Egidio
Country report · 2025-2026

Australian data breaches: the raw material behind scams

A data breach rarely stays contained to the organisation that was hit. Once your name, address or account details are out, they become the raw material for a scam call built specifically around you — not a random guess.

What the OAIC records

1,205
Data breach notifications received by the Office of the Australian Information Commissioner in 2025 — the highest number since the Notifiable Data Breaches scheme began in 2018, up 8% on the 1,112 notified in 2024.
OAIC, Notifiable Data Breaches statistics, published 6 July 2026.
716
Of those notifications attributed to malicious or criminal activity — around 59% of the total, with cyber hacking the single leading cause.
OAIC, Notifiable Data Breaches statistics, 2025.
225
Notifications from health service providers, the most affected sector at 19% of the total — ahead of financial services (157) and Australian Government agencies (118).
OAIC, Notifiable Data Breaches statistics, 2025.
82%
Australians who say they are concerned about data breaches, up from 74% in 2023 — a concern the year's incidents did little to ease.
OAIC, Australian Community Attitudes to Privacy Survey, 2026.

Health is the most-notified sector in Australia, and that ordering matters. A medical record cannot be reset the way a password or a card number can, and it carries exactly the kind of detail — a provider name, a recent appointment, a condition — that makes an unsolicited call sound like it comes from someone entitled to know.

Origin Energy: a case study in what "confirmed" means

2 July 2026
Origin Energy receives emails from an individual claiming to have accessed customer records. The company does not initially treat the threat as credible: at that point there is no evidence that customer data has actually been reached.
22-23 July 2026
The claimant supplies proof. Origin announces publicly that it is investigating a potential security incident which may involve unauthorised access to some customers' data, and notifies the Australian Cyber Security Centre, the Australian Federal Police and the OAIC. Journalists shown a sample of records are unable to independently verify that the data is genuine — at this stage the scale is still an allegation.
28 July 2026
Origin confirms that around 900,000 current and former customers had data accessed: names, addresses, dates of birth, phone numbers, account details and partial payment information such as the last four digits of a card or the BSB and last three digits of a bank account. The company said it did not believe full credit card or bank account details were included.

Three weeks separate the first contact from the confirmed figure, and the number only became citable at the end of that process. This is the ordinary shape of a breach disclosure, not an unusual one — which is why we do not treat an attacker's opening claim as a count, and why a figure that changes is not evidence of dishonesty but of an investigation still running.

Beyond the household names

💳youX — a database left open for about ten months

The lending platform youX was at the centre of a breach affecting a reported 444,000 borrowers and around 800 broker organisations. According to the attacker's own account, the exposed database had been flagged by a security researcher roughly ten months before it was exploited. Also claimed stolen: 8,075 password hashes, reportedly stored using MD5, an algorithm considered broken for password use. The technical claims are the attacker's and have not been independently re-verified by Egidio. See the full dossier.

Security research disclosures and breach analysis, 2026.

🏥Health providers — the most-notified sector

Health services accounted for 225 of the 1,205 notifications in 2025, roughly one in five, making it the most affected sector for the year. The OAIC publishes the sector totals but not a per-incident count of individuals affected, so the number of Australians touched by health breaches specifically is not a figure we can state — only that the sector reports more breaches than any other.

OAIC, Notifiable Data Breaches statistics, 2025.

Method note: the OAIC's statistics count notifications, not people. A single notification can cover one individual or several hundred thousand, and the regulator does not publish a national total of affected Australians. Anyone quoting such a total is estimating — we would rather say so than repeat it.

🔒 An energy account, a gym membership, a loan application — none of it looks like "banking" data. That is exactly what makes it useful to a scammer: a caller who knows your energy retailer and your billing history sounds like someone with a legitimate reason to be calling. See how a leak becomes a scam script.

The vocabulary to know

Have I Been Pwned

A free service built by security researcher Troy Hunt: enter your email to check whether it appears in a known data breach.

Credential stuffing

An attacker takes credentials stolen in one breach and tries them en masse on other sites, betting that you reused the same password elsewhere.

Password spraying

The reverse of classic brute-forcing: an attacker tries one very common password across a large number of different accounts, to stay under detection thresholds.

MFA fatigue

An attacker who already has your password triggers a flood of push notification approval requests, hoping you'll eventually tap "approve" out of annoyance or mistake.

SIM swap, another technique that depends directly on leaked personal data, is detailed in the glossary.

🔒 Your data may have leaked through no fault of your own — but protection downstream is still possible. Egidio recognises the patterns of calls built from stolen data, even when they are personalised. See how Medusa works.

Other markets we cover

The OAIC publishes Australia's notification data. Other national regulators run their own tallies, and they point the same direction.

🇺🇸United States — a record 3,322 compromises

The Identity Theft Resource Center tracked 3,322 data compromises in 2025, an all-time record and a 79% rise over five years, with 278.8 million victim notices issued. See our US data breaches report.

ITRC, 2025 Annual Data Breach Report.

🇬🇧United Kingdom — 3,600 incidents in one quarter

The UK's Information Commissioner's Office received 3,600 incident reports in the fourth quarter of 2025 alone, up 16% year on year, though 77% were non-cyber. See our UK data breaches report.

ICO, Data Security Incident Trends dashboard, Q4 2025.

Go further

Frequently asked questions

How can I check if my data has been exposed?

Have I Been Pwned (haveibeenpwned.com) is a free service, built by security researcher Troy Hunt, that lets you check whether your email address appears in a known data breach.

How many data breaches are reported in Australia?

The Office of the Australian Information Commissioner received 1,205 data breach notifications in 2025, the highest number since the Notifiable Data Breaches scheme began in 2018 and an 8% increase on the 1,112 notified in 2024. Around 59% of them, 716 notifications, were attributed to malicious or criminal activity.

How many Origin Energy customers were affected?

Origin Energy confirmed on 28 July 2026 that around 900,000 current and former customers had data accessed, including names, addresses, dates of birth, phone numbers, account details and partial payment information. The company said it did not believe full credit card or bank account details were included.

Which sector reports the most data breaches in Australia?

Health service providers, with 225 notifications in 2025, around 19% of the total — ahead of financial services on 157 and Australian Government agencies on 118. A medical record cannot be reset the way a password or card number can, which is part of why the sector is so heavily targeted.

Cite this page Egidio — The Threat Laboratory, "Australian data breaches: the raw material behind personalised scams", egidio.app/en-au/laboratoire/australia-data-breaches/. Licensed CC BY 4.0.

Free to reuse, including commercially, with attribution. Reuse terms.