Desk live·
ForensicPost
Breaches/Analysis/File 25-1227b

Australia's Eight Years of Breach Statistics Show What a Register Is Worth

Australia has published notifiable breach statistics continuously since 2018. The corpus has spent 480 files wishing for exactly this and should say what it is worth.

Constructed geometry · not a chart of case data
JurisdictionAustraliathe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetBreach measurement
ActorRegulator
D. Kennedy & S. Rosler12 min readConfidence: medium2 sources reviewed

Australia’s notifiable data breach scheme has produced published statistics on a consistent basis since 2018. This file sets out what that provides that nothing else in this corpus does.

A Trend You Can Believe

The corpus holds four incompatible 2025 ransomware totals at 25-1210b, two leak-site counts disagreeing about 2024 at 25-1230, an 80% single-year swing attributable to methodology at 25-0423, and a 3,000% figure at 25-0821 that almost certainly measures new reporting.

Against that, an 8% annual change measured the same way for eight years is a different class of statement — and it is the reason this desk graded 25-1229b high while grading most sector totals low.

Causes, Not Just Counts

The register distinguishes malicious attack from human error and system fault, which is how 25-1230b established that around 40% of notifiable breaches involve no adversary — a fact this corpus could not otherwise have known.

Leak sites cannot produce that. Vendor telemetry cannot produce it. Only a register that requires notification regardless of cause can.

Sector Shares On A Common Basis

Because every sector notifies on the same test, the health finding at 25-0802b is comparable in a way the US healthcare register at 25-0630 is not — that one measures a sector against sectors with no obligation at all.

What It Still Cannot Do

It counts notifications meeting a statutory harm threshold, so smaller incidents fall outside — the size problem at 25-0613b. It publishes a mean and no median, per 25-0731b. It records exposure and not outcome, so the unbridged link at 25-1219 remains unbridged.

And it says nothing about availability. A council whose telephones fail at 25-1127b, a manufacturer that stops building at 25-0902, a distributor that cannot invoice at 25-0606 — none of that is a notifiable data breach in any regime this corpus has found.

The Corpus’s Recommendation, Stated Plainly

A universal mandatory register with cause classification and published aggregates is achievable — one country has run it for eight years. It answers questions this database has repeatedly been unable to answer.

It would not answer the availability question, the outcome question, or the small-organisation question. Graded medium: this is an argument from what one register produced, not a finding.

This is an analysis file

It assesses what a long-running national register provides, against the measurement problems recorded throughout this database. Corrections: corrections@forensicpost.com.

Sources
  1. Notifiable data breaches reportOAIC
  2. Data breach notification requirements in AustraliaInvotec
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary