Data Breach Statistics in Australia 2026
Data breach statistics in Australia in 2026 paint a picture of a country whose exposure to cybercrime has escalated dramatically even as its regulatory response has matured significantly. In the first three months of 2026 alone, an estimated 1.1 million Australian accounts were exposed in data breaches, placing Australia 15th globally by breach volume for a country of just 26 million people. This came against a global backdrop where Q1 2026 saw 210.3 million breached accounts worldwide — three times higher than the same period in 2025 — confirming that Australia’s own escalating breach rate is part of a much larger global surge rather than an isolated national problem.
This report compiles the key verified statistics on data breaches in Australia in 2026, covering the Office of the Australian Information Commissioner’s (OAIC) Notifiable Data Breaches scheme, major recent incidents affecting companies like Qantas and Origin Energy, sector-by-sector breach patterns, and the country’s tightening regulatory response under the Cyber Security Act 2024. Sources include OAIC official reporting, the Australian Signals Directorate’s Annual Cyber Threat Report, Surfshark’s quarterly breach analysis, and independent cybersecurity research firms. Because Australia’s official OAIC reporting and independent breach-tracking firms use different measurement methodologies and reporting periods, this article notes each figure’s specific source.
Interesting Facts About Data Breaches in Australia 2026
| Fact Category | Key Data Point |
|---|---|
| Australian accounts exposed, Q1 2026 (Surfshark) | ~1.1 million |
| Australia’s global rank by breach volume (Q1 2026) | 15th globally |
| Global breached accounts, Q1 2026 | 210.3 million — 3x higher than Q1 2025 |
| Cumulative Australian accounts leaked since 2004 | ~207.2 million (Surfshark) — for a population of 26 million |
| Cumulative Australian email identifiers breached since 2004 (Corbado) | ~37 million — roughly 13 accounts compromised per minute |
| OAIC data breach notifications, July–December 2024 | 595 — highest single reporting period since the scheme began in 2018 |
| OAIC data breach notifications, January–June 2025 | 532 — down 10% from the record prior period |
| Share of H1 2025 breaches from malicious/criminal attacks | 59% (308 of 532 notifications) |
| Average individuals affected per cyber incident (H1 2025) | Just over 10,000 |
| Australian businesses breached at least once in the past year (Cloudflare) | 41% |
| Australian businesses reporting 11+ breaches in the past year | 33% |
| Origin Energy customers affected by July 2026 breach | ~900,000 |
| Qantas customers affected by 2025 breach | Up to 6 million |
Source: Surfshark Quarterly Breach Analysis; Office of the Australian Information Commissioner (OAIC) Notifiable Data Breaches Report; Cloudflare Australia business survey; Corbado data breach research, 2024–2026
The numbers above confirm that Australia’s data breach exposure has entered a genuinely new phase of severity. The jump to 210.3 million globally breached accounts in Q1 2026 alone — three times the equivalent 2025 figure — suggests the entire global threat landscape shifted sharply upward heading into 2026, and Australia’s own 1.1 million exposed accounts in the same quarter kept it firmly in the top 15 most-breached nations worldwide, a ranking it has now held consistently across multiple reporting periods. For context on the sheer accumulated scale, the 207.2 million total Australian accounts leaked since 2004 works out to roughly eight breached accounts for every Australian resident when measured cumulatively — though this figure counts repeat exposures of the same individuals across multiple incidents rather than 207 million unique people.
What stands out most is the maturing regulatory detection infrastructure running in parallel with the worsening breach volume: the OAIC’s 595 notifications in the second half of 2024 represented the highest six-month total since Australia’s Notifiable Data Breaches scheme began in 2018, and while the following period showed a 10% decline to 532 notifications, officials have been careful to frame this as reflecting improved organizational detection and reporting maturity rather than a genuine reduction in underlying attack volume — especially given that malicious and criminal attacks still accounted for 59% of all reported breaches in that same period.
Australia’s OAIC Notifiable Data Breaches Scheme 2026
OAIC DATA BREACH NOTIFICATIONS — RECENT REPORTING PERIODS
════════════════════════════════════════════════════════════════════
Jul–Dec 2024 ████████████████████████████████████████ 595 (record high)
Jan–Jun 2025 ███████████████████████████████████░░░░░ 532 (-10%)
════════════════════════════════════════════════════════════════════
Malicious/criminal attacks: 59% of all H1 2025 notifications
| NDB Scheme Metric | Data Point |
|---|---|
| Reporting period covered by latest report | January–June 2025 |
| Total notifications received | 532 |
| Change vs. previous 6-month period | -10% |
| Previous period’s notification total (Jul–Dec 2024) | 595 — record high since scheme inception |
| Share of breaches caused by malicious/criminal attacks | 59% (308 notifications) |
| Average individuals affected per cyber incident | Just over 10,000 |
| Top sector by breach volume: Health | 18% of reported breaches |
| Second sector: Finance | 14% of reported breaches |
| Third sector: Australian Government agencies | 13% of reported breaches |
| NDB scheme commencement year | 2018 |
| New reporting format introduced (2025) | Interactive dashboard, replacing static PDF reports |
Source: OAIC “Latest Notifiable Data Breach statistics for January to June 2025”; Australian Cyber Security Magazine; Pinsent Masons legal analysis of the OAIC dashboard launch, 2025
The OAIC’s shift to an interactive dashboard format for its January–June 2025 report marks a genuine change in how Australia’s data breach statistics are communicated, replacing the previous roughly 40-page static PDF documents with a tool that allows organizations, media, and the public to explore and benchmark breach data directly. This transparency push comes as the underlying numbers remain stubbornly elevated: even with the 10% decline to 532 notifications, this period still sits well within the “heightened levels seen throughout 2024,” according to the OAIC’s own characterization, rather than representing any meaningful return to pre-2024 baseline levels.
The sector breakdown — with health leading at 18%, followed by finance at 14% and government agencies at 13% — reflects where Australia’s most sensitive and valuable personal data concentrates. Healthcare providers hold medical histories, government identification numbers, and insurance details that carry both high resale value on criminal marketplaces and severe personal consequences for victims when exposed, which likely explains why this sector has consistently topped or near-topped OAIC’s sectoral breakdown across multiple reporting periods rather than being a one-off anomaly.
Major Australian Data Breaches 2026
| Company / Incident | Scale and Details |
|---|---|
| Origin Energy (July 2026) | ~900,000 current and former customers had data accessed; breach initially assessed as not credible in early July before being confirmed July 22 |
| Qantas (2025) | Up to 6 million customers affected via a call centre system compromise; names, emails, phone numbers, birth dates, frequent flyer numbers exposed |
| youX (2026) | 444,000 Australians affected; data exposed via mortgage and car finance broker referrals; unsecured database exposed for at least 10 months before discovery |
| Eurail (early 2026) | Australia is Eurail’s second-largest market after the US; stolen data sold on dark web and Telegram by early March |
| Hertz (Oct–Dec 2024, disclosed 2025) | Customer personal data and driver’s license details stolen via a third-party vendor breach |
| The Fullerton Hotel Sydney | 148 gigabytes of data stolen, including passports and driver’s licenses of hotel guests |
| Historical reference: Medibank and Optus | Cited repeatedly as the benchmark incidents that shaped Australia’s current regulatory response |
Source: Insurance Journal reporting on Origin Energy, July 28, 2026; Packetlabs “Major Cyber Breaches in Australia” compilation; Webber Insurance Data Breaches List; arnav.au Australian Data Breaches and Incidents analysis, 2025–2026
The Origin Energy breach, disclosed just days before this report was compiled, illustrates a recurring and troubling pattern in Australia’s recent breach history: the company initially assessed a possible threat in early July 2026 as not credible, only for new information on July 22 to confirm a genuine breach had occurred — a detection delay that meant the company’s own systems failed to recognize a real threat on first assessment. This pattern of delayed recognition echoes the youX incident, where an unsecured database sat exposed for at least 10 months before discovery, exposing 444,000 Australians whose data had been passed to the platform indirectly through mortgage and car finance brokers who had no direct relationship with the affected individuals.
The Qantas breach affecting up to 6 million customers remains one of the most consequential incidents of the current wave, not for its technical sophistication but for its method: attackers compromised a call centre system rather than exploiting a software vulnerability, exposing names, contact details, birth dates, and frequent flyer numbers — data combination valuable enough for identity theft and highly targeted follow-up phishing campaigns. Together with Optus and Medibank, cited throughout industry analysis as the incidents that fundamentally reshaped Australia’s regulatory posture, these breaches form a continuous chain of major-brand incidents that has kept data breach risk squarely in Australian public consciousness since 2022.
Australia’s Cyber Security Regulatory Response 2026
AUSTRALIA'S TIGHTENING REGULATORY TIMELINE
════════════════════════════════════════════════════════════════════
2018 NDB scheme commences — 41%
2022 Optus and Medibank breaches — regulatory catalyst
2024 Cyber Security Act 2024 passed
2025 OAIC dashboard launched; 72-hour ransomware reporting mandate active
2026 Q1: 210.3M global accounts breached — 3x YoY increase
════════════════════════════════════════════════════════════════════
| Regulatory Metric | Data Point |
|---|---|
| Governing legislation for mandatory reporting | Cyber Security Act 2024 |
| Ransomware/extortion payment reporting threshold | Businesses with annual turnover above $3 million |
| Reporting deadline for ransomware payments | Within 72 hours to the Australian Signals Directorate |
| REDSPICE program | Government investment doubling ASD’s size and cyber-strike capability |
| NDB scheme notification requirement basis | Privacy Act 1988 |
| Average daily cybercrime reports (historical ACSC benchmark) | ~164 reports per day — about one every 10 minutes |
| IBM global average data breach cost (2025) | $4.44 million — down 9% from 2024’s $4.88 million |
| IBM US average data breach cost (2025), for comparison | $10.22 million — a record high |
Source: Cyber.gov.au Annual Cyber Threat Report 2024-2025; Cyber Security Act 2024 official text; IBM Cost of a Data Breach Report 2025; UpGuard Australian Data Breach Statistics, 2025–2026
Australia’s Cyber Security Act 2024 represents the country’s most significant legislative response yet to the sustained wave of major breaches since 2022, introducing a mandatory 72-hour reporting window for ransomware and cyber extortion payments made by businesses with annual turnover above $3 million. This threshold captures a substantial share of Australia’s mid-to-large business sector while exempting the smallest operations from what would otherwise be a significant compliance burden, reflecting a regulatory balancing act between transparency and practical enforceability.
The government’s parallel investment in Project REDSPICE, which doubles the Australian Signals Directorate’s size and its capacity to conduct offensive cyber operations against malicious actors, signals a shift beyond purely defensive posture toward active disruption of the criminal infrastructure targeting Australian organizations. Whether this expanded capability translates into a measurable reduction in breach volume remains to be seen in future reporting periods, particularly given that Australia’s breach exposure has continued climbing through Q1 2026 even as these regulatory and capability investments have come online. For readers interested in how these same AI-driven and social-engineering attack techniques are playing out at a much larger scale in the world’s biggest economy, our Phishing Statistics in US report documents that US phishing-related losses grew 208% in a single year, reflecting a global pattern of attacks becoming dramatically more effective even where raw volume has plateaued.
Credential Theft and the Dark Web Connection 2026
| Credential/Dark Web Metric | Data Point |
|---|---|
| Global stolen credentials circulating (2022 baseline) | Over 15 billion — up 82% year-over-year |
| Active cybercriminals using dark web-sourced data in attacks | 65% globally |
| Share of email addresses estimated leaked to the dark web | ~80% globally |
| Credential stuffing role in Australian breaches | Increasingly fuels attacks, per Corbado 2026 analysis |
| youX and Eurail data | Both confirmed sold/posted on dark web marketplaces and Telegram in 2026 |
| Dark web annual illicit marketplace revenue (global) | ~$1.5 billion |
| Compromised credit card details on dark web (global, 2022) | ~60 million |
Source: Market.us Dark Web Statistics; PrivacySavvy Dark Web Statistics 2026; arnav.au Australian Data Breaches analysis, 2025–2026
The connection between Australia’s rising breach rate and the broader global credential-theft economy is direct and well-documented: both the youX and Eurail incidents affecting Australian consumers in 2026 saw stolen data specifically routed onto dark web marketplaces and Telegram channels for resale, following the exact distribution pattern that fuels the estimated $1.5 billion annual dark web illicit marketplace economy. Credential stuffing — where credentials leaked in one breach are systematically tested against unrelated platforms — represents a growing and increasingly automated threat specifically because the pool of over 15 billion circulating stolen credentials globally gives attackers an enormous existing inventory to weaponize against Australian accounts without needing to breach those specific platforms directly.
For a fuller picture of how this credential economy operates at the infrastructure level — including exactly how stolen Australian data moves from initial breach to criminal marketplace to fraudulent use — our Dark Web Statistics report documents that 65% of active cybercriminals worldwide now use dark web-sourced data in their attacks, and that stolen credentials trade for as little as $1 per record, a commodity price point that reflects just how oversaturated the global supply of breached personal data has become.
Australian Business Vulnerability and Cybercrime Costs 2026
| Business Impact Metric | Data Point |
|---|---|
| Australian businesses breached at least once in past year | 41% |
| Businesses reporting 11 or more breaches in past year | 33% |
| Australia’s ranking, total data breach cost (2020, IBM/Ponemon, 18 countries) | 13th — below the global average |
| Increase in average total breach cost, 2014–2020 | 10% |
| NDB notification growth since scheme inception (2018–circa 2025) | +712% |
| Historical ACSC cyberattack reports (2019-20 period) | Almost 60,000 |
| Historical ACSC incident responses (2019-20 period) | Almost 2,300 |
Source: Cloudflare Australia business cybersecurity survey; UpGuard “13 Critical Data Breach Stats for Australian Businesses”; Australian Cyber Security Centre historical reporting
The Cloudflare survey finding that 41% of Australian businesses suffered at least one breach in the past year, with a striking 33% reporting 11 or more separate breach incidents, reveals that for a meaningful minority of Australian organizations, data breaches are no longer isolated crisis events but a recurring operational reality requiring sustained incident response capability rather than one-off remediation. This pattern of repeat victimization is consistent with the broader credential-reuse and infrastructure-targeting patterns documented throughout this report, where attackers who successfully breach an organization once often retain access pathways or return using freshly stolen credentials from unrelated incidents.
The 712% growth in NDB notifications since the scheme’s 2018 launch provides the clearest long-run trendline in Australia’s data breach history, though this figure reflects both genuinely rising attack volume and the scheme’s own maturation, as more organizations have become aware of their reporting obligations and improved their internal breach-detection capabilities over the same period. For a broader view of how data breaches and cybercrime fit within Australia’s overall crime landscape, including how authorities are responding to technology-facilitated offending more broadly, our Crime Statistics in Australia 2025 report documents that law enforcement agencies continue to report insufficient specialized investigative capacity to keep pace with the volume and sophistication of cyber-enabled crimes nationally.
Data Reliability Notes for Data Breach Statistics in Australia 2026
| Category | Status as of 2026 |
|---|---|
| OAIC’s next reporting period (July–December 2025) | Not yet published at time of writing; latest confirmed data covers January–June 2025 |
| Full-year 2026 breach totals | Not yet available; year in progress, only Q1 confirmed via independent trackers |
| OAIC vs. independent tracker figures | Measure different things — OAIC counts formal notifications; Surfshark and similar firms estimate exposed accounts, which can include duplicates across incidents |
| Origin Energy investigation | Still developing as of this report; full scope of the July 2026 breach not yet finalized |
Source: Cross-referenced OAIC, Surfshark, and independent cybersecurity research data, current as of mid-2026
Because Australia’s official OAIC reporting operates on a lagging six-month reporting cycle while independent trackers like Surfshark publish rolling quarterly estimates, readers comparing figures across sources in this report should note they are not always measuring identical things: OAIC notifications reflect formally reported breach events under the Privacy Act 1988, while quarterly account-exposure estimates from independent security researchers can include the same individual’s data being exposed multiple times across different incidents. Both are legitimate, complementary measures of Australia’s cybersecurity landscape, and this report has used each source for what it measures best — official notification trends from OAIC, and real-time exposure scale from independent breach trackers.
Disclaimer: This research report is compiled from publicly available sources. While reasonable efforts have been made to ensure accuracy, no representation or warranty, express or implied, is given as to the completeness or reliability of the information. We accept no liability for any errors, omissions, losses, or damages of any kind arising from the use of this report.

