Desk live·
ForensicPost
Breaches/International/File 25-1206

Five Countries Accounted for 62% of Tracked Incidents Across Asia-Pacific

China, India, Australia, Japan and South Korea together accounted for 61.78% of tracked incidents across Asia and the South Pacific. This database contains almost none of them.

Constructed geometry · not a chart of case data
TargetAsia-Pacific organisations
ActorMultiple
D. Kennedy11 min readConfidence: medium2 sources reviewed

Regional assessment data records China, India, Australia, Japan and South Korea together accounting for 61.78% of tracked incidents, with China at 15.4% and India at 14.7%. Australia recorded 2,537 incidents, Japan 2,282, and Singapore 963.

Population Is Doing Most Of The Work

China and India lead by incident count and have the largest populations and internet user bases in the region. Australia at 2,537 incidents has a population under 30 million.

Per capita, the ordering inverts entirely. Absolute counts describe where the most people are online, which is not the same question as where risk is concentrated — and it is the question these tables are usually read as answering.

And Detection Capability Distorts The Rest

A tracked incident requires somebody to notice, classify and report it. Countries with mature computer emergency response teams, mandatory reporting and active security industries generate more tracked incidents at any given level of underlying activity.

Australia and Singapore both have substantial national cyber capability relative to their size, which is a plausible reason their counts look high. The corpus made the same point about the healthcare sector at 25-0630: sectors and countries that measure appear worse than those that do not.

The Comparison This Desk Cannot Avoid

This database contains a handful of files concerning any of these five countries. It contains dozens concerning the United States and the United Kingdom.

That is not a judgement about where incidents occur. It is a direct consequence of which jurisdictions require disclosure in English, and it is the subject of 25-1225.

This is an analysis file

Built on published regional assessment data, listed below. Incident counts are of tracked incidents and are not normalised for population, internet penetration or detection capability. Corrections: corrections@forensicpost.com.

Sources
  1. Asia and South Pacific cyber threat assessment report 2025/2026INTERPOL
  2. Cybersecurity in the Asia-Pacific region — statistics and factsStatista
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary