a figure that helps explain why boards and executives across the country have elevated cyber risk to a standing agenda item rather than treating it as a purely technical concern confined to IT departments.

OAIC Data Breach Notification Statistics in Australia 2026

Jul-Dec 2024............................ 595  (+15% on H1 2024)
Jan-Jun 2025............................ 532
2025 (Full Year, Record High).......... 1,205  (+8% year-on-year)
Reporting Period Data Breach Notifications
July–December 2024 595 (+15% vs. prior half)
January–June 2025 532
Full Year 2025 (Record High) 1,205
Year-on-Year Increase, 2025 vs. 2024 8%
Share Attributed to Malicious/Criminal Attacks (2025) 716 (59%)
Share Attributed to Human Error (H1 2025) 37%
OAIC Notifiable Data Breaches Scheme Commenced 2018

Data source: Office of the Australian Information Commissioner, Notifiable Data Breaches Reports, 2024–2026

The OAIC publishes Notifiable Data Breach statistics every six months, and the trend line across recent reporting periods shows a consistent upward trajectory. The July to December 2024 period recorded 595 notifications, itself a 15% increase on the first half of that year and, at the time, the highest six-month total since the scheme’s 2018 inception. That record was then comprehensively broken across the full 2025 calendar year, when the OAIC confirmed 1,205 total notifications — an 8% rise on 2024’s full-year figure and, notably, more than double what the scheme recorded in some of its earlier reporting years.

The composition of these breaches has shifted somewhat between reporting periods: while malicious or criminal attacks led notifications throughout 2025, accounting for 716 cases (59%), the January to June 2025 period specifically saw human error notifications jump to 37% of the total, a rise the OAIC has linked partly to organisations’ outsourcing of personal information handling to third parties, with the agency specifically flagging a case where supplier activity exposed private documents online. This third-party risk pattern is precisely what played out this month in the Quest Apartment Hotels incident, where the exposure originated not from Quest’s own systems but from “a vulnerability through our third-party service provider,” according to the company’s own customer notification — a textbook example of the supply-chain risk category the OAIC has been highlighting in its recent reporting.

ASD Cybercrime Reporting and Incident Response Statistics in Australia 2026

ReportCyber Cybercrime Reports, FY2023-24............ 87,400+
ASD Cyber Security Incidents Responded To............ 1,100+
ASD Cyber Security Hotline Calls..................... 36,700+
ASD Metric (FY2023–24) Figure
Total Cybercrime Reports via ReportCyber 87,400+
Average Reporting Frequency ~1 report every 6 minutes
Cyber Security Incidents Responded To 1,100+
Cyber Security Hotline Calls Received 36,700+
Joint AFP-ASD Operation Targeting Top-Tier Cybercriminals Operation Aquila
Cybercrime Reports From Individuals Majority of total reports

Data source: Australian Signals Directorate, Annual Cyber Threat Report 2024–2025, cyber.gov.au

The Australian Signals Directorate’s Cyber Security Centre (ASD’s ACSC) operates ReportCyber, the national online reporting portal through which individuals and businesses log cybercrime incidents, and its most recent Annual Cyber Threat Report confirms more than 87,400 reports were lodged during the 2023–24 financial year — a volume the ASD itself frames as roughly one report every six minutes, around the clock, across the entire year. Beyond intake, the ASD’s incident response teams directly handled more than 1,100 cyber security incidents, providing technical assistance to affected Australian entities, while its dedicated hotline fielded more than 36,700 calls from individuals and organisations seeking guidance or reporting active incidents.

To disrupt the most damaging actors behind this reporting volume, the ASD runs Operation Aquila, a joint standing operation with the Australian Federal Police (AFP) specifically tasked with identifying and disrupting the highest-priority cybercriminals targeting Australia — a recognition that a meaningful share of the country’s cybercrime volume originates from a comparatively small number of sophisticated, repeat-offending criminal groups rather than being evenly distributed across countless independent actors. The ASD explicitly recommends that any entity experiencing a cybercrime, cyber security incident, or discovered vulnerability report it directly through this channel, both to access technical incident response support and to feed the national intelligence picture that underpins operations like Aquila.

Stolen Credentials and Identity Fraud Statistics in Australia 2026

Phishing With Compromised Credentials (OAIC, Jul-Dec 2024)..... 84 notifications
Compromised/Stolen Credentials, Method Unknown................. 51 notifications
Identity Fraud — Top Reported Cybercrime Type, FY2024-25....... Confirmed by ACSC
Credential Theft Metric Figure
Phishing With Compromised Credentials (Jul–Dec 2024 Notifications) 84
Compromised/Stolen Credentials, Method Unknown 51
Top Reported Cybercrime Type, FY2024–25 (ACSC) Identity fraud
Notable Trend, FY2024–25 Service disruption (DoS/DDoS) rising sharply
Ransomware Presence in Incident Response Continues to appear regularly

Data source: OAIC Notifiable Data Breaches statistics; ASD’s ACSC cybercrime type reporting, FY2024–25

Credential theft and fraud remain among the most consistent themes running through Australia’s official cyber incident data. OAIC breach notification records from the July to December 2024 reporting period show 84 notifications specifically involving phishing attacks that led to compromised credentials, alongside a further 51 notifications where credentials were confirmed stolen or compromised but the precise method used by attackers could not be determined. The ASD’s own cybercrime-type reporting for FY2024–25 confirms identity fraud as the single top reported cybercrime type nationally, reinforcing that stolen personal and financial identifiers — rather than purely technical system exploitation — remain the most common entry point criminals use against Australian individuals and organisations.

The ASD also flags service disruption, particularly denial-of-service and distributed denial-of-service (DoS/DDoS) activity, as rising sharply within its most recent reporting period, alongside the continued regular appearance of ransomware in the agency’s incident response caseload. Together, this pattern — persistent credential-driven fraud, growing disruption attacks, and sustained ransomware activity — describes a threat landscape where attackers increasingly favour approaches that exploit human behaviour and existing access rather than relying solely on discovering novel technical vulnerabilities, a trend closely mirrored in the broader security challenges now emerging around autonomous AI systems, detailed further in the AI agent security statistics, where credential theft and identity-based attacks against non-human AI accounts have become one of the fastest-growing categories of enterprise risk globally.

Ransomware Statistics in Australia 2026

Australian Organisations Hit by Ransomware (Past Year)........... ~33% (1 in 3)
Organisations That Paid the Ransom, 2025 (Sophos)................. 41%
Organisations That Paid the Ransom, 2024 (Prior Year)............. 66%
Organisations Confident in Data Protection Despite Evidence....... 97%
Ransomware Metric Figure
Australian Organisations Hit by Ransomware in the Past Year ~33% (1 in 3)
Organisations That Paid the Ransom (Sophos State of Ransomware 2025) 41%, down from 66% the year before
Organisations Reporting a Data Breach in the Past 12 Months 1 in 5
Organisations Confident in Their Data Protection 97% — despite contrary evidence
Mandatory Ransom Payment Reporting Threshold Businesses with turnover over $3 million
Reporting Window Required Under Cyber Security Act 2024 Within 72 hours
Active Enforcement of Ransom Payment Reporting Began January 1, 2026

Data source: RSM Australia 2026 Cyber Security Report; Sophos State of Ransomware 2025; Cyber Security Act 2024, Australian Government

The RSM Australia 2026 Cyber Security Report, which surveyed business and IT leaders across 155 medium-to-large Australian organisations, found that roughly one in three organisations had been hit by ransomware within the past year, and one in five reported experiencing a data breach in the previous 12 months. Perhaps most striking is the confidence gap the report identified: 97% of surveyed organisations said they were confident in their ability to protect sensitive customer data, a figure RSM itself pointedly noted comes “despite contrary evidence” given the actual breach and ransomware rates the same survey uncovered.

On the response side, independent benchmarking from Sophos’s State of Ransomware 2025 report found that 41% of Australian organisations hit by ransomware chose to pay the ransom, a meaningful decline from 66% the year before — genuine, if modest, progress in resisting extortion demands. This shift comes as Australia’s regulatory framework around ransom payments has tightened considerably: since May 30, 2025, the Cyber Security Act 2024 has required organisations with turnover exceeding $3 million to report any ransom payment within 72 hours, and from January 1, 2026, the Department of Home Affairs moved from an education-first grace period into active enforcement, meaning organisations that quietly pay a ransom and stay silent now face a genuine legal risk rather than simply a compliance recommendation.

Sector-by-Sector Data Breach Statistics in Australia 2026

Health Sector — Share of 2025 Notifications............. 19%
Financial Services — Share of 2025 Notifications........ 14%
Australian Government Agencies — Share (H1 2025)........ 13%
Sector Share of Notifications
Health Service Providers 19% (2025 full year) — highest of any sector
Financial Services 14% (2025 full year) — second highest
Australian Government Agencies 13% (January–June 2025)
Sectors Reporting Rapid Recent Increases Professional services, retail, education
Average Cost of a Data Breach in Australia (Broader Estimates) Exceeding $3.35 million
Regulatory Penalties Under the Privacy Act (Maximum) Up to $2.22 million

Data source: OAIC Notifiable Data Breaches Report, 2025; Holding Redlich analysis of OAIC data, 2026

Consistent with prior reporting periods, health service providers recorded the highest volume of data breach notifications of any sector in 2025, accounting for 19% of the total, a pattern the OAIC attributes to the sheer volume of sensitive personal and medical information healthcare organisations hold combined with often-fragmented legacy IT systems across the sector. Financial services followed at 14%, while Australian Government agencies accounted for 13% of notifications during the January to June 2025 reporting period specifically — together, these three sectors have consistently occupied the top positions in OAIC sector breakdowns across multiple consecutive reporting periods, reflecting the concentration of high-value personal and financial data these industries handle.

Beyond the traditionally dominant sectors, analysts tracking OAIC publications note that professional services, retail, and education sectors are experiencing notably rapid increases in breach notification volume, suggesting cybercriminals are actively broadening their targeting strategy beyond the historically most-targeted health and finance industries. With the average cost of a data breach in Australia now exceeding $3.35 million, and regulatory penalties under the Privacy Act 1988 capable of reaching $2.22 million for serious or repeated non-compliance, the financial stakes of adequate data protection now extend well beyond the health and finance sectors that have traditionally borne the brunt of Australia’s reported cyber incidents, a trend that intersects directly with the country’s broader digital economy and population growth, detailed further in the population of Australia statistics, given how a growing, increasingly digitally-connected population expands the overall pool of personal data available for criminals to target.

Recent High-Profile Cybercrime Incidents in Australia 2026

Origin Energy Data Breach (Confirmed)................. Up to 2 million customer records claimed
Quest Apartment Hotels Breach (Aug 17, 2026).......... Pre-June 2025 guest records exposed
3-Point Australia Ransomware Claim (Aug 13, 2026)..... Passports and documents listed as eviden
Incident Key Detail
Origin Energy Data Breach Hacker claims access to records of up to 2 million customers
Quest Apartment Hotels Breach Confirmed August 17, 2026; third-party database vulnerability; records predate June 2025
3-Point Australia Ransomware Claim (Storm group) Publicly claimed August 13, 2026; passports listed as evidence
Data Exposed in Quest Incident Full names, email/contact details; small number of records include date of birth
UNSW Physics Website Attack (RipperSec) Claimed as part of an ongoing multi-nation campaign
Kairos Ransomware — Austin’s Financial Solutions 147 gigabytes of NSW wealth management firm data stolen and published

Data source: SecurityWeek; The Register; webberinsurance.com.au, List of Data Breaches and Cyber Attacks in Australia

Beyond the aggregate national statistics, individual incidents reported across 2026 illustrate the practical, ongoing nature of the threat documented in the ASD and OAIC data above. Origin Energy, one of Australia’s largest energy retailers, confirmed a data breach after a hacker claimed to have stolen the records of up to 2 million customers and threatened to leak the data. More recently, Quest Apartment Hotels — one of Australia’s largest hotel chains — told affected guests on Monday, August 17, 2026 that it had “identified unauthorised access to a database system and immediately took steps to contain the incident,” with the company confirming the breach “arose from a vulnerability through our third-party service provider” rather than Quest’s own core systems, exposing guest full names, email and contact details, and, in a small number of cases, dates of birth.

Just days before that disclosure, the ransomware group Storm publicly claimed responsibility on August 13, 2026 for an attack against 3-Point Australia, a Victorian project management consultancy, listing stolen passports and other documents as proof of the exfiltration — an unconfirmed claim as of this report but one consistent with the broader pattern of ransomware groups using stolen identity documents as leverage seen throughout 2025 and 2026 Australian incidents. Other notable 2025–26 cases include a RipperSec-claimed attack on a University of New South Wales physics department website, part of an ongoing campaign the group has run against multiple nations, and a ransomware incident against NSW wealth management firm Austin’s Financial Solutions, in which the Kairos group stole and published 147 gigabytes of client data — together painting a picture of a threat landscape spanning critical infrastructure, hospitality, professional services, and education alike, a pattern of expanding financial exposure that sits alongside Australia’s other major fiscal pressures documented in the Australia national debt statistics, as government agencies balance cyber defence investment against a broader $1 trillion-plus national debt position.

Public Trust and Consumer Response Statistics in Australia 2026

Australians Concerned About Data Breaches (2026)................. 82%
Australians Concerned About Data Breaches (2023)................. 74%
Adults Who Would Pause/Stop Spending After a Brand's Breach...... Majority
Public Trust Metric Figure
Australians Ranking Data Breaches as Top Privacy Risk (2026) 82%
Same Figure in 2023 74%
Increase Over 3 Years +8 percentage points
Australians Who Would Pause or Stop Spending With a Breached Brand Majority of surveyed adults
OAIC Survey Name Australian Community Attitudes to Privacy Survey
Latest Survey Edition 2026

Data source: OAIC, Australian Community Attitudes to Privacy Survey, 2026

The OAIC’s Australian Community Attitudes to Privacy Survey provides the clearest available window into how ordinary Australians perceive the risks documented throughout this report, and the 2026 edition confirms that data breaches are now the single top perceived privacy risk for Australians, with concern climbing from 74% in 2023 to 82% in 2026 — an increase that closely tracks the parallel rise in actual reported notification volumes over the same period. This alignment between rising public concern and rising official breach statistics suggests Australians are responding rationally to genuinely worsening real-world conditions rather than reacting to media coverage alone, since the OAIC’s own notification data confirms the underlying incident rate has, in fact, climbed substantially across the same three-year window.

That elevated concern is translating into real commercial consequences for breached organisations: OAIC research consistently finds that a majority of Australian adults say they would either pause or completely stop spending with a brand or organisation following a reported hack or data breach, a behavioural response that gives commercial weight to what might otherwise be treated as a purely regulatory or reputational concern. As the OAIC itself has noted, “how an organisation prepares for, manages and communicates during a privacy incident affects public confidence, stakeholder relationships and reputation,” meaning entities covered by the Privacy Act increasingly need to treat data security not merely as a compliance obligation but as a core commercial risk directly tied to customer retention and long-term brand trust — a dynamic that will only intensify as Australia’s population continues its rapid, migration-driven growth documented in the population of Australia statistics, expanding the pool of consumers whose data organisations must adequately protect.

Disclaimer: This research report is compiled from publicly available sources. While reasonable efforts have been made to ensure accuracy, no representation or warranty, express or implied, is given as to the completeness or reliability of the information. We accept no liability for any errors, omissions, losses, or damages of any kind arising from the use of this report.