Notifiable Data Breaches
Notifications received 1 July to 31 December 2025, platform-computed from the published statistics.
+12.6% on Jul-Dec 2024 (same half last year)
basis: period · as at 29 June 2026
Notifications per half year, 2018-2025
Source of breach, Jul-Dec 2025
Change on the same half last year
What the data says
- Notifications are up on the same half last year. 670 notifications received Jul-Dec 2025, 12.6% on 595 in Jul-Dec 2024 Notifications, Jul-Dec 2025 Change on the previous period
- Notification to the OAIC stays within a month for about half of breaches. 50.6% of in-range breaches were notified to the OAIC within 30 days (308 of 609) Notified within 30 days
- Malicious or criminal attacks remain the dominant source. malicious or criminal attacks were the source of 60.4% of notifications Malicious or criminal attacks
- Most breaches are identified quickly. 58.7% of in-range breaches were identified within 10 days (349 of 595) Identified within 10 days
The latest period
The four figures above the fold cover source mix and response times; these are the rest of the latest period. Shares are platform-computed over the published counts; the time shares on this page are over the in-range breaches only, and the basis label on each carries its base.
Year on year
Malicious share, movement in percentage points
basis: period (published report figure)
Source: the OAIC workbook 1 July to 31 December 2025 (as at 29 June 2026), data.gov.au dataset 5781dc17-2ad0-4dd1-bced-01c544943ce3.
Where did this come from?Change in the malicious-or-criminal share, in percentage points, against the same half of the previous year. Shares are platform-computed from the published counts; a half with unpublished source counts is a gap.
Time to respond
Notified to the OAIC within 30 days
basis: period (published report figure)
Source: the OAIC workbook 1 July to 31 December 2025 (as at 29 June 2026), data.gov.au dataset 5781dc17-2ad0-4dd1-bced-01c544943ce3.
Where did this come from?The line is transcribed from report prose, which published this share from 2020 to 2023. No whole-period figure is published for 2024; that stretch stays a gap. The single marker is the platform share for Jul-Dec 2025, computed from the workbook's time bands over the in-range breaches; it is a different base from the prose line and is labelled as such. The 30-day window reflects the section 26WH assessment obligation; the reports publish it as a timeliness measure.
Identified within 30 days
basis: period (published report figure)
Source: the OAIC workbook 1 July to 31 December 2025 (as at 29 June 2026), data.gov.au dataset 5781dc17-2ad0-4dd1-bced-01c544943ce3.
Where did this come from?The line is transcribed from report prose, which published this share from 2020 to 2023. No whole-period figure is published for 2024; that stretch stays a gap. The single marker is the platform share for Jul-Dec 2025, computed from the workbook's time bands over the in-range breaches; it is a different base from the prose line and is labelled as such. The 30-day window reflects the section 26WH assessment obligation; the reports publish it as a timeliness measure.
The series
Notifications by source of breach, per half year
basis: period (published report figure)
Source: the OAIC workbook 1 July to 31 December 2025 (as at 29 June 2026), data.gov.au dataset 5781dc17-2ad0-4dd1-bced-01c544943ce3.
Where did this come from?Source counts are the published figures; a gap means the report did not publish a count for that source that period. Jul-Dec 2025 totals exclude Currently unknown and Other, which the workbook publishes only monthly. Early halves are platform sums of quarterly reports where both quarters published counts.
Data provenance · Historical series · Time to respond · Sectors and movers