Data & research · Australia
Data breach statistics: Australia, 2026
How often breaches happen in Australia, the largest ones, and what data they exposed. Official figures, plus our own breach tracking. Each figure shows its source and how sure we are.
Data as at · We review these figures monthly · Method · Free to reuse with attribution (CC BY 4.0)
13
breaches at Australian organisations from 2019 to 2026 that each affected 1 million+ people
In The Event Of breach tracker
6 of 13
of those exposed email, name, phone and date of birth together
In The Event Of breach tracker
01 · How often
Breach reports reached a record in 2025
Organisations must tell the OAIC (the Australian privacy regulator) about serious breaches. It received 1,205 notifications in 2025, up 8% from 1,112 in 2024.
Notifications to the OAIC, per half-year
| Period | Notifications |
|---|---|
| H1 2023 | 409 |
| H2 2023 | 483 |
| H1 2024 | 527 |
| H2 2024 | 595 |
| H1 2025 | 532 |
| H2 2025 | 670 |
Each bar is as first published by the OAIC: its half-year reports, and its data set for July to December 2025. The OAIC revises counts later, so two halves may not add up to the annual total (for 2025: 1,205).
02 · The largest
The largest breaches at Australian organisations
Breaches at Australian organisations that affected 1 million people or more. Some, like Canva, also affected people outside Australia. Bar length shows the reported count.
Canva
137,272,116 peopleGlobal users- Name
- Password
Ticketek
2024 · Source: Cyber Daily
17,000,000 peopleNot confirmed by Ticketek; HIBP found 17.6m unique emails- Name
- DOB
- 14,000,000 recordsIncl. ~7.9m licences; Australia and NZ
- Name
- DOB
- Gov ID
MediSecure
12,900,000 people- Name
- Phone
- DOB
- Address
- Gov ID
- Health
2022 · Source: Cyber Daily
9,700,000 people- Name
- Phone
- DOB
- Health
- 9,500,000 peopleOAIC figure in its court case; Optus first said 9.8m
- Name
- Phone
- DOB
- Address
- Gov ID
- 5,700,000 people
- Name
- Phone
- DOB
- Address
- 2,200,000 people
- Name
- Phone
- Address
Quest Apartment Hotels
1,991,613 people- Name
- Phone
- DOB
- Address
- Gov ID
- Financial
Oz Hair and Beauty
1,988,331 peopleHIBP unique emails- Name
- Phone
Show the other 3 breaches
Early Settler
2024 · Source: Cyber Daily
1,100,000 peopleAttacker's claim- Name
- Phone
- DOB
- Address
Mathspace
2026 · Source: BleepingComputer
1,079,819 peopleAustralia and NZ- Name
NSW pubs and clubs (Outabox)
Up to 1,000,000 peoplenot independently verified- Phone
- DOB
- Address
- Gov ID
- Biometrics
All 13 breaches, largest first. Bars use a log scale so smaller breaches stay visible. Small text next to a count says when it is unconfirmed, a claim, records rather than people, or not only Australians. Where we have a guide, the name links to it. Data types are as recorded for each breach (DOB = date of birth; Gov ID = government ID, such as a licence or passport number).
03 · What leaks together
Email and name leaked together in 12 of the 13 large breaches we track
One data type on its own is a small risk. Together, email, name, phone and date of birth are enough for many scams. This is how often they leaked together in the 13 large Australian breaches.
Small sample: we show counts, not percentages.
04 · What companies collect
What Australian websites say they collect
We read the privacy policies of 2,293 businesses on .au websites and recorded the data types each one says it may collect.
- Email address90% (2,059 of 2,293)
- Name82% (1,888 of 2,293)
- Address78% (1,799 of 2,293)
- Phone number77% (1,756 of 2,293)
- Payment details51% (1,167 of 2,293)
- Date of birth34% (786 of 2,293)
"Says it may collect" means the policy names that data type in a collection statement. We use the .au domain as a stand-in for an Australian business.
Need more detail?
Journalists and researchers can ask for access to the data behind this page, such as breaches by sector or by data type. We review each request.
How we make these numbers
- High confidence: official figures, copied from the regulator (OAIC).
- Medium confidence: our own data. We check each figure by hand before each update.
- No figure on this page describes any individual person.
- Large breaches: breaches at Australian organisations (an .au website, an OAIC record, or an Australian head office) that each affected 1 million people or more. We remove duplicates and rows we cannot confirm. We group each breach's recorded data into ten types: email, name, phone, date of birth, address, government ID, health, financial, password and biometrics.
- Privacy policies: we read each policy automatically and record the data types it names in a collection statement. We do not report password or health data from this analysis, because our checks found it was not reliable enough.
You may reuse the figures on this page with attribution to In The Event Of, under CC BY 4.0. Please link to the figure's #anchor.
Breach data sourced from Have I Been Pwned
Have I Been Pwned data is licensed under CC BY 4.0.
Sources
Where this information comes from
- OAIC, Data breach notifications increase to all-time high in 2025
- OAIC, Notifiable Data Breaches reports
- OAIC, Notifiable data breaches report: January to June 2023
- OAIC, Notifiable data breaches report: July to December 2023
- OAIC, Notifiable data breaches report: January to June 2024
- OAIC, Notifiable data breaches report: July to December 2024
- OAIC, Latest Notifiable Data Breach statistics for January to June 2025
- OAIC, Notifiable Data Breaches (NDB) scheme dataset, 1 July to 31 December 2025 (data.gov.au)
- Have I Been Pwned, breach list (CC BY 4.0)
- Qantas, cyber incident update (5.7 million customers)