Desk live·
ForensicPost
Breaches/International/File 25-1230b

716 of Australia's 1,205 Breach Notifications Were Attributed to Criminal Activity

Of Australia’s 1,205 notifications in 2025, 716 were attributed to malicious or criminal activity. The remainder were not, and the corpus has almost no files on them.

Constructed geometry · not a chart of case data
JurisdictionAustraliathe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetAustralian organisations
ActorMultiple and none
S. Rosler12 min readConfidence: high2 sources reviewed

Of the 1,205 Australian notifications in 2025, 716 were attributed to malicious or criminal attack. The balance — roughly 489 — arose from human error and system faults.

Forty Per Cent Of Breaches Had No Attacker

This corpus is organised around adversaries. Its four sections are breaches, ransomware, nation-state and cloud, and almost every file names or discusses an actor.

A register covering all causes says that two in five notifiable breaches involve nobody attacking anything — an email sent to the wrong recipient, a misconfigured permission, a document published in error.

The corpus has a handful: the misconfigured database at 26-0219, the accidental publication at 26-0428, the agent that deleted a production database with no adversary at all at 25-0817. That is not 40% of this database.

The Bias Is The Same One As Everywhere Else

An attacker produces a named group, a leak site, a research write-up and a story. Human error produces a notification and nothing else.

This desk filed at 25-0421b that the corpus over-weights exploitation because a CVE generates documentation while a stolen password does not. The same mechanism applies one level up: adversarial incidents generate documentation and accidental ones do not.

And The Remedy Question Is Different

The corpus’s recommendations — segmentation, detection, out-of-band verification, inventory, narrowed sessions — all address an adversary.

None addresses an email autocomplete selecting the wrong recipient, which is a design problem in a mail client rather than a security control. Two in five notifiable breaches sit outside everything this database has to say.

How we reported this

Compiled from the regulator’s published statistics, listed below. The residual figure is our arithmetic on the published total and malicious count. Corrections: corrections@forensicpost.com.

Sources
  1. Data breach notifications increase to all-time high in 2025OAIC
  2. Latest notifiable data breach statistics for January to June 2025OAIC
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary