Notifiable Data Breaches

Notifications received 1 July to 31 December 2025, platform-computed from the published statistics.

670

+12.6% on Jul-Dec 2024 (same half last year)

basis: period · as at 29 June 2026

60.4%Malicious or criminal
58.7%Identified within 10 days
50.6%Notified within 30 days
19.1%Top sector share

Notifications per half year, 2018-2025

Source of breach, Jul-Dec 2025

Change on the same half last year

What the data says

The latest period

Human error29%basis: period
System faults5.2%basis: period
Cyber incidents37.8%basis: period
Large-scale breaches3basis: period

The four figures above the fold cover source mix and response times; these are the rest of the latest period. Shares are platform-computed over the published counts; the time shares on this page are over the in-range breaches only, and the basis label on each carries its base.

Year on year

Malicious share, movement in percentage points

basis: period (published report figure)

Source: the OAIC workbook 1 July to 31 December 2025 (as at 29 June 2026), data.gov.au dataset 5781dc17-2ad0-4dd1-bced-01c544943ce3.

Where did this come from?

Change in the malicious-or-criminal share, in percentage points, against the same half of the previous year. Shares are platform-computed from the published counts; a half with unpublished source counts is a gap.

Time to respond

Notified to the OAIC within 30 days

basis: period (published report figure)

Source: the OAIC workbook 1 July to 31 December 2025 (as at 29 June 2026), data.gov.au dataset 5781dc17-2ad0-4dd1-bced-01c544943ce3.

Where did this come from?

The line is transcribed from report prose, which published this share from 2020 to 2023. No whole-period figure is published for 2024; that stretch stays a gap. The single marker is the platform share for Jul-Dec 2025, computed from the workbook's time bands over the in-range breaches; it is a different base from the prose line and is labelled as such. The 30-day window reflects the section 26WH assessment obligation; the reports publish it as a timeliness measure.

Identified within 30 days

basis: period (published report figure)

Source: the OAIC workbook 1 July to 31 December 2025 (as at 29 June 2026), data.gov.au dataset 5781dc17-2ad0-4dd1-bced-01c544943ce3.

Where did this come from?

The line is transcribed from report prose, which published this share from 2020 to 2023. No whole-period figure is published for 2024; that stretch stays a gap. The single marker is the platform share for Jul-Dec 2025, computed from the workbook's time bands over the in-range breaches; it is a different base from the prose line and is labelled as such. The 30-day window reflects the section 26WH assessment obligation; the reports publish it as a timeliness measure.

The series

Notifications by source of breach, per half year

basis: period (published report figure)

Source: the OAIC workbook 1 July to 31 December 2025 (as at 29 June 2026), data.gov.au dataset 5781dc17-2ad0-4dd1-bced-01c544943ce3.

Where did this come from?

Source counts are the published figures; a gap means the report did not publish a count for that source that period. Jul-Dec 2025 totals exclude Currently unknown and Other, which the workbook publishes only monthly. Early halves are platform sums of quarterly reports where both quarters published counts.

Data provenance · Historical series · Time to respond · Sectors and movers