Of the 1,205 Australian notifications in 2025, 716 were attributed to malicious or criminal attack. The balance — roughly 489 — arose from human error and system faults.
Forty Per Cent Of Breaches Had No Attacker
This corpus is organised around adversaries. Its four sections are breaches, ransomware, nation-state and cloud, and almost every file names or discusses an actor.
A register covering all causes says that two in five notifiable breaches involve nobody attacking anything — an email sent to the wrong recipient, a misconfigured permission, a document published in error.
The corpus has a handful: the misconfigured database at 26-0219, the accidental publication at 26-0428, the agent that deleted a production database with no adversary at all at 25-0817. That is not 40% of this database.
The Bias Is The Same One As Everywhere Else
An attacker produces a named group, a leak site, a research write-up and a story. Human error produces a notification and nothing else.
This desk filed at 25-0421b that the corpus over-weights exploitation because a CVE generates documentation while a stolen password does not. The same mechanism applies one level up: adversarial incidents generate documentation and accidental ones do not.
And The Remedy Question Is Different
The corpus’s recommendations — segmentation, detection, out-of-band verification, inventory, narrowed sessions — all address an adversary.
None addresses an email autocomplete selecting the wrong recipient, which is a design problem in a mail client rather than a security control. Two in five notifiable breaches sit outside everything this database has to say.
Compiled from the regulator’s published statistics, listed below. The residual figure is our arithmetic on the published total and malicious count. Corrections: corrections@forensicpost.com.