Author: Dan Briggs | Published: 23 July 2026 | Reading time: 16 minutes
The Office of the Australian Information Commissioner has just confirmed what most of us handling incident calls already suspected: 2025 was the worst year on record for data breach notifications in Australia. The OAIC received 1,205 notifications under the Notifiable Data Breaches (NDB) scheme in the 2025 calendar year, an 8% rise on 2024 and the highest total since the scheme began in 2018. Financial services, business and professional associations, and legal, accounting and management firms are among the fastest-growing categories — not just the large banks and hospitals the headlines usually focus on. If your business holds client files, financial records or health information, this report is a signal to check your own exposure before you become one of next year’s statistics.
The 2025 numbers, and what actually changed
On 6 July 2026, the OAIC published its statistics for the full 2025 calendar year under the Notifiable Data Breaches scheme. The headline number is 1,205 notifications, up 8% from 1,112 in 2024, and the highest annual total since the mandatory reporting scheme started in February 2018. Malicious or criminal attack remained the dominant cause, responsible for 716 of the 1,205 notifications reported, or roughly 59% of the total.
The sector breakdown is where it gets interesting for readers of this paper. Health service providers topped the list again, with 225 notifications (19% of the total) — a result of both the sensitivity of health records and the sheer number of covered entities. But the next tier down is not what most business owners picture when they hear “data breach”: financial services (157 notifications), the Australian Government (118), business and professional associations (103), and education (81) and legal, accounting and management services (81, tied for fifth) rounded out the top five sectors by volume.
| Sector | Notifications in 2025 | Share of total |
|---|---|---|
| Health service providers | 225 | 19% |
| Financial services | 157 | 13% |
| Australian Government | 118 | 10% |
| Business and professional associations | 103 | 9% |
| Education | 81 | 7% |
| Legal, accounting and management services | 81 | 7% |
Put together, financial services, business and professional associations, and legal, accounting and management services accounted for 341 of the 1,205 notifications lodged in 2025 — more than one in four, by our own tally of the OAIC’s published sector breakdown. That is a meaningful concentration in exactly the kind of advisory, accounting, legal and financial businesses that make up a large share of Australia’s professional services sector, and it is the reason this report deserves more attention from that audience than the topline “record year” headline suggests.
Why a government statistics release matters to your business
It is easy to read a regulator’s statistics release as background noise — a once-a-year data point for compliance teams to file away. That reading misses two things that matter for Australian SMBs and mid-market firms specifically.
First, the NDB scheme only captures breaches that were serious enough to require notification under Part IIIC of the Privacy Act — meaning a breach “likely to result in serious harm” to an affected individual. The scheme’s own numbers are therefore a floor, not a ceiling, on how many incidents actually happened last year. Smaller, contained incidents that did not clear the “serious harm” threshold are not counted at all. If notified breaches are up 8%, the underlying attempt volume is almost certainly higher again.
Second, Australian Privacy Commissioner Carly Kind made a point in the OAIC’s own release that is easy to miss: the threat to Australian businesses and organisations “is substantial and rising year on year.” The regulator is not just tracking a number, it is responding to it — the OAIC used this release to publish a new quick reference guide for entities with NDB obligations, specifically because it expects a growing number of businesses to need one. That is a reasonable early signal that examination of smaller entities’ compliance is likely to increase, not decrease, from here.
Quotable fact: The OAIC received 1,205 data breach notifications in the 2025 calendar year, an 8% increase on 2024’s 1,112 and the highest annual total since the Notifiable Data Breaches scheme began in February 2018, according to the OAIC’s 6 July 2026 statistics release.
Professional and financial services: the fastest-growing exposure
We work with accounting practices, financial advisory firms, legal practices and other professional services businesses across Sydney’s Northern Beaches, greater Sydney, Central West NSW and Brisbane, and the pattern in the OAIC’s sector data matches what we are seeing on the ground with these clients. It is not the largest, most heavily regulated firms that tend to trip over a notifiable breach. It is the smaller and mid-sized practices that have added a new piece of the technology stack in the past year — a new practice management platform, an outsourced bookkeeping arrangement, a new HR or payroll provider — without extending their access reviews, multi-factor authentication requirements or vendor risk checks to cover it.
A financial advisory practice in Orange or Dubbo with eight staff typically has the same client data sensitivity as a metro firm of the same size, but rarely has the same dedicated IT or compliance resourcing to match. The same goes for boutique accounting and legal practices on Sydney’s Northern Beaches, where we regularly see firms running a capable core Microsoft 365 environment but with looser controls on the practice management software, client portal or e-signature tool bolted on alongside it. Attackers do not care whether the weak point is the core platform or the add-on — a compromised third-party integration with access to client files creates the same notification obligation either way.
This matters because professional services firms hold a disproportionately sensitive mix of data for their size: tax file numbers, financial account details, estate and family information, medical records referenced in legal matters, and identity documents collected for AML/CTF or know-your-client checks. A single compromised mailbox or file-sharing link at a five-person advisory firm can trigger the same OAIC notification requirements — and reputational exposure — as a breach at a much larger organisation.
What the Notifiable Data Breaches scheme actually requires
The NDB scheme, established under Part IIIC of the Privacy Act 1988 (Cth), applies to organisations covered by the Australian Privacy Principles — broadly, businesses with annual turnover above $3 million, plus health service providers, credit reporting bodies and a handful of other categories regardless of size. If you are not sure whether your business is covered, assume it might be if you handle health information, financial data, or provide services under a government contract; the small business exemption has more exceptions than most owners realise.
The scheme’s mechanics are straightforward in principle:
- Suspect a breach, assess it. If you have reasonable grounds to suspect an eligible data breach may have occurred, you must carry out a reasonable and expeditious assessment, and take all reasonable steps to complete it within 30 days.
- Serious harm test. If the assessment concludes the breach is likely to result in serious harm to any individual whose information was involved, it becomes an “eligible data breach” and notification is mandatory.
- Notify the OAIC and affected individuals. Notification must happen as soon as practicable, via a statement to the Commissioner and direct or published notice to affected individuals, covering what happened, what information was involved, and what people should do in response.
- Remediation counts. If you can remediate the breach before serious harm eventuates — for example, remotely wiping a lost device before it is accessed — notification may not be required. Document the remediation carefully; the OAIC will expect evidence, not just an assertion.
The consequences of getting this wrong have increased sharply. The Privacy and Other Legislation Amendment Act 2024 lifted maximum penalties for serious or repeated interferences with privacy to whichever is greatest of $50 million, three times the value of any benefit obtained, or 30% of adjusted turnover during the breach period. Very few Australian SMBs will ever face a penalty at that ceiling, but the direction of travel — higher penalties, more OAIC guidance, more public reporting — is unambiguous.
Where this connects to the ransomware payment reporting rules
The NDB scheme is not the only reporting obligation that has tightened recently. Since 30 May 2025, businesses with annual turnover of $3 million or more, along with all entities responsible for critical infrastructure assets, have been required to report ransomware payments and extortion demands to the Australian Signals Directorate within 72 hours, under the Cyber Security (Ransomware Payment Reporting) Rules 2025 made pursuant to the Cyber Security Act 2024. The Department of Home Affairs ran an education-first enforcement approach through the back half of 2025; from 1 January 2026, the regime moved into full compliance and enforcement mode, with civil penalties of up to $19,800 for non-reporting.
The overlap matters in practice: a ransomware incident that involves personal information will almost always trigger both obligations at once — the ransomware payment report to ASD, and a potential NDB notification to the OAIC if personal information was accessed or exfiltrated. Firms that have only mapped one of these two obligations into their incident response plan are missing half the picture. We covered the ransomware reporting rules and the 72-hour obligation in more detail in our recent piece on ransomware rates among Australian organisations, which is worth reading alongside this one if ransomware sits anywhere on your risk register.
What’s actually causing these breaches
Malicious or criminal attack accounted for 716 of the 1,205 notifications reported in 2025 — about 59% of the total, per the OAIC’s release. That figure sits close to the pattern the OAIC reported for the first half of 2025, when malicious or criminal attacks made up 59% of notifications and human error accounted for 37%, with the remainder attributed to system faults. Human error — sending information to the wrong recipient, misconfiguring a file share, failing to redact a document properly — is not a footnote in these figures; it is a substantial, persistent share of every reporting period the OAIC has published.
Within the malicious and criminal category, the mechanics we see most often in Australian client environments break down into a few repeat patterns:
- Compromised credentials, not exotic exploits. Phishing and credential-stuffing attacks against email and cloud accounts remain the most common entry point, particularly where multi-factor authentication is inconsistently enforced across a practice’s full user base, not just its administrators.
- Third-party and vendor compromise. Attackers increasingly go after smaller suppliers — IT providers, payroll bureaus, marketing agencies, practice management software vendors — specifically because they hold aggregated access to many downstream clients’ data at once.
- Social engineering against staff, not systems. Attackers posing as IT support or a senior partner to talk a staff member into resetting a password or approving a payment continue to work because the request looks routine. We wrote about one recent variant of this in our piece on fake IT-support calls targeting Australian staff.
- Insider and departing-staff risk. Unauthorised access or exfiltration by an employee or contractor with legitimate credentials is harder to detect than an external attack and often surfaces only once data has already left the building — as in the NSW Treasury case we covered earlier this year, which carries direct lessons for wealth managers and other advisory firms handling sensitive client files.
A 90-day action checklist
None of the individual actions below are exotic. What we consistently see separating firms that handle a breach assessment smoothly from those that do not is whether these steps were done before an incident, not during one.
| Action | Why it matters | Suggested timeframe |
|---|---|---|
| Map what personal information you hold, where, and who can access it | You cannot assess “serious harm” or scope a breach quickly if you do not already know what data lives where | Weeks 1–2 |
| Confirm MFA is enforced for every user, not just admins, across email, file storage and any client portal | Compromised credentials remain the leading entry point into notifiable breaches | Weeks 1–2 |
| List every third party with access to client or staff data (IT provider, payroll, practice management software, marketing tools) | Vendor compromise is a growing share of incidents and is often missed in internal risk reviews | Weeks 2–4 |
| Document (or update) a breach response plan that names who assesses suspected breaches and against what timeframe | The NDB scheme expects assessment “as soon as practicable” and within 30 days — a plan written during an incident is too slow | Weeks 3–5 |
| Confirm your plan explicitly covers both NDB notification and ransomware payment reporting obligations | The two schemes have different regulators, different triggers and different timeframes; most incident plans only cover one | Weeks 4–6 |
| Run a real backup restore test on at least one business-critical system | A tested recovery process shortens both downtime and the “serious harm” window that drives notification decisions | Weeks 5–8 |
| Brief all staff, not just IT-facing ones, on how to spot fake IT-support and impersonation calls | Social engineering against non-technical staff continues to be a reliable way past technical controls | Weeks 6–9 |
| Review your Essential Eight maturity against Maturity Level One and note any gaps for the board or leadership team | Patching, MFA and tested backups sit at the centre of nearly every avoidable notifiable breach | Weeks 8–12 |
Baseline controls: Essential Eight and beyond
None of the sector-specific advice above replaces a solid technical baseline. The Australian Signals Directorate’s Essential Eight remains the reference point for that baseline in Australia, even as the ASD works through a multi-year transition to a broader framework called Essentials. If you have already invested in Essential Eight controls — patching, application control, restricted admin privileges, MFA and tested backups — that investment carries forward into the new framework, so there is no reason to pause current programs while waiting for the transition to land. We covered exactly what is changing, and what stays the same, in our recent piece on the ASD’s Essential Eight retirement.
For a professional or financial services firm specifically, three controls do the most work against the breach patterns in this report: phishing-resistant multi-factor authentication on every account with access to client data, not just administrator accounts; role-based access so a compromised junior staff account cannot reach the whole client file store; and a documented, tested process for offboarding both staff and third-party vendor access promptly when a relationship ends.
If it happens to you: the first 72 hours
When a suspected breach lands on your desk, the sequence that keeps both your legal exposure and your client relationships intact looks roughly like this:
- Contain first, assess in parallel. Isolate affected systems or accounts immediately — disable compromised credentials, revoke active sessions, pull a compromised device off the network — while your assessment of scope and harm begins alongside, not after, containment.
- Preserve evidence. Do not wipe or rebuild affected systems before you have captured logs, timestamps and access records. You will need this evidence both for your NDB assessment and, if ransomware or extortion is involved, for the ASD report.
- Run the dual-obligation check. Ask two questions in the same breath: is this likely to cause serious harm to an individual (NDB trigger), and does this involve a ransomware payment or extortion demand (Cyber Security Act trigger)? They can both be “yes” at once, and each has its own clock running.
- Brief leadership honestly and early. Under-scoping a breach to leadership in the first 24 hours is one of the most common reasons organisations miss their 30-day assessment window — decisions get delayed because the true scope only becomes clear weeks later.
- Get an outside read before you notify. A second set of eyes — your IT provider, a privacy lawyer, or both — on the “serious harm” assessment reduces the risk of both under-notifying (a compliance failure) and over-notifying (unnecessary alarm to clients and reputational cost).
All IT supports Australian professional services, financial services, hospitality and not-for-profit clients across Sydney, Central West NSW, Brisbane and Melbourne with exactly this kind of incident planning and response — not as a one-off document, but as a plan tested and refined before you ever need it.
Frequently asked questions
Does the Notifiable Data Breaches scheme apply to my small business?
It applies to organisations covered by the Australian Privacy Principles, which generally means businesses with annual turnover above $3 million, plus health service providers and a number of other categories regardless of size. Many smaller professional services and financial advisory firms are covered because they handle health information, provide services under a government contract, or otherwise fall outside the small business exemption, so it is worth checking your specific position rather than assuming turnover alone settles the question.
What counts as an “eligible data breach” that must be notified?
A breach becomes notifiable once your assessment concludes it is likely to result in serious harm to an individual whose personal information was involved. Not every incident clears this bar, but organisations must complete a reasonable and expeditious assessment, generally within 30 days of first suspecting a breach, to reach that conclusion rather than assume it away.
How is the ransomware payment reporting obligation different from the NDB scheme?
The ransomware payment reporting obligation, in force since 30 May 2025 under the Cyber Security Act 2024, requires businesses with turnover of $3 million or more to report ransomware payments and extortion demands to the Australian Signals Directorate within 72 hours. It is a separate obligation from NDB notification to the OAIC, has a different regulator and a different timeframe, and can apply at the same time as an NDB obligation if the same incident involves both a ransom payment and exposure of personal information.
Why are financial and professional services firms showing up more in the 2025 figures?
OAIC’s 2025 data places financial services, business and professional associations, and legal, accounting and management services among the top five reporting sectors by volume, together accounting for more than one in four notifications lodged during the year. These firms typically hold a concentrated mix of sensitive financial, identity and health-adjacent data relative to their size, often across a growing stack of practice management and outsourced service platforms, which increases both the attack surface and the number of incidents that clear the serious harm threshold.
What is the single most useful thing a small professional services firm can do this quarter?
Enforce multi-factor authentication on every account with access to client data, not only administrator accounts, and confirm it explicitly covers any third-party practice management, client portal or file-sharing platform bolted onto your core email and document systems. Compromised credentials remain the most common entry point into the incidents that end up as notifiable breaches, and MFA is the single control most likely to stop that entry point cold.
Talk to All IT Services
If you are not confident your business could complete a breach assessment inside the OAIC’s 30-day window, or you are not sure whether your incident response plan actually covers both the NDB scheme and the ransomware payment reporting rules, that is worth fixing before it is tested for real. All IT Services works with professional services, financial services, hospitality and not-for-profit organisations across Sydney, Central West NSW, Brisbane and Melbourne on exactly this kind of preparation. Call us on 1300 425 548 or get in touch via our contact page for a straight assessment of where your data protection and breach response planning currently stand.
Sources
- OAIC: Data breach notifications increase to all-time high in 2025, new NDB stats show (6 July 2026)
- OAIC: Notifiable Data Breaches scheme
- OAIC: Quick reference guide for responding to data breaches
- Department of Home Affairs: Cyber Security Act 2024
- Department of Home Affairs: Mandatory ransomware and cyber extortion payment reporting factsheet
- Federal Register of Legislation: Cyber Security (Ransomware Payment Reporting) Rules 2025
- Australian Signals Directorate: Annual Cyber Threat Report 2024–25 factsheet for businesses and organisations
