Data & research · Australia

Data breach statistics: Australia, 2026

How often breaches happen in Australia, the largest ones, and what data they exposed. Official figures, plus our own breach tracking. Each figure shows its source and how sure we are.

Data as at · We review these figures monthly · Method · Free to reuse with attribution (CC BY 4.0)

01 · How often

Breach reports reached a record in 2025

Organisations must tell the OAIC (the Australian privacy regulator) about serious breaches. It received 1,205 notifications in 2025, up 8% from 1,112 in 2024.

Notifications to the OAIC, per half-year

Data breach notifications to the OAIC, per half-year
PeriodNotifications
H1 2023409
H2 2023483
H1 2024527
H2 2024595
H1 2025532
H2 2025670

Each bar is as first published by the OAIC: its half-year reports, and its data set for July to December 2025. The OAIC revises counts later, so two halves may not add up to the annual total (for 2025: 1,205).

OAIC, Notifiable Data Breaches reports· n: Six half-years, January 2023 to December 2025High confidence#oaic-half-year
OAIC, Data breach notifications increase to all-time high in 2025· n: All notifications to the OAIC, calendar year 2025· annual totalHigh confidence#oaic-2025-total

02 · The largest

The largest breaches at Australian organisations

Breaches at Australian organisations that affected 1 million people or more. Some, like Canva, also affected people outside Australia. Bar length shows the reported count.

  1. 137,272,116 peopleGlobal users
    • Email
    • Name
    • Password
  2. Ticketek

    2024 · Source: Cyber Daily

    17,000,000 peopleNot confirmed by Ticketek; HIBP found 17.6m unique emails
    • Email
    • Name
    • DOB
  3. 14,000,000 recordsIncl. ~7.9m licences; Australia and NZ
    • Email
    • Name
    • DOB
    • Gov ID
  4. 12,900,000 people
    • Email
    • Name
    • Phone
    • DOB
    • Address
    • Gov ID
    • Health
  5. 9,700,000 people
    • Email
    • Name
    • Phone
    • DOB
    • Health
  6. 9,500,000 peopleOAIC figure in its court case; Optus first said 9.8m
    • Email
    • Name
    • Phone
    • DOB
    • Address
    • Gov ID
  7. 5,700,000 people
    • Email
    • Name
    • Phone
    • DOB
    • Address
  8. 2,200,000 people
    • Email
    • Name
    • Phone
    • Address
  9. Quest Apartment Hotels

    2026 · Source: Information Age (ACS)

    1,991,613 people
    • Email
    • Name
    • Phone
    • DOB
    • Address
    • Gov ID
    • Financial
  10. 1,988,331 peopleHIBP unique emails
    • Email
    • Name
    • Phone
Show the other 3 breaches
  1. Early Settler

    2024 · Source: Cyber Daily

    1,100,000 peopleAttacker's claim
    • Email
    • Name
    • Phone
    • DOB
    • Address
  2. Mathspace

    2026 · Source: BleepingComputer

    1,079,819 peopleAustralia and NZ
    • Email
    • Name
  3. NSW pubs and clubs (Outabox)

    2024 · Source: Information Age (ACS)

    Up to 1,000,000 peoplenot independently verified
    • Phone
    • DOB
    • Address
    • Gov ID
    • Biometrics

All 13 breaches, largest first. Bars use a log scale so smaller breaches stay visible. Small text next to a count says when it is unconfirmed, a claim, records rather than people, or not only Australians. Where we have a guide, the name links to it. Data types are as recorded for each breach (DOB = date of birth; Gov ID = government ID, such as a licence or passport number).

In The Event Of breach tracker, from OAIC, company notices and Have I Been Pwned· n: 13 breaches of 1 million+ people, 2019 to 2026· counts as reported by each source; see the notes by each countMedium confidence#tier1-au

03 · What leaks together

Email and name leaked together in 12 of the 13 large breaches we track

One data type on its own is a small risk. Together, email, name, phone and date of birth are enough for many scams. This is how often they leaked together in the 13 large Australian breaches.

Email + name12 of 13
Email + name + phone8 of 13
Email + name + phone + date of birth6 of 13

Small sample: we show counts, not percentages.

In The Event Of breach tracker, from OAIC, company notices and Have I Been Pwned· n: 13 breaches of 1 million+ people, 2019 to 2026Medium confidence#combo-au

04 · What companies collect

What Australian websites say they collect

We read the privacy policies of 2,293 businesses on .au websites and recorded the data types each one says it may collect.

  • Email address90% (2,059 of 2,293)
  • Name82% (1,888 of 2,293)
  • Address78% (1,799 of 2,293)
  • Phone number77% (1,756 of 2,293)
  • Payment details51% (1,167 of 2,293)
  • Date of birth34% (786 of 2,293)

"Says it may collect" means the policy names that data type in a collection statement. We use the .au domain as a stand-in for an Australian business.

In The Event Of privacy-policy analysis· n: 2,293 privacy policies on .au domainsMedium confidence#au-policy-collect

Need more detail?

Journalists and researchers can ask for access to the data behind this page, such as breaches by sector or by data type. We review each request.

Request access

How we make these numbers

  • High confidence: official figures, copied from the regulator (OAIC).
  • Medium confidence: our own data. We check each figure by hand before each update.
  • No figure on this page describes any individual person.
  • Large breaches: breaches at Australian organisations (an .au website, an OAIC record, or an Australian head office) that each affected 1 million people or more. We remove duplicates and rows we cannot confirm. We group each breach's recorded data into ten types: email, name, phone, date of birth, address, government ID, health, financial, password and biometrics.
  • Privacy policies: we read each policy automatically and record the data types it names in a collection statement. We do not report password or health data from this analysis, because our checks found it was not reliable enough.

You may reuse the figures on this page with attribution to In The Event Of, under CC BY 4.0. Please link to the figure's #anchor.

Breach data sourced from Have I Been Pwned

Have I Been Pwned data is licensed under CC BY 4.0.