The Office of the Australian Information Commissioner reported 1,205 data breach notifications for 2025, up 8% from 1,112 in 2024. 716 — 59% — came from malicious or criminal attacks. Health service providers made the most notifications (225, or 19%), followed by finance (157) and the Australian Government (118).

The OAIC also reported that 82% of Australians are concerned about data breaches, up from 74% in 2023. Privacy Commissioner Carly Kind described the threat as “substantial and rising year on year”. And these figures only count breaches that met the notification threshold and were reported.

For small businesses — particularly in health, allied health and professional services — the useful number isn’t the total, it’s the 59%. Most breaches are people deliberately trying to get in. The controls that make that harder are unglamorous: MFA that resists phishing, patched systems, least-privilege access and backups you have actually tested.

What it means for your businessBreach numbers keep climbing and customers are paying attention. The basics — phishing-resistant MFA, patching, least privilege and tested backups — are still the best return on your security spend.
Source & referenceOAIC — Data breach notifications increase to all-time high in 2025 ↑