Data Breaches Just Hit a Record High — What It Means for Not-for-Profits
The privacy regulator’s latest numbers are blunt: 2025 was the worst year for data breaches since mandatory reporting began. For not-for-profits sitting on donor records and volunteer databases, that’s not a headline to scroll past.
Australia’s privacy regulator recorded 1,205 notifiable data breaches in 2025 — an all-time high and an 8% jump on the year before. Most of them (716) came from malicious or criminal attacks, and “business and professional associations” landed in the top five sectors for the year. In other words, community organisations are squarely in the firing line, not off to one side of it.
Why not-for-profits are a soft target
The reason is simple. NFPs hold exactly the data attackers want — names, addresses, payment details, sometimes health or hardship information — but rarely carry the security budget of a bank. In the community organisations we support across the Sydney Northern Beaches and Central West NSW, the recurring weak spot isn’t exotic malware. It’s access sprawl: volunteers and former board members who still have logins to the donor CRM months after they’ve moved on. Every one of those dormant accounts is a door left unlocked. And under the Notifiable Data Breaches scheme, a breach likely to cause serious harm has to be reported to both the OAIC and the people affected, usually within 30 days — with the reputational hit landing on your name, not your software vendor’s.
Three things that move the needle fast
Turn on phishing-resistant MFA for every account that touches donor or financial data. Run an access review this quarter and switch off logins for anyone who has left. And write a one-page breach response plan now, while you’re calm — not at 9pm on a Friday when something has already gone wrong. The OAIC’s new quick-reference guide is a solid starting template, and none of these three steps needs a big cheque.
We help Australian not-for-profits get this in place without enterprise budgets — access reviews, MFA rollouts and Essential Eight uplift built around how charities actually work. If a record year for breaches has you wondering where you stand, that’s exactly the conversation to have.
Office of the Australian Information Commissioner, “Data breach notifications increase to all-time high in 2025” (6 July 2026).
Related Guide
IT Services for Not-for-Profits
Learn how we help NFPs operate efficiently and stay compliant.
