Two findings from recent research into Australian breach data are worth putting side by side.
The first is volume. Reported Australian breaches rose about 48 per cent year on year, against roughly 18 per cent globally. Australia is not being hit at the world average. It is well ahead of it.
The second matters more, and gets almost no attention. Stolen data is increasingly sold in bundles. Rather than listing one victim organisation at a time, sellers combine records from many breaches into composite packages and sell those.
Why bundling changes the shape of the risk
The commercial logic is dull and effective. A single company's customer list has a limited pool of buyers. A package combining a dozen Australian breaches into one searchable set is worth more, sells to more people, and appeals to fraud crews and access brokers who were never interested in your organisation specifically.
For you, the consequence is that a breach stops being an event with an end date. Your 2024 incident, which you notified and closed and moved on from, becomes an ingredient. It gets recombined with three other datasets in 2026 and sold to buyers who have no idea which company any given record came from and do not care.
It also defeats the reasoning most people apply after a breach. Only email addresses were exposed, so the harm is limited. That holds if the data stays alone. It stops holding when the email addresses are joined against a set containing dates of birth, and another containing phone numbers, and another containing passwords from an unrelated service. Individually thin records become a usable identity package.
What this means practically
Treat credential exposure as ongoing rather than incident-driven. If your only check happens after you hear about a breach, you are looking at the wrong moment. The exposure that hurts you is often assembled long after the event you were told about.
Assume reused passwords are already gone. Bundled sets make credential stuffing far more efficient, because the attacker can filter to Australian records, to one industry, or to one email domain before trying anything. That is what makes your staff a targeted list rather than a rounding error in a global dump.
remains the control that breaks this chain, which is unglamorous advice that people are tired of hearing. It is still true. A password in a bundle is worth very little against an account that requires a second factor, and it is worth a great deal against one that does not.
The uncomfortable part
There is no remediation for data that has already gone. You cannot recall it, and as this market matures it will keep resurfacing in new combinations for years. Anyone offering to remove your data from the dark web is selling you something that does not exist.
What you can control is the next one. Every record you are still holding without a reason is a future ingredient in someone else's package, which is the practical argument for a retention pass and for turning MFA on everywhere rather than only where it was easy.



