IronSights
←All insights

threat intelligence

Australian cyber crime statistics 2026: every number, with its source

The current headline figures from ASD, the OAIC, the National Anti-Scam Centre, the AIC and our own breach tracker, each with the period it covers and the caveat it carries. Current at 29 September 2026, updated as each source publishes.

Ryan BallootBy Ryan Balloot, Managing Director29 September 20266 min read
ByRyan Balloot29 September 20266 min read

Every Australian cyber crime statistic worth quoting comes from one of five sources, and each one counts something different. counts what is reported to it and what it responds to. The counts data breaches that organisations were legally required to notify. The National Anti-Scam Centre counts scam reports and losses across five reporting channels. The Australian Institute of Criminology surveys people and asks what happened to them. And our own tracker counts the incidents Australian organisations disclosed publicly this year.

This page holds the current headline number from each, with the period it covers and the caveat it carries, so that a figure is never quoted without its base. It is current at 29 September 2026 and is updated when a source publishes. The next scheduled updates are listed at the end.

The short version

FigureNumberPeriod and note
Cybercrime reports to ASD84,700+FY2024-25, one every six minutes, down 3% on the year before.
Average cost of a cybercrime report, business$80,850FY2024-25, self-reported, up 50%.
Average cost of a cybercrime report, small business$56,600FY2024-25, self-reported, up 14%.
Notifiable data breaches1,205Calendar 2025, up 8% on 2024 and the highest since the scheme began in 2018.
Reported scam losses$2.18 billionCalendar 2025, up 7.8% on 2024, down 29.7% from the 2022 peak.
Australians who were cybercrime victims in the past year45.5%AIC survey of 10,593 people, published 2025.
Incidents on our breach tracker571 January to 29 September 2026, publicly disclosed and human-reviewed.

ASD Annual Cyber Threat Report 2024-25

The Australian Signals Directorate's report covers the financial year to 30 June 2025 and is built from calls to the Australian Cyber Security Hotline, cybercrime reports to ReportCyber and the incidents ASD's responded to. Costs are self-reported by the people making the report, which is why the averages move so much year to year.

FigureNumberPeriod and note
Cybercrime reports receivedover 84,700Down 3%. One report every six minutes on average, the same rate as the previous year.
Hotline calls answeredover 42,500Up 16%. An average of 116 calls a day, up from 100.
Cyber security incidents ASD responded toover 1,200Up 11%.
Incidents involving ransomware11% of incidents responded toConsistent with the previous year.
Incidents involving DoS or DDoSmore than 200Up more than 280%.
Entities notified of potentially malicious activitymore than 1,700 timesUp 83%. Critical infrastructure entities were notified over 190 times, up 111%.
Average self-reported cost per report, individuals$33,000Up 8%.
Average self-reported cost per report, businesses$80,850Up 50% overall.
Small business$56,600Up 14%.
Medium business$97,200Up 55%.
Large business$202,700Up 219%.
Top reported cybercrimeIdentity fraudUp 8%.
Publicly reported vulnerabilities (CVEs)Up 28%Global count, cited by ASD as a driver of edge-device compromise.
Malicious domains blocked by the Australian Protective Domain Name System334 millionUp 307%.

ASD's own reading of the year: average losses, the frequency of attacks and the number of reported data breaches all increased, and stolen usernames and passwords bought from the dark web were the common thread. Its four recommended moves for businesses were best-practice logging, replacing legacy IT, managing third-party risk and preparing for post-quantum cryptography.

OAIC Notifiable Data Breaches statistics

The Office of the Australian Information Commissioner publishes the number of breaches notified under the . The scheme only captures organisations covered by the Privacy Act, which in the private sector broadly means those with turnover above $3 million, so the count understates what happens to small businesses. The OAIC now publishes through a statistics dashboard rather than half-yearly reports; the 2025 calendar-year figures were released on 6 July 2026.

FigureNumberPeriod and note
Notifications in calendar 20251,205Up 8% from 1,112 in 2024. The highest since mandatory reporting began in 2018.
Attributed to malicious or criminal activity716The majority of 2025 notifications. The OAIC names cyber hacking as the primary cause.
Health service providers22519% of the total. Health has led every period since the scheme began.
Financial services157Second.
Australian Government118Third.
Business and professional associations103Fourth.
Education; legal, accounting and management services81 eachEqual fifth.
Notifications, January to June 2025532Down 10% on the previous six months. Malicious or criminal attacks were 59% of them, at 308.

What a notification obliges you to do, and by when, is covered in our guide to the Notifiable Data Breaches scheme.

National Anti-Scam Centre: Targeting Scams 2025

The NASC's annual report, published in March 2026, combines scam reports from Scamwatch, ReportCyber, IDCARE, the Australian Financial Crimes Exchange and ASIC. It has the widest base of any source here and is the only one that reports a national total for dollars lost.

FigureNumberPeriod and note
Scam reports, all channels481,523Calendar 2025. Reports have stabilised year on year.
Reports involving a financial loss274,577Calendar 2025.
Total reported losses$2.18 billionUp 7.8% on 2024. Down 29.7% from the $3.1 billion peak in 2022.
Investment scams$837.7 millionThe largest category by a wide margin.
Payment redirection scams$166.8 millionBusiness email compromise in its most common form.
Romance scams$139.9 million
Phishing scams$97.6 million
Top five scam types combined60% of lossesInvestment, payment redirection, romance, phishing and remote access.

Payment redirection is the scam category that lands on businesses. Our piece on business email compromise in Australia covers how it works and what stops it.

AIC: Cybercrime in Australia 2025

The Australian Institute of Criminology's report is a nationally representative survey rather than a count of reports, which makes it the only source that can say how much cybercrime goes unreported. It asked 10,593 Australians what had happened to them in the previous 12 months.

FigureNumberPeriod and note
Victims of cybercrime in the past 12 months45.5%Roughly steady on 2024.
Victims at some point in their lifetime63.9%
Online fraud and scam victimisation11.1%Up from 9.7% the year before.
Ransomware victimisation3.2%Up from 2.5%, a 28% relative increase.
Received a ransom message on a device5.8%Includes data-theft extortion without encryption.
Malware victimisation, SME owners and managers31.5%Against 20.4% for other workers.
Fraud victims who reported it13.7%The highest reporting rate of any category, which still means about 86% did not report.
Most common business impactOperations disrupted, 28.7%Then extra expenses 16.4%, business information lost 15.9%, reputation or revenue damaged 14.1%, staff impacts 10.0% (up from 5.9%).

The reporting gap is the number to remember when reading every other table on this page. Our analysis of fraud under-reporting in Australia goes further.

Government and framework figures

FigureNumberPeriod and note
Commonwealth entities at Essential Eight Maturity Level 222%2025 Commonwealth Cyber Security Posture report. PSPF Policy 14 requires Level 2.
Ransomware payment reporting72 hoursCyber Security Act 2024. Businesses with turnover above $3 million must report a payment to the Department of Home Affairs. In force since 30 May 2025.
Notifiable data breach assessment30 daysPrivacy Act. The window to assess a suspected eligible data breach.
APRA CPS 234 incident notification72 hoursFor a material information security incident at an APRA-regulated entity.

IronSights breach tracker, 2026 to date

Our tracker lists incidents that Australian organisations, or the attackers claiming them, have made public. Each entry is reviewed by a person before it appears and labelled as claimed where the organisation has not confirmed it. It is a count of disclosure, not of incidence, and it runs well below the OAIC's figures because most notifiable breaches are never made public.

FigureNumberPeriod and note
Incidents listed571 January to 29 September 2026.
Confirmed by the organisation39
Attacker claims, unconfirmed11
Busiest monthSeptember, 11 incidentsThen June with 10.

The full list is at Australian data breaches in 2026, and the searchable version with sources is the live tracker.

How to read these together

Do not add them. The OAIC counts breaches notified by regulated organisations. ASD counts reports made to it by anyone. The NASC counts scam reports across five channels and de-duplicates them. The AIC counts survey respondents. A single ransomware attack on a medical practice could be one OAIC notification, one ReportCyber report, one ASD incident and one respondent in the AIC survey, or it could be none of them if nobody reported it, which the AIC says is the usual outcome.

Two of the figures are self-reported dollar amounts, and both moved sharply: ASD's average business cost rose 50% and the large-business figure rose 219%. Averages built from self-reported losses are pulled around by a small number of large events, so quote the small-business figure of $56,600 where it fits and treat the large-business figure as indicative.

When each source next updates

ASD's Annual Cyber Threat Report for 2025-26 is expected around November 2026, going on previous years; the 2024-25 edition was the source for the figures above. The OAIC's dashboard is next due to add July to December 2025 and January to June 2026. The National Anti-Scam Centre's Targeting Scams report for 2026 is expected in March 2027. The AIC's next Cybercrime in Australia survey report is expected mid-2027. Our tracker updates weekly.

Frequently asked questions

How many cyber attacks happen in Australia each year?

There is no single count. The closest official figures are ASD's 84,700-plus cybercrime reports and 1,200-plus incidents responded to in FY2024-25, the OAIC's 1,205 notifiable data breaches in calendar 2025, and the AIC's finding that 45.5% of Australians were a victim of some form of cybercrime in the past year.

How much did Australians lose to scams in 2025?

$2.18 billion in reported losses across 481,523 reports, according to the National Anti-Scam Centre's Targeting Scams report for 2025. That is up 7.8% on 2024 and down 29.7% from the 2022 peak of $3.1 billion. Investment scams accounted for $837.7 million of it.

What does a cyber attack cost an Australian small business?

ASD's FY2024-25 figure is $56,600 per report for small businesses, self-reported and up 14% on the year before. The average across all businesses was $80,850. Both are averages of what victims chose to report, so an individual incident can sit a long way either side.

How many data breaches were reported in Australia in 2025?

1,205 notifications to the OAIC under the Notifiable Data Breaches scheme, an 8% rise on 2024 and the most since the scheme began in 2018. Health service providers accounted for 225 of them.

What share of cybercrime is reported?

Very little. The AIC found fraud and scams had the highest reporting rate of any cybercrime category at 13.7%, which means roughly 86% of victims did not report. Other categories were lower.

If you are reading this because it just happened

Statistics are for the board paper. If your organisation is dealing with an incident now, 1300 004 766 is answered 24 hours a day and our incident response page explains what the first hours should look like.

Incident response

If this happens to you, the first hour decides the rest.

Our incident response team is available 24/7 on 1300 004 766. We contain the incident, work out what was taken, and handle the reporting clocks you are now on.