Every Australian cyber crime statistic worth quoting comes from one of five sources, and each one counts something different. counts what is reported to it and what it responds to. The counts data breaches that organisations were legally required to notify. The National Anti-Scam Centre counts scam reports and losses across five reporting channels. The Australian Institute of Criminology surveys people and asks what happened to them. And our own tracker counts the incidents Australian organisations disclosed publicly this year.
This page holds the current headline number from each, with the period it covers and the caveat it carries, so that a figure is never quoted without its base. It is current at 29 September 2026 and is updated when a source publishes. The next scheduled updates are listed at the end.
The short version
| Figure | Number | Period and note |
|---|---|---|
| Cybercrime reports to ASD | 84,700+ | FY2024-25, one every six minutes, down 3% on the year before. |
| Average cost of a cybercrime report, business | $80,850 | FY2024-25, self-reported, up 50%. |
| Average cost of a cybercrime report, small business | $56,600 | FY2024-25, self-reported, up 14%. |
| Notifiable data breaches | 1,205 | Calendar 2025, up 8% on 2024 and the highest since the scheme began in 2018. |
| Reported scam losses | $2.18 billion | Calendar 2025, up 7.8% on 2024, down 29.7% from the 2022 peak. |
| Australians who were cybercrime victims in the past year | 45.5% | AIC survey of 10,593 people, published 2025. |
| Incidents on our breach tracker | 57 | 1 January to 29 September 2026, publicly disclosed and human-reviewed. |
ASD Annual Cyber Threat Report 2024-25
The Australian Signals Directorate's report covers the financial year to 30 June 2025 and is built from calls to the Australian Cyber Security Hotline, cybercrime reports to ReportCyber and the incidents ASD's responded to. Costs are self-reported by the people making the report, which is why the averages move so much year to year.
| Figure | Number | Period and note |
|---|---|---|
| Cybercrime reports received | over 84,700 | Down 3%. One report every six minutes on average, the same rate as the previous year. |
| Hotline calls answered | over 42,500 | Up 16%. An average of 116 calls a day, up from 100. |
| Cyber security incidents ASD responded to | over 1,200 | Up 11%. |
| Incidents involving ransomware | 11% of incidents responded to | Consistent with the previous year. |
| Incidents involving DoS or DDoS | more than 200 | Up more than 280%. |
| Entities notified of potentially malicious activity | more than 1,700 times | Up 83%. Critical infrastructure entities were notified over 190 times, up 111%. |
| Average self-reported cost per report, individuals | $33,000 | Up 8%. |
| Average self-reported cost per report, businesses | $80,850 | Up 50% overall. |
| Small business | $56,600 | Up 14%. |
| Medium business | $97,200 | Up 55%. |
| Large business | $202,700 | Up 219%. |
| Top reported cybercrime | Identity fraud | Up 8%. |
| Publicly reported vulnerabilities (CVEs) | Up 28% | Global count, cited by ASD as a driver of edge-device compromise. |
| Malicious domains blocked by the Australian Protective Domain Name System | 334 million | Up 307%. |
ASD's own reading of the year: average losses, the frequency of attacks and the number of reported data breaches all increased, and stolen usernames and passwords bought from the dark web were the common thread. Its four recommended moves for businesses were best-practice logging, replacing legacy IT, managing third-party risk and preparing for post-quantum cryptography.
OAIC Notifiable Data Breaches statistics
The Office of the Australian Information Commissioner publishes the number of breaches notified under the . The scheme only captures organisations covered by the Privacy Act, which in the private sector broadly means those with turnover above $3 million, so the count understates what happens to small businesses. The OAIC now publishes through a statistics dashboard rather than half-yearly reports; the 2025 calendar-year figures were released on 6 July 2026.
| Figure | Number | Period and note |
|---|---|---|
| Notifications in calendar 2025 | 1,205 | Up 8% from 1,112 in 2024. The highest since mandatory reporting began in 2018. |
| Attributed to malicious or criminal activity | 716 | The majority of 2025 notifications. The OAIC names cyber hacking as the primary cause. |
| Health service providers | 225 | 19% of the total. Health has led every period since the scheme began. |
| Financial services | 157 | Second. |
| Australian Government | 118 | Third. |
| Business and professional associations | 103 | Fourth. |
| Education; legal, accounting and management services | 81 each | Equal fifth. |
| Notifications, January to June 2025 | 532 | Down 10% on the previous six months. Malicious or criminal attacks were 59% of them, at 308. |
What a notification obliges you to do, and by when, is covered in our guide to the Notifiable Data Breaches scheme.
National Anti-Scam Centre: Targeting Scams 2025
The NASC's annual report, published in March 2026, combines scam reports from Scamwatch, ReportCyber, IDCARE, the Australian Financial Crimes Exchange and ASIC. It has the widest base of any source here and is the only one that reports a national total for dollars lost.
| Figure | Number | Period and note |
|---|---|---|
| Scam reports, all channels | 481,523 | Calendar 2025. Reports have stabilised year on year. |
| Reports involving a financial loss | 274,577 | Calendar 2025. |
| Total reported losses | $2.18 billion | Up 7.8% on 2024. Down 29.7% from the $3.1 billion peak in 2022. |
| Investment scams | $837.7 million | The largest category by a wide margin. |
| Payment redirection scams | $166.8 million | Business email compromise in its most common form. |
| Romance scams | $139.9 million | |
| Phishing scams | $97.6 million | |
| Top five scam types combined | 60% of losses | Investment, payment redirection, romance, phishing and remote access. |
Payment redirection is the scam category that lands on businesses. Our piece on business email compromise in Australia covers how it works and what stops it.
AIC: Cybercrime in Australia 2025
The Australian Institute of Criminology's report is a nationally representative survey rather than a count of reports, which makes it the only source that can say how much cybercrime goes unreported. It asked 10,593 Australians what had happened to them in the previous 12 months.
| Figure | Number | Period and note |
|---|---|---|
| Victims of cybercrime in the past 12 months | 45.5% | Roughly steady on 2024. |
| Victims at some point in their lifetime | 63.9% | |
| Online fraud and scam victimisation | 11.1% | Up from 9.7% the year before. |
| Ransomware victimisation | 3.2% | Up from 2.5%, a 28% relative increase. |
| Received a ransom message on a device | 5.8% | Includes data-theft extortion without encryption. |
| Malware victimisation, SME owners and managers | 31.5% | Against 20.4% for other workers. |
| Fraud victims who reported it | 13.7% | The highest reporting rate of any category, which still means about 86% did not report. |
| Most common business impact | Operations disrupted, 28.7% | Then extra expenses 16.4%, business information lost 15.9%, reputation or revenue damaged 14.1%, staff impacts 10.0% (up from 5.9%). |
The reporting gap is the number to remember when reading every other table on this page. Our analysis of fraud under-reporting in Australia goes further.
Government and framework figures
| Figure | Number | Period and note |
|---|---|---|
| Commonwealth entities at Essential Eight Maturity Level 2 | 22% | 2025 Commonwealth Cyber Security Posture report. PSPF Policy 14 requires Level 2. |
| Ransomware payment reporting | 72 hours | Cyber Security Act 2024. Businesses with turnover above $3 million must report a payment to the Department of Home Affairs. In force since 30 May 2025. |
| Notifiable data breach assessment | 30 days | Privacy Act. The window to assess a suspected eligible data breach. |
| APRA CPS 234 incident notification | 72 hours | For a material information security incident at an APRA-regulated entity. |
IronSights breach tracker, 2026 to date
Our tracker lists incidents that Australian organisations, or the attackers claiming them, have made public. Each entry is reviewed by a person before it appears and labelled as claimed where the organisation has not confirmed it. It is a count of disclosure, not of incidence, and it runs well below the OAIC's figures because most notifiable breaches are never made public.
| Figure | Number | Period and note |
|---|---|---|
| Incidents listed | 57 | 1 January to 29 September 2026. |
| Confirmed by the organisation | 39 | |
| Attacker claims, unconfirmed | 11 | |
| Busiest month | September, 11 incidents | Then June with 10. |
The full list is at Australian data breaches in 2026, and the searchable version with sources is the live tracker.
How to read these together
Do not add them. The OAIC counts breaches notified by regulated organisations. ASD counts reports made to it by anyone. The NASC counts scam reports across five channels and de-duplicates them. The AIC counts survey respondents. A single ransomware attack on a medical practice could be one OAIC notification, one ReportCyber report, one ASD incident and one respondent in the AIC survey, or it could be none of them if nobody reported it, which the AIC says is the usual outcome.
Two of the figures are self-reported dollar amounts, and both moved sharply: ASD's average business cost rose 50% and the large-business figure rose 219%. Averages built from self-reported losses are pulled around by a small number of large events, so quote the small-business figure of $56,600 where it fits and treat the large-business figure as indicative.
When each source next updates
ASD's Annual Cyber Threat Report for 2025-26 is expected around November 2026, going on previous years; the 2024-25 edition was the source for the figures above. The OAIC's dashboard is next due to add July to December 2025 and January to June 2026. The National Anti-Scam Centre's Targeting Scams report for 2026 is expected in March 2027. The AIC's next Cybercrime in Australia survey report is expected mid-2027. Our tracker updates weekly.
Frequently asked questions
How many cyber attacks happen in Australia each year?
There is no single count. The closest official figures are ASD's 84,700-plus cybercrime reports and 1,200-plus incidents responded to in FY2024-25, the OAIC's 1,205 notifiable data breaches in calendar 2025, and the AIC's finding that 45.5% of Australians were a victim of some form of cybercrime in the past year.
How much did Australians lose to scams in 2025?
$2.18 billion in reported losses across 481,523 reports, according to the National Anti-Scam Centre's Targeting Scams report for 2025. That is up 7.8% on 2024 and down 29.7% from the 2022 peak of $3.1 billion. Investment scams accounted for $837.7 million of it.
What does a cyber attack cost an Australian small business?
ASD's FY2024-25 figure is $56,600 per report for small businesses, self-reported and up 14% on the year before. The average across all businesses was $80,850. Both are averages of what victims chose to report, so an individual incident can sit a long way either side.
How many data breaches were reported in Australia in 2025?
1,205 notifications to the OAIC under the Notifiable Data Breaches scheme, an 8% rise on 2024 and the most since the scheme began in 2018. Health service providers accounted for 225 of them.
What share of cybercrime is reported?
Very little. The AIC found fraud and scams had the highest reporting rate of any cybercrime category at 13.7%, which means roughly 86% of victims did not report. Other categories were lower.
If you are reading this because it just happened
Statistics are for the board paper. If your organisation is dealing with an incident now, 1300 004 766 is answered 24 hours a day and our incident response page explains what the first hours should look like.



