In the January to June 2025 Australian reporting period, malicious or criminal attacks accounted for 59% of notifications — 308 of them — with cyber security incidents affecting an average of just over 10,000 individuals each.
Per-Incident Figures Are What The Corpus Lacks
This database records enormous individual incidents — 62.4 million claimed at 25-0105, 33.7 million at 25-1130, 13,924,906 at 25-0618 — because those are the ones that get written about.
It has no sense of the typical incident, because a typical incident produces a regulatory filing and no coverage. Just over 10,000 people is that missing figure.
And It Is An Average Over A Very Skewed Distribution
The corpus objected to exactly this at 25-0208, where a $730 average scam loss described nobody, and at 25-0808 and 25-0616, where sector breach-cost averages spanned corner shops and multinationals.
A handful of large incidents will dominate a mean of this kind. The median is likely to be far lower — a few hundred people, or fewer — and is not published.
Which Makes The Corpus’s Scale Intuition Wrong
Reading this database gives an impression that a data breach means millions of records. On a national register covering all sectors, the average is five thousand times smaller than the largest file here, and the median smaller again.
The corpus filed at 25-1005 that a 4,541-person breach was small enough to be remarkable here, and observed that an implicit size threshold shapes what this database contains. This is the number that threshold sits above.
Compiled from the regulator’s published statistics, listed below. The figure is a mean; no median is published. Corrections: corrections@forensicpost.com.
- Latest notifiable data breach statistics for January to June 2025OAIC
- OAIC reports continued rise in notifiable data breaches in first half of 2025Australian Cyber Security Magazine