Desk live·
ForensicPost
Breaches/International/File 25-1229b

Australia Recorded 1,205 Notifiable Data Breaches in 2025, the Highest Since 2018

Australia recorded 1,205 notifiable data breaches in 2025, an 8% rise and the highest annual total since the scheme began in 2018.

Constructed geometry · not a chart of case data
JurisdictionAustraliathe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetAustralian organisations
ActorMultiple
D. Kennedy12 min readConfidence: high2 sources reviewed

Australia’s privacy regulator recorded 1,205 notifiable data breaches during 2025, an increase of around 8% on 2024 and the highest annual figure since the mandatory scheme commenced in 2018.

This Is The Second Usable National Register In The Corpus

The first is the US healthcare register at 25-0630, which produced 343 filings in six months and is the reason this database can quote exact figures for health incidents and ranges for everything else.

Australia’s scheme covers every sector, is mandatory, is published in aggregate, and has run continuously for eight years. It is a better instrument than anything else this desk has found — better than leak-site counts at 25-1230, vendor telemetry at 26-0513 and the four incompatible 2025 ransomware totals at 25-1210b.

An 8% Rise Is The Right Size To Believe

This desk has discounted an 80% single-year jump at 25-0423, a 3,000% scam figure at 25-0821 and a 241% nonprofit increase at 25-0614b, on the grounds that a number moving faster than the world is measuring the instrument.

Eight per cent, in a scheme with a stable definition and eight years of continuity, is a measurement. It is the most credible year-on-year change in this database.

And It Makes The International Comparisons Worse

The corpus filed at 25-1123 that a region introducing disclosure requirements will show dramatic apparent rises and be penalised in insurance and procurement for becoming transparent.

Australia has been transparent since 2018, so its figures are neither inflating from a low base nor suppressed. It is the closest thing to a control this corpus has, and every jurisdiction it might be compared with is measured differently.

How we reported this

Compiled from the regulator’s published statistics and reporting on them, listed below. The scheme covers breaches meeting a statutory harm threshold and does not capture all incidents. Corrections: corrections@forensicpost.com.

Sources
  1. Data breach notifications increase to all-time high in 2025OAIC
  2. OAIC reports continued rise in notifiable data breaches in first half of 2025Australian Cyber Security Magazine
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary