Tech Translated

IT Security & Technology Blog

Practical IT insights for Australian businesses. Our team covers cybersecurity advisories, compliance updates, and plain-English explainers on the technology your business relies on, published regularly as the landscape shifts.

Teal shield graphic on charity cyber risk and ACNC guidance for not-for-profit boards

Data Breaches Just Hit a Record High — What It Means for Not-for-Profits

The privacy regulator’s latest numbers are blunt: 2025 was the worst year for data breaches since mandatory reporting began. For not-for-profits sitting on donor records and volunteer databases, that’s not a headline to scroll past.

Australia’s privacy regulator recorded 1,205 notifiable data breaches in 2025 — an all-time high and an 8% jump on the year before. Most of them (716) came from malicious or criminal attacks, and “business and professional associations” landed in the top five sectors for the year. In other words, community organisations are squarely in the firing line, not off to one side of it.

Why not-for-profits are a soft target

The reason is simple. NFPs hold exactly the data attackers want — names, addresses, payment details, sometimes health or hardship information — but rarely carry the security budget of a bank. In the community organisations we support across the Sydney Northern Beaches and Central West NSW, the recurring weak spot isn’t exotic malware. It’s access sprawl: volunteers and former board members who still have logins to the donor CRM months after they’ve moved on. Every one of those dormant accounts is a door left unlocked. And under the Notifiable Data Breaches scheme, a breach likely to cause serious harm has to be reported to both the OAIC and the people affected, usually within 30 days — with the reputational hit landing on your name, not your software vendor’s.

Three things that move the needle fast

Turn on phishing-resistant MFA for every account that touches donor or financial data. Run an access review this quarter and switch off logins for anyone who has left. And write a one-page breach response plan now, while you’re calm — not at 9pm on a Friday when something has already gone wrong. The OAIC’s new quick-reference guide is a solid starting template, and none of these three steps needs a big cheque.

Not sure who can still get into your donor database? That single question is usually where the biggest risk is hiding — and it takes an afternoon to answer.

We help Australian not-for-profits get this in place without enterprise budgets — access reviews, MFA rollouts and Essential Eight uplift built around how charities actually work. If a record year for breaches has you wondering where you stand, that’s exactly the conversation to have.

Source
Office of the Australian Information Commissioner, “Data breach notifications increase to all-time high in 2025” (6 July 2026).
Michael Sacco
All IT Services
Michael works with not-for-profits, hospitality groups and financial services firms across Sydney, the Central West NSW, Brisbane and Melbourne, helping them get practical cyber security and compliance in place without enterprise overheads.

Related Guide

IT Services for Not-for-Profits

Learn how we help NFPs operate efficiently and stay compliant.

Read the Full Guide →