02 8987 4501  ·  0406 340 856
Google Reviews
Privacy & Compliance

Health, finance and legal sit at the top of Australia's breach list. That isn't an accident.

Published 8 October 2026

Australia recorded 1,205 notifiable data breaches in 2025, the highest figure since the scheme started in 2018 and 8% up on the year before. Health service providers reported more than anyone else. Financial services came second. Legal, accounting and management services were in the top six. If you're reading this, you're probably in one of them.

Why IT Service Centre
Since 2004Two decades supporting Sydney businesses
2-hour responseDuring business hours, sooner for urgent issues
One partnerSupport, security, networks and cloud, together

The numbers

The Office of the Australian Information Commissioner published its 2025 figures in July. There were 1,205 breach notifications across the year, up from 1,112 in 2024. Malicious or criminal activity accounted for 716 of them, a little under 60%, with the rest split between human error and system fault.

The sector breakdown is the part worth sitting with. Health service providers reported 225 notifications, 19% of everything. Financial services reported 157. Australian Government bodies 118, business and professional associations 103, education 81, and legal, accounting and management services 81. Privacy Commissioner Carly Kind described the threat to Australian organisations as "substantial and rising year on year".

Why those sectors, specifically

It isn't because they're wealthy or large. Plenty of the practices in those numbers have fewer than ten staff. It's what the records contain.

A dental or medical practice holds Medicare numbers, clinical history, identity documents and next-of-kin details, often going back a decade, usually in a system nobody has audited since it was installed. An accounting firm holds tax file numbers, bank details and a clear picture of what a client is worth. A law firm holds the things a client would pay to keep quiet: family circumstances, disputes, settlements. All of that has resale value or extortion value in a way that a retailer's order history does not.

Put that next to the second fact, which is that a nine-person practice has no security team, no one watching logs, and a practice manager already doing three jobs. High-value records, thin defences. The list writes itself.

What the notifications actually describe

Read enough of these and the pattern in small practices turns out to be unremarkable. Three things come up again and again.

A mailbox gets compromised, usually through a convincing sign-in page rather than anything clever. Whoever is in there can read every message that mailbox has ever received, which in a clinic or a firm is years of attachments. That's one control: multi-factor authentication on every account, plus conditional access so a sign-in from an unexpected place gets challenged. We've written about how far a single login usually reaches.

An email goes to the wrong person. Someone picks the second Sarah in the autocomplete list, or attaches the wrong file, or replies to all on a thread they shouldn't have. This is the most common human-error breach there is and it's fixed with dull measures: a short delay on outbound mail so it can be recalled, external-recipient warnings turned on, and data loss prevention rules that flag a message carrying what looks like patient or client records.

A device leaves the building. A laptop in a car, a phone at a cafe. Full disk encryption and a working remote wipe path turn that from a notifiable breach into a bad afternoon, and both are already included in what you're paying Microsoft.

Reportable doesn't mean large

The threshold that trips most small practices up is this one. The test under the Notifiable Data Breaches scheme is whether serious harm is likely, not how many records were involved. One email containing a patient list is reportable. A single mailbox with a decade of client correspondence in it is reportable. Practices routinely assume the bar is thousands of records and a newspaper story, and then lose time arguing about it while the thirty-day clock runs.

That clock starts when you become aware, which is earlier than most people would like it to be. We looked at how a clinic lost most of its window to exactly that question.

What to do with this

The number to aim for isn't zero incidents, because nobody achieves that. It's zero incidents you couldn't detect, contain and explain.

Four things get you most of the way. Know which systems hold personal information, written down, including the ones that aren't the main one. Know who can reach each system and whether that still matches what their job needs. Know how quickly you'd actually find out, which for most practices means someone is looking at sign-in alerts rather than hoping. And have the breach decision written before you need it: who gets called, who decides whether harm is likely, what gets preserved before anyone starts cleaning up.

If your practice has recently become a reporting entity under the AML reforms, that last point stopped being optional. We've covered what Tranche 2 did to your privacy obligations separately.

In one of those sectors?

Let's see how you'd find out.

We map where your personal information sits, who can reach it, and how fast an unusual sign-in would reach someone who can act on it.

Start a conversation