Historical series, 2018-2025

Notifications under the NDB scheme from the scheme start in February 2018. The series is transcribed from the bi-annual reports with qualifiers; the workbook supplies the latest period.

Notifications per half year

basis: period (published report figure)

Source: the OAIC workbook 1 July to 31 December 2025 (as at 29 June 2026), data.gov.au dataset 5781dc17-2ad0-4dd1-bced-01c544943ce3.

Where did this come from?

2018-H1 and 2019-H1 are platform sums of the two published quarterly reports. No report was published for January to June 2025: the dashboard replaced the PDF cycle before it was released.

Notifications, change on the same half of the previous year

basis: period (published report figure)

Source: the OAIC workbook 1 July to 31 December 2025 (as at 29 June 2026), data.gov.au dataset 5781dc17-2ad0-4dd1-bced-01c544943ce3.

Where did this come from?

Percentage change against the same half of the previous year, where both halves are published. 2018-H1, 2018-H2 and 2019-H1 are platform sums of the quarterly reports, so their comparisons sit on a derived base. 2025-H1 has no published total, so that half has no bar; 2025-H2 compares with 2024-H2.

Notifications by source of breach

basis: period (published report figure)

Source: the OAIC workbook 1 July to 31 December 2025 (as at 29 June 2026), data.gov.au dataset 5781dc17-2ad0-4dd1-bced-01c544943ce3.

Where did this come from?

Source counts are the published figures; a gap means the report did not publish a count for that source that period. Jul-Dec 2025 totals exclude Currently unknown and Other, which the workbook publishes only monthly. Early halves are platform sums of quarterly reports where both quarters published counts.

Malicious share, movement in percentage points

basis: period (published report figure)

Source: the OAIC workbook 1 July to 31 December 2025 (as at 29 June 2026), data.gov.au dataset 5781dc17-2ad0-4dd1-bced-01c544943ce3.

Where did this come from?

Change in the malicious-or-criminal share, in percentage points, against the same half of the previous year. Shares are platform-computed from the published counts; a half with unpublished source counts is a gap.

Share of notifications that were malicious or criminal

basis: period (published report figure)

Source: the OAIC workbook 1 July to 31 December 2025 (as at 29 June 2026), data.gov.au dataset 5781dc17-2ad0-4dd1-bced-01c544943ce3.

Where did this come from?

Median individuals affected per malicious or criminal attack

basis: period (published report figure)

Source: the OAIC workbook 1 July to 31 December 2025 (as at 29 June 2026), data.gov.au dataset 5781dc17-2ad0-4dd1-bced-01c544943ce3.

Where did this come from?

Median individuals affected per malicious or criminal attack, world-wide, where a report publishes the breakdown table. The reports publish no whole-period median, so this series follows the malicious-breakdown total row only.

Restatements

PeriodFirst publishedLatestRestated in
2019-H1460447notifiable-data-breaches-report-januaryjune-2020
2019-H2537532notifiable-data-breaches-report-januaryjune-2020
2020-H1518512notifiable-data-breaches-report-julydecember-2020
2020-H2539530notifiable-data-breaches-report-januaryjune-2021
2021-H1446436notifiable-data-breaches-report-july-to-december-2021
2021-H2464460notifiable-data-breaches-report-january-to-june-2022
2022-H1396393notifiable-data-breaches-report-july-to-december-2022
2022-H2497486notifiable-data-breaches-report-january-to-june-2023
2023-H1409407notifiable-data-breaches-report-july-to-december-2023
2023-H2483485notifiable-data-breaches-report-january-to-june-2024
2024-H1527518notifiable-data-breaches-report-july-to-december-2024

Published figures restate over time as notifications are assessed. The site pins the latest value and shows the first-published figure beside it.

Top 5 sectors per period

PeriodTop sectors (published names kept verbatim)
2018-Q1Health service providers (15), Legal, Accounting & Management services (10), Finance (incl. superannuation) (8), Education (6), Charities (4)
2018-Q2Health service providers (49), Finance (36), Legal, Accounting & Management services (20), Education (19), Business and Professional Associations (15)
2018-Q3Health service providers (45), Finance (incl. superannuation) (35), Legal, accounting & management services (34), Education (16), Personal services (13)
2018-Q4Health service providers (54), Finance (incl. superannuation) (40), Legal, accounting and management services (23), Education (21), Mining and manufacturing (12)
2019-H2Health service providers (117), Finance (incl. superannuation) (77), Education (49), Legal, accounting & management services (40), Personal services (23)
2019-Q1Health service providers (58), Finance (including superannuation) (27), Legal, accounting and management services (23), Education (19), Retail (11)
2019-Q2Health service providers (47), Finance (including superannuation) (42), Legal, accounting and management services (24), Education (23), Retail (15)
2020-H1Health service providers (115), Finance (incl. superannuation) (75), Education (44), Insurance (35), Legal, accounting & management services (26)
2020-H2Health service providers (123), Finance (incl. superannuation) (80), Education (40), Legal, accounting & management services (38), Australian Government (33)
2021-H1Health service providers (85), Finance (including superannuation) (57), Legal, accounting & management services (35), Australian Government (34), Insurance (34)
2021-H2Health service providers (83), Finance (56), Legal, accounting & management services (51), Personal services (36), Insurance (32)
2022-H1Health service providers (79), Finance (52), Education (35), Legal, accounting and management services (26), Recruitment agencies (25)
2022-H2Health service providers (71), Finance (68), Insurance (42), Legal, accounting and management services (37), Recruitment agencies (35)
2023-H1Health service providers (63), Finance (54), Recruitment agencies (33), Legal, accounting and management services (26), Insurance (25)
2023-H2Health service providers (104), Finance (49), Insurance (45), Retail (39), Australian Government (38)
2024-H1Health service providers (102), Australian Government (63), Finance (incl. superannuation) (58), Education (44), Retail (29)
2024-H2Health service providers (121), Australian Government (100), Finance (incl. superannuation) (54), Legal, accounting and management services (36), Retail (34)

Individuals affected per breach

PeriodIndividuals affected per breach (as published, per cause)
2022-H1human error: median —, average 68 individuals
large-scale breaches affecting Australians: 24 (over 5,000 Australians)
2022-H2human error: median —, average 481 individuals
large-scale breaches affecting Australians: 40 (over 5,000 Australians)
2023-H1malicious attacks: median 59, average 186,951 individuals
human error: median 2, average 84 individuals
large-scale breaches affecting Australians: 23 (over 5,000 Australians)
2023-H2malicious attacks: median 58, average 37,346 individuals
human error: median 1, average 348 individuals
large-scale breaches affecting Australians: 26 (over 5,000 Australians)
2024-H1malicious attacks: median 68, average 60,584 individuals
human error: median 2, average 1,405 individuals
large-scale breaches affecting Australians: 8 (over 100,000 Australians)
2024-H2malicious attacks: median 81, average 9,655 individuals
human error: median 1, average 79 individuals

Sector names are the printed names of each period; definitions changed across the series (Recruitment agencies first reported separately in 2022-H1) and the site does not re-map across eras. Counting rules changed with primary-notification counting, so early periods are not like-for-like with later ones; see the data notes.