The biggest data breaches in Australia now stretch well past the Optus and Medibank era, and as of July 2026 the 23 largest and most consequential incidents range from the Ticketmaster and Live Nation Snowflake campaign, Canva, Latitude, and MediSecure to Optus and Medibank. Entries are ranked primarily by the number of records affected, with a few high-notability incidents included regardless of scale, and every disputed or attacker-claimed figure is flagged so you can tell a confirmed count from a claim.
What connects these cases is rarely exotic. Stolen third-party credentials, an exposed interface with no authentication, missing multi-factor authentication, and data retained long after it was needed appear again and again. For each incident below you'll find the records affected, the key dates, the sector, the attack vector, the data exposed, and the regulatory aftermath, framed by the latest figures from Australia's privacy regulator.
Australian breach reporting reached a new high in 2025. The Office of the Australian Information Commissioner (OAIC) received 1,205 data breach notifications in the 2025 calendar year, an 8% increase on 2024 (1,112 notifications) and the highest annual total since the Notifiable Data Breaches scheme commenced in February 2018. Of those, 716 notifications (around 59%) were attributed to malicious or criminal attack, and health service providers were the most frequently affected sector with 225 notifications, roughly 19% of the total.
The half-year data shows the same pressure from a different angle. In the January to June 2025 period the OAIC recorded 532 notifications, a 10% decrease on the preceding record six months, which it characterized as breaches staying persistently high rather than genuinely improving. Human error accounted for 37% of breaches (193 notifications) in that period, up from 29%, meaning more than a third of Australian notifiable breaches are self-inflicted rather than adversarial.
The list runs from the largest record counts to smaller but nationally significant incidents. Where a figure is disputed, estimated, or drawn from breach-tracking aggregation rather than a company or regulator confirmation, that is noted so the caveat travels with the number.
Records affected: Up to 560 million customers globally, a figure claimed by the attackers, disputed, and never confirmed by Live Nation; Australian Ticketmaster customers were among those affected.
Date of breach: Unauthorized activity from around April 2, 2024, identified May 20, 2024.
Date disclosed: Claimed by attackers May 28, 2024; confirmed by Live Nation in a Securities and Exchange Commission filing May 31, 2024.
Sector: Ticketing and entertainment.
Attack vector: Compromised credentials used against a third-party cloud database environment (Snowflake) that lacked multi-factor authentication, part of the wider UNC5537 and ShinyHunters campaign.
Data exposed: Names, addresses, email addresses, phone numbers, and partial payment card data.
The broader campaign was not a breach of Snowflake itself but a mass sweep against tenants that had not enabled multi-factor authentication, hitting an estimated 165 organizations and becoming the defining supply-chain identity failure of 2024.
Aftermath: Two suspects were arrested in connection with the campaign, and Snowflake began enforcing multi-factor authentication by default for new accounts. Class actions were filed in multiple jurisdictions.
Source: BleepingComputer
Records affected: Approximately 139 million users.
Date of breach: May 24, 2019.
Date disclosed: May 24, 2019.
Sector: Technology and design software (Australian-headquartered).
Attack vector: Intrusion attributed to the actor known as GnosticPlayers, detected while in progress.
Data exposed: Names, usernames, email addresses, city and country data, and bcrypt-hashed passwords for around 61 million users, plus Google and Facebook OAuth login tokens for some users.
Canva remains the largest breach by record count of an Australian-headquartered company. It detected the intrusion while it was still under way and disclosed the same day, which was unusually fast for 2019.
Aftermath: In January 2020 around four million passwords decrypted from the bcrypt hashes were published, which escalated the risk profile of an incident that had initially looked contained. Canva force-reset passwords and notified users, and no regulator determination followed.
Source: Huntress: Canva data breach | OAIC Notifiable Data Breaches scheme
Records affected: Approximately 14 million customer records, including 7.9 million Australian and New Zealand driver license numbers, 53,000 passport numbers, and 6.1 million records dating back to at least 2005.
Date of breach: Detected March 16, 2023.
Date disclosed: March 16, 2023, with the scope revised sharply upward on March 27, 2023.
Sector: Consumer finance and non-bank lending.
Attack vector: Stolen employee credentials used to access two third-party service providers holding Latitude customer data.
Data exposed: Names, addresses, dates of birth, phone numbers, driver license numbers, passport numbers, and Medicare numbers.
The initial disclosure put the impact at around 328,000 records, then revised it to 14 million within eleven days, a scale of revision that badly damaged confidence in early breach estimates. Much of the exposed data related to customers who had long stopped using Latitude, exposing the risk of indefinite data retention, a pattern seen across major financial services breaches.
Aftermath: Latitude publicly refused to pay the ransom demand. The OAIC and New Zealand's Office of the Privacy Commissioner opened a joint investigation, and a class action was filed in the Federal Court of Australia.
Source: Latitude Financial cyber incident updates | OAIC media centre
Records affected: Approximately 12.9 million Australians.
Date of breach: Around April 13, 2024.
Date disclosed: May 16, 2024, with the 12.9 million figure confirmed July 19, 2024.
Sector: Healthcare and electronic prescriptions.
Attack vector: Ransomware; the National Cyber Security Coordinator stated the compromise originated from a third-party vendor.
Data exposed: Names, dates of birth, addresses, Medicare card numbers, Individual Healthcare Identifiers, contact details, and prescription and dispensing records.
MediSecure was one of two national electronic prescription providers, so the breach exposed the medication histories of roughly half the population. Prescription data is deeply revealing because it discloses conditions by inference, which is why healthcare data breaches carry outsized harm, and the company said it could not identify affected individuals precisely because of how legacy data was stored.
Aftermath: MediSecure entered voluntary administration on June 3, 2024, with insufficient funds to continue and no buyer found, which effectively ended any prospect of meaningful remediation. The OAIC opened an investigation, complicated by the insolvency.
Source: National Cyber Security Coordinator MediSecure statement | BleepingComputer
Records affected: Up to 9.8 million customer records; approximately 2.1 million customers had at least one current and valid identification number exposed, and around 10,200 records were published by the attacker.
Date of breach: September 17 to 20, 2022.
Date disclosed: September 22, 2022.
Sector: Telecommunications.
Attack vector: An unauthenticated, publicly exposed API endpoint that required no credentials to query customer records, with enumerable customer identifiers.
Data exposed: Names, dates of birth, phone numbers, email addresses, and for subsets, home addresses, driver license numbers, passport numbers, and Medicare card numbers.
This is the breach that changed Australian privacy law. The exposure of current government identity numbers, rather than just contact data, forced state and territory governments into mass driver license reissuance and prompted emergency amendments to telecommunications regulations.
Aftermath: The Privacy Legislation Amendment (Enforcement and Other Measures) Act 2022 raised maximum corporate penalties to the greater of A$50 million, three times the benefit obtained, or 30% of adjusted turnover. The Australian Communications and Media Authority commenced Federal Court proceedings against Optus in February 2024, and the OAIC commenced its own civil penalty proceedings in August 2025.
Source: OAIC civil penalty action against Optus | ACMA commences proceedings
Records affected: 9.7 million current and former customers, including health claims data for approximately 480,000 people.
Date of breach: Initial access around August 12, 2022; detected October 12, 2022.
Date disclosed: October 13, 2022, with full scope confirmed November 9, 2022.
Sector: Health insurance.
Attack vector: Stolen credentials belonging to a third-party contractor, used to access the corporate network through a virtual private network that did not enforce multi-factor authentication; ransomware group REvil.
Data exposed: Names, dates of birth, addresses, contact details, Medicare numbers, passport numbers for international students, and health claims data for around 480,000 people.
When Medibank refused to pay, the attackers published customer health claims data on the dark web in tranches, including files labeled to identify people who had received sensitive treatment. This was the most deliberately harmful use of stolen data in Australian history, which is what elevates it above Optus and above many of the biggest data breaches globally despite a similar record count.
Aftermath: The OAIC commenced civil penalty proceedings in the Federal Court on June 5, 2024, alleging Medibank interfered with the privacy of 9.7 million Australians; the proceedings remained on foot as of July 2026. The prudential regulator also imposed a A$250 million capital adjustment in June 2023 pending remediation of Medibank's information security environment.
Source: OAIC civil penalty action against Medibank | APRA action against Medibank
Records affected: 5.7 million unique customers, revised down from an initial estimate of up to 6 million.
Date of breach: Detected June 30, 2025.
Date disclosed: July 2, 2025, with the detailed breakdown published July 9, 2025.
Sector: Aviation.
Attack vector: Compromise of a third-party customer service platform used by a Manila-based contact center, via social engineering; attributed to the Scattered Spider and ShinyHunters ecosystem targeting Salesforce-linked environments.
Data exposed: For around 1.2 million customers, name and email address only; for around 2.8 million, name, email, and frequent flyer number; for around 1.7 million, additional combinations of home address, date of birth, phone number, gender, and meal preference. Qantas stated no credit card, financial, or passport data was held in the affected system.
Qantas obtained an interim injunction to restrain publication, but the data was released anyway in October 2025 as part of the ShinyHunters mass extortion campaign against Salesforce customers, demonstrating the practical limits of injunctive relief against anonymous offshore actors.
Aftermath: On July 16, 2026, the OAIC completed its preliminary inquiries and decided not to open a formal investigation, concluding that Qantas did not appear to have breached its obligations under the Privacy Act. Qantas reduced short-term executive bonuses in response.
Source: Qantas Newsroom cyber incident update | Computer Weekly
Records affected: Approximately 2.2 million customers, of whom around 1.2 million had only email addresses exposed.
Date of breach: Detected October 11, 2022.
Date disclosed: October 14, 2022.
Sector: Retail and e-commerce.
Attack vector: A compromised user credential used to access MyDeal's customer relationship management system.
Data exposed: Names, email addresses, phone numbers, delivery addresses, and in some cases dates of birth. MyDeal stated no payment, identity document, or password data was accessed.
Coming three weeks after Optus, the breach landed at the peak of public alarm and helped cement the political consensus behind sharply increased privacy penalties. Woolworths had acquired MyDeal only months earlier, another case of a breach surfacing shortly after an acquisition.
Aftermath: Woolworths notified affected customers and reported the incident to the OAIC. No civil penalty proceedings followed, and the marketplace was later wound down in 2024.
Source: Woolworths Group MyDeal breach notification | BleepingComputer MyDeal breach
Records affected: Approximately 1.1TB of data published of around 1.45TB exfiltrated; no authoritative individual-record count has ever been published, and any figure should be treated as an estimate.
Date of breach: Around April 25, 2023.
Date disclosed: April 28, 2023 (attacker claim); firm confirmation and government notification through mid-2023.
Sector: Legal services (a major provider to Commonwealth, state, and territory governments).
Attack vector: ALPHV and BlackCat ransomware; the firm did not publish the initial access vector.
Data exposed: Client legal files, government advice, employee personal and identity records, and highly sensitive material including insurance, veterans' affairs, and law enforcement data.
Because the firm acted for the Commonwealth and most states, the leak exposed privileged legal advice, government litigation strategy, and personal data held on behalf of an estimated 65 government agencies plus hundreds of private clients. It was the most consequential Australian breach measured by sensitivity of institutional data rather than consumer record count.
Aftermath: The firm obtained a Supreme Court of New South Wales injunction restraining publication, which limited public reporting. The Australian Government coordinated a whole-of-government response, and no civil penalty proceedings had been commenced as of July 2026.
Source: HWL Ebsworth cyber incident statement | National Cyber Security Coordinator
Records affected: Reported as approximately 900,000 current and former customers, an estimated figure drawn from Origin's public confirmation as reported and not yet independently verified.
Date of breach: Not publicly specified at the time of writing.
Date disclosed: July 28, 2026.
Sector: Energy and utilities.
Attack vector: Not disclosed; Origin described the incident as a criminal matter under active investigation.
Data exposed: Not fully itemized in the initial disclosure; Origin said it was working to identify affected customers and the specific data categories involved.
This is the largest disclosed Australian breach of 2026 to date and the most recent addition to the list. Utility customer records typically combine identity data with address history and payment details, a strong foundation for identity fraud.
Aftermath: Origin said it was engaging with the Australian Cyber Security Centre, the National Office of Cyber Security, the Australian Federal Police, and the OAIC. Because the disclosure is recent, all figures here are provisional and should be re-verified before publication.
Source: Rescana Origin Energy data breach analysis
Records affected: 836,120 customer records.
Date of breach: Around June 24, 2023.
Date disclosed: September 8, 2023.
Sector: Retail and bookselling.
Attack vector: Unauthorized access via an external third-party service provider with access to Dymocks' customer records.
Data exposed: Names, dates of birth, email addresses, postal addresses, gender, mobile numbers, and Booklover loyalty account details.
Dymocks discovered the breach only when it was notified that customer data was circulating on the dark web, more than two months after the intrusion. Because loyalty records include purchase-linked profiles, the exposure supports both identity fraud and highly credible phishing.
Aftermath: Dymocks notified customers and the OAIC and engaged forensic investigators. The dataset was subsequently loaded into Have I Been Pwned, and no regulatory penalty followed.
Source: Have I Been Pwned Dymocks
Records affected: Firstmac did not publicly confirm the number of customers affected; the Embargo ransomware group exfiltrated more than 500GB of data.
Date of breach: April 2024.
Date disclosed: April 30, 2024, with the data leaked May 8, 2024.
Sector: Non-bank lending and financial services.
Attack vector: Embargo ransomware group; Firstmac did not publish the initial access vector.
Data exposed: Names, residential addresses, email addresses, phone numbers, dates of birth, external bank account details, driver license numbers, and in some cases passport numbers.
Firstmac is one of Australia's largest non-bank mortgage lenders, and the exposed dataset combined identity documents with bank account details, which is close to a complete identity theft kit. The group published a data leak site entry within days of the intrusion, before Firstmac had notified customers.
Aftermath: Firstmac notified affected customers and reported to the OAIC. No civil penalty proceedings had been commenced as of July 2026.
Source: SecurityAffairs Firstmac data breach
Records affected: Reported as approximately 444,000 Australians; the figure is documented primarily through breach-tracking aggregation and should be verified with youX or the OAIC.
Date of breach: Not publicly specified.
Date disclosed: First half of 2026.
Sector: Financial services technology and broker platform.
Attack vector: Not publicly confirmed.
Data exposed: Reported to include personal and financial information submitted as part of loan application processes.
youX is a platform used by mortgage and car finance brokers to process loan applications, so the records it holds are unusually rich: identity documents, income, employment, liabilities, and bank data submitted for credit assessment. Loan application data is among the highest-value categories for identity fraud because it is assembled specifically to satisfy know-your-customer checks.
Aftermath: Details of regulatory engagement had not been published at the time of writing. Because this rests on aggregated breach-tracking, both the figure and the characterization should be confirmed against a primary source.
Source: Webber Insurance data breaches list
Records affected: Reported as more than 340,000 customers, a figure drawn from breach-tracking aggregation and the organization's own confirmation as reported.
Date of breach: Not publicly specified.
Date disclosed: First half of 2026.
Sector: Arts and culture, events.
Attack vector: Not publicly confirmed.
Data exposed: Customer information; a full itemization had not been published at the time of writing.
The figure is unusually large for a cultural organization and a reminder that ticketing and membership databases held by arts bodies are meaningful targets. Not-for-profit and arts organizations typically hold consumer data at commercial scale while operating on budgets that cannot support commercial-grade security.
Aftermath: No regulatory action had been published at the time of writing. The count should be verified against a direct statement before publication.
Source: Webber Insurance data breaches list
Records affected: Estimated at approximately 300,000 customers, a figure reported through breach-tracking sources rather than a confirmed company disclosure.
Date of breach: Not publicly specified.
Date disclosed: First half of 2026.
Sector: Insurance (car rental insurance).
Attack vector: Not publicly confirmed.
Data exposed: Reported to include personal and policy information.
Insurance policy data typically links identity, vehicle, address, and claims history, and claims records can include medical and incident detail.
Aftermath: No regulatory action had been published at the time of writing. Treat the record count as unverified and confirm it with Prosura or the OAIC before publication.
Source: Webber Insurance data breaches list
Records affected: Approximately 280,000 active iiNet email addresses, around 20,000 active landline numbers, around 10,000 records containing usernames, street addresses and phone numbers, and around 1,700 modem setup passwords.
Date of breach: Confirmed by TPG on August 16, 2025.
Date disclosed: August 20 to 21, 2025.
Sector: Telecommunications and internet service provision.
Attack vector: Stolen credentials belonging to a single iiNet employee, used to access an order management system.
Data exposed: Email addresses, landline numbers, usernames, street addresses, and modem setup passwords. TPG stated the system held no identity documents and no credit card or banking data.
A single set of employee credentials reaching data on 280,000 customers, with no additional authentication barrier evident, showed that Australian telco credential hygiene had not fundamentally improved three years after Optus. The exposure of around 1,700 modem setup passwords is the most operationally dangerous element, since it can enable interference with customer home networks.
Aftermath: TPG revoked the access, engaged external forensics, and notified the OAIC and the Australian Cyber Security Centre. No penalty had been published as of July 2026.
Source: The Register TPG iiNet breach
Records affected: More than 223,000 individuals.
Date of breach: Around February 25, 2022.
Date disclosed: October 27, 2022 (approximately eight months after the breach).
Sector: Healthcare and pathology.
Attack vector: Quantum ransomware group; ACL's Medlab Pathology business was compromised and data exfiltrated.
Data exposed: Names, addresses, dates of birth, Medicare numbers, credit card numbers for around 28,000 individuals, and pathology test results for a subset of patients.
This is the most legally significant Australian data breach case, because it produced the first civil penalty ever imposed under the Privacy Act 1988. ACL was told by the Australian Cyber Security Centre in March 2022 that Medlab data had been published on the dark web and still did not complete a proper assessment or notify the Commissioner for months.
Aftermath: On October 8, 2025, the Federal Court ordered ACL to pay A$5.8 million in civil penalties, comprising A$4.2 million for failing to protect personal information, A$800,000 for failing to assess whether an eligible data breach had occurred, and A$800,000 for failing to notify the Commissioner. The decision established that delay and inadequate assessment are independently punishable.
Source: OAIC Australian Clinical Labs penalties
Records affected: ANU stated the number affected was significantly fewer than the 200,000 people initially feared and never published a precise figure, so no exact count should be stated.
Date of breach: Initial compromise around November 2018.
Date disclosed: June 4, 2019.
Sector: Higher education and research.
Attack vector: A sophisticated actor used spear-phishing that required no click to compromise a senior staff member's credentials, then built custom tooling and multiple attack stations inside the network, evading detection for months.
Data exposed: Names, addresses, dates of birth, contact details, tax file numbers, payroll and bank details, passport details, and student academic records spanning up to 19 years.
ANU published a detailed incident report in October 2019, describing an actor operating at a level normally associated with nation-state intelligence services, and it reframed Australian higher education as a strategic espionage target.
Aftermath: The report drove sector-wide reform through the Australian Cyber Security Centre's engagement with universities. No formal attribution or regulatory penalty followed.
Source: ANU 2018 data breach report
Records affected: 186,000 customers, from 738GB of data comprising approximately 3.8 million documents held in 47 compromised staff email accounts.
Date of breach: March to April 2020.
Date disclosed: May 14, 2020, with the 186,000 figure confirmed September 7, 2020.
Sector: State government and citizen services.
Attack vector: Phishing attack compromising the email accounts of 47 Service NSW staff members.
Data exposed: Driver licenses, Medicare cards, passports, birth certificates, marriage certificates, credit card details, and other documents held in staff email.
The breach was caused not by a database compromise but by the accumulation of citizen identity documents inside ordinary staff email inboxes. The NSW Auditor-General's December 2020 report found the agency had continued unsafe information-handling practices despite known risks and lacked multi-factor authentication on email at the time.
Aftermath: Service NSW funded replacement identity documents and drove mandatory multi-factor authentication rollout across NSW agencies.
Source: NSW Auditor-General report
Records affected: Approximately 100,000 individuals across Australia and New Zealand.
Date of breach: December 5, 2023.
Date disclosed: December 2023, with a detailed breakdown published March 2024.
Sector: Automotive and consumer finance.
Attack vector: Akira ransomware, with initial access reported via a compromised remote access account.
Data exposed: For up to 10% of affected individuals, government identification, including around 4,000 Medicare cards, 7,500 driver licenses, 220 passports, and 1,300 tax file numbers; others had loan-related statements, employment or salary information, or dates of birth exposed.
Because the finance arm held identity and income documentation for customers who had financed vehicle purchases, the compromise reached deep identity data. Akira published data on its leak site after Nissan declined to pay.
Aftermath: Nissan offered credit monitoring and identity document replacement support, and no penalty proceedings followed.
Source: SecurityWeek Nissan data breach
Records affected: 940.7GB of data exfiltrated; the number of patients affected has not been officially confirmed and any patient count should be treated as unverified.
Date of breach: Network accessed January 31, 2025; data exfiltrated February 14, 2025.
Date disclosed: February 19, 2025, with data published by the attackers shortly afterward.
Sector: Healthcare and assisted reproductive technology.
Attack vector: Compromise of a Citrix server followed by exfiltration to an attacker-controlled cloud server; the Termite ransomware and extortion group claimed responsibility.
Data exposed: Names, addresses, contact details, Medicare numbers, private health insurance details, medical histories, and fertility treatment records.
Genea is one of Australia's largest IVF providers, and the exposed dataset includes some of the most intimate health information a person can hold. The case cemented Australian healthcare as the sector where breach harm is most acute, since medical history cannot be reissued like a driver license.
Aftermath: Genea obtained a Supreme Court of New South Wales injunction restraining dissemination, and Termite published the data anyway. A class action investigation was launched, and as of July 2026 no OAIC determination had been published.
Source: BleepingComputer Genea breach
Records affected: More than 20,000 accounts breached across multiple funds; AustralianSuper confirmed around 600 accounts accessed and Rest confirmed personal information accessed for around 8,000 members.
Date of breach: Attacks over the weekend of March 29 to 30, 2025 (Rest Super), with related credential-stuffing activity continuing into early April.
Date disclosed: April 4, 2025 onward.
Sector: Superannuation and retirement savings.
Attack vector: Large-scale automated credential stuffing using username and password pairs harvested from unrelated third-party breaches, exploiting password reuse and the absence of mandatory multi-factor authentication on member portals.
Data exposed: Member names, contact details, account balances, and in some cases beneficiary and bank details.
Australian Retirement Trust, Hostplus, and Insignia Financial also confirmed unusual activity, and four AustralianSuper members lost a combined A$500,000 through fraudulent withdrawals. This was the first coordinated attack on Australia's A$4 trillion superannuation system, and attackers did not need to breach any fund's systems, only to reuse credentials leaked elsewhere.
Aftermath: In June 2025 the prudential regulator wrote to all superannuation trustees setting expectations on multi-factor authentication and information security controls. Funds accelerated multi-factor authentication rollouts.
Source: BleepingComputer superannuation credential stuffing | SBS News
Records affected: Not disclosed; Eastern Health never published a confirmed count of affected patient records.
Date of breach: March 16, 2021.
Date disclosed: March 18, 2021.
Sector: Healthcare and public hospitals (Box Hill, Angliss, Healesville, and Maroondah).
Attack vector: Ransomware; the strain and initial access vector were not publicly disclosed.
Data exposed: Not confirmed. Eastern Health said it had no evidence patient data was accessed or removed, though systems including patient records were taken offline.
Eastern Health shut down most IT systems as a precaution, postponing all but urgent and Category 1 elective surgery for several days across four Melbourne hospitals. It is included here for notability rather than record count, because it demonstrated to Australian health administrators that ransomware could suspend surgical capacity in a major metropolitan health service.
Aftermath: The Victorian Government and the Australian Cyber Security Centre assisted with recovery, which took weeks. No regulatory penalty or attribution followed.
Source: iTnews Eastern Health cyber attack
Read together, these incidents point to one throughline. The largest Australian breaches rarely start with a novel exploit; they start with a third-party or supply-chain relationship, a credential that should have required multi-factor authentication, or data retained years past its usefulness. Continuous monitoring of your external attack surface and your vendors narrows the window between compromise and detection, which is often where the real damage is done. The recurring third-party thread is why steps to prevent third-party data breaches matter as much as internal controls, and the wider data breach statistics show the trend is not slowing.
Most breaches on this list trace back to exposures that continuous visibility can surface early, and closing them is central to any effort to reduce the risk of data breaches. The UpGuard platform helps security teams find and close those gaps across their own attack surface, their vendors, and their workforce:
Together these give security and risk teams one view of cyber risk instead of fragmented point tools. Start a free trial to see how the platform maps your exposure.
By record count of an Australian-headquartered company, Canva is the largest at approximately 139 million users. By consumer-identity and regulatory impact, Optus and Medibank are the most consequential, at roughly 9.7 to 9.8 million people each.
The OAIC received 1,205 data breach notifications in the 2025 calendar year, the highest annual total since the Notifiable Data Breaches scheme began in 2018, up 8% on 2024.
Optus was a September 2022 breach of up to 9.8 million customer records through an unauthenticated public API endpoint. It exposed identity documents for millions and drove major increases to Australian privacy penalties.
Medibank was an October 2022 breach of 9.7 million customers whose stolen health data was later published on the dark web. The OAIC commenced civil penalty proceedings in June 2024 that remained on foot as of July 2026.
It is the scheme requiring organizations covered by the Privacy Act to notify the regulator and affected individuals of eligible data breaches likely to cause serious harm. It has been in force since February 2018.