What the OAIC records
Health is the most-notified sector in Australia, and that ordering matters. A medical record cannot be reset the way a password or a card number can, and it carries exactly the kind of detail — a provider name, a recent appointment, a condition — that makes an unsolicited call sound like it comes from someone entitled to know.
Origin Energy: a case study in what "confirmed" means
Three weeks separate the first contact from the confirmed figure, and the number only became citable at the end of that process. This is the ordinary shape of a breach disclosure, not an unusual one — which is why we do not treat an attacker's opening claim as a count, and why a figure that changes is not evidence of dishonesty but of an investigation still running.
Beyond the household names
💳youX — a database left open for about ten months
The lending platform youX was at the centre of a breach affecting a reported 444,000 borrowers and around 800 broker organisations. According to the attacker's own account, the exposed database had been flagged by a security researcher roughly ten months before it was exploited. Also claimed stolen: 8,075 password hashes, reportedly stored using MD5, an algorithm considered broken for password use. The technical claims are the attacker's and have not been independently re-verified by Egidio. See the full dossier.
Security research disclosures and breach analysis, 2026.🏥Health providers — the most-notified sector
Health services accounted for 225 of the 1,205 notifications in 2025, roughly one in five, making it the most affected sector for the year. The OAIC publishes the sector totals but not a per-incident count of individuals affected, so the number of Australians touched by health breaches specifically is not a figure we can state — only that the sector reports more breaches than any other.
OAIC, Notifiable Data Breaches statistics, 2025.Method note: the OAIC's statistics count notifications, not people. A single notification can cover one individual or several hundred thousand, and the regulator does not publish a national total of affected Australians. Anyone quoting such a total is estimating — we would rather say so than repeat it.
The vocabulary to know
Have I Been Pwned
A free service built by security researcher Troy Hunt: enter your email to check whether it appears in a known data breach.
Credential stuffing
An attacker takes credentials stolen in one breach and tries them en masse on other sites, betting that you reused the same password elsewhere.
Password spraying
The reverse of classic brute-forcing: an attacker tries one very common password across a large number of different accounts, to stay under detection thresholds.
MFA fatigue
An attacker who already has your password triggers a flood of push notification approval requests, hoping you'll eventually tap "approve" out of annoyance or mistake.
SIM swap, another technique that depends directly on leaked personal data, is detailed in the glossary.
Other markets we cover
The OAIC publishes Australia's notification data. Other national regulators run their own tallies, and they point the same direction.
🇺🇸United States — a record 3,322 compromises
The Identity Theft Resource Center tracked 3,322 data compromises in 2025, an all-time record and a 79% rise over five years, with 278.8 million victim notices issued. See our US data breaches report.
ITRC, 2025 Annual Data Breach Report.🇬🇧United Kingdom — 3,600 incidents in one quarter
The UK's Information Commissioner's Office received 3,600 incident reports in the fourth quarter of 2025 alone, up 16% year on year, though 77% were non-cyber. See our UK data breaches report.
ICO, Data Security Incident Trends dashboard, Q4 2025.Go further
Frequently asked questions
How can I check if my data has been exposed?
Have I Been Pwned (haveibeenpwned.com) is a free service, built by security researcher Troy Hunt, that lets you check whether your email address appears in a known data breach.
How many data breaches are reported in Australia?
The Office of the Australian Information Commissioner received 1,205 data breach notifications in 2025, the highest number since the Notifiable Data Breaches scheme began in 2018 and an 8% increase on the 1,112 notified in 2024. Around 59% of them, 716 notifications, were attributed to malicious or criminal activity.
How many Origin Energy customers were affected?
Origin Energy confirmed on 28 July 2026 that around 900,000 current and former customers had data accessed, including names, addresses, dates of birth, phone numbers, account details and partial payment information. The company said it did not believe full credit card or bank account details were included.
Which sector reports the most data breaches in Australia?
Health service providers, with 225 notifications in 2025, around 19% of the total — ahead of financial services on 157 and Australian Government agencies on 118. A medical record cannot be reset the way a password or card number can, which is part of why the sector is so heavily targeted.
Egidio — The Threat Laboratory, "Australian data breaches: the raw material behind personalised scams", egidio.app/en-au/laboratoire/australia-data-breaches/. Licensed CC BY 4.0.
Free to reuse, including commercially, with attribution. Reuse terms.