DATA BREACH ANALYSIS · 2026 REPORT

Australian Data Breach Analysis Report: Trends, Causes and Decision Frameworks

The five largest Australian data breaches of the last four years exposed more records than the entire population. The pattern is consistent — and so is the response CISOs and CIOs should mount.

Run your first mission free

Executive summary

Between 2022 and 2024, five Australian organisations — Optus, Medibank, Latitude Financial, HWL Ebsworth and MediSecure — collectively exposed records belonging to nearly every adult in the country. None of these breaches required novel attacker capability. Each was enabled by a control that was either missing, misconfigured, or extended to a third party without commensurate oversight.

This report consolidates the root causes, the regulatory response that has reshaped director accountability, and the decision frameworks security and technology leaders should use to prevent the next incident on the list.

The five breaches that reshaped the threat model

Optus (September 2022)

Impact:
~9.8 million customer records exposed via an unauthenticated public API endpoint.
Root cause:
Missing authentication on an internet-facing API plus enumerable customer IDs — a basic access-control failure.
Leadership lesson:
Treat every internet-facing API as an asset class. Authenticated-by-default, rate-limited, and tested against OWASP API Security Top 10 before exposure.

Medibank (October 2022)

Impact:
~9.7 million current and former customers; sensitive health claims data published on the dark web after ransom refusal.
Root cause:
Stolen privileged credentials from a third-party IT service provider; insufficient MFA on high-privilege access.
Leadership lesson:
Phishing-resistant MFA on all administrative and remote access paths is non-negotiable. Third-party privileged access must be in scope of your identity threat detection.

Latitude Financial (March 2023)

Impact:
~14 million records including driver licence and passport numbers — the largest exposure of government-issued identifiers to date.
Root cause:
Credential compromise at a service provider, lateral movement across two providers before reaching Latitude systems.
Leadership lesson:
Data minimisation: do not retain identity documents beyond regulatory necessity. Segment third parties and treat their breach as your incident.

HWL Ebsworth (April 2023)

Impact:
Confidential legal files belonging to ~65 Commonwealth agencies and dozens of corporates leaked by ALPHV/BlackCat ransomware crew.
Root cause:
Initial access via compromised employee credentials; flat network with broad access to client matter files.
Leadership lesson:
Least-privilege access to client/customer data stores. Segment by matter, business unit and clearance level — not by convenience.

MediSecure (May 2024)

Impact:
~12.9 million prescriptions data set offered for sale; the company entered administration.
Root cause:
Third-party vendor compromise; legacy data set retained beyond contract expiry.
Leadership lesson:
Retention policy is a security control. Data that no longer needs to exist cannot be stolen.

The shared root causes

Strip the brand names away and the same four root causes recur: over-retention of sensitive data, third-party privileged access without parity controls, inconsistent MFA coverage on administrative paths, and flat data architectures where a single compromised credential can read crown-jewel data. None of these are exotic; all of them are addressable with controls that exist today.

The regulatory shift CIOs and CISOs cannot ignore

What changed between 2022 and 2026

  • Privacy Act reforms (2024–2025): tiered civil penalties, statutory tort for serious invasions of privacy, expanded OAIC enforcement powers.
  • Cyber Security Act 2024: mandatory ransomware payment reporting, limited-use protection for incident reports to the National Cyber Security Coordinator.
  • SOCI Act amendments: expanded critical infrastructure definitions, mandatory risk management programmes and incident reporting for designated systems.
  • APRA CPS 234 enforcement: regulator-led control testing, third-party assurance expectations and board attestation of information security capability.
  • ASIC RG 271/272 expectations: directors are personally accountable for cyber resilience oversight; the Medibank class action set the litigation tone.

Director accountability is no longer abstract. The Medibank class action, the OAIC's expanded civil penalty powers, and ASIC's published expectations have moved cyber resilience from "CIO's problem" to "board's defensible record".

Four decision frameworks for security and technology leaders

1. Pre-breach: scenario-led control investment

Map your top five plausible breach scenarios (API exposure, third-party privileged access, ransomware, insider data theft, identity-document leak). For each, identify the single control that breaks the kill chain earliest and invest there first. Defensible decisions cite scenarios, not vendor categories.

2. During-breach: pre-authorised response playbooks

The first 24 hours decide whether you face a contained incident or a national news event. Pre-authorise isolation, communications, OAIC notification and ransom-position decisions at the board level — not in the war room at 2am.

3. Post-breach: regulatory and litigation posture

Under the strengthened Privacy Act, the OAIC can pursue civil penalties up to $50M or 30% of adjusted turnover. The Cyber Security Act 2024 mandates ransomware payment reporting for entities over $3M turnover. Position evidence retention, legal privilege and customer remediation in your incident-response runbook before you need them.

4. Board reporting: outcomes, not activities

Boards have moved on from 'we patched X systems'. Report on outcomes the board can defend: mean time to detect, percentage of crown-jewel data with phishing-resistant MFA, third-party residual risk movement, tabletop coverage of top scenarios.

FOR LEADERS RESPONDING TO BOARD QUESTIONS

"Could Optus, Medibank or Latitude happen to us?"

FORTE/CYBERx runs the question through 7 specialist AI advisors and a 3-director board — and returns three ranked strategic options with a tactical plan in under 60 seconds.

Start a free mission

The five-question post-incident review

Use this after any internal incident or third-party breach disclosure:

  1. Could this attacker have reached our data the same way? Map the kill chain against your environment, not theirs.
  2. What single control would have broken the kill chain earliest? Invest there before investing in detection improvements.
  3. Do we retain data we would not want stolen? Retention is a control. Delete what you do not need.
  4. Which third parties have privileged access to crown-jewel systems? Apply parity controls — MFA, monitoring, segregation — or remove the access.
  5. Could the board defend our position publicly in 24 hours? If not, write the playbook now.

FAQ

What are the biggest data breaches in Australia?

The largest publicly disclosed Australian data breaches by impact include Latitude Financial (~14M records, 2023), MediSecure (~12.9M, 2024), Optus (~9.8M, 2022), Medibank (~9.7M, 2022) and HWL Ebsworth (Commonwealth and corporate legal files, 2023). Each was triggered by a different root cause — API exposure, credential compromise, third-party access and data retention failure — which is why a single-control mitigation strategy will not prevent the next one.

What is causing the increase in Australian data breaches?

Three structural factors: (1) over-retention of personal data beyond business need, (2) third-party and service-provider access pathways that bypass primary controls, and (3) inconsistent MFA coverage on privileged and remote-access surfaces. Threat actor capability is increasing, but the controls that would have stopped the largest 2022–2024 incidents are basic and well understood.

What must Australian organisations report after a data breach?

Under the Notifiable Data Breaches scheme, eligible data breaches must be reported to the OAIC and affected individuals as soon as practicable. The Cyber Security Act 2024 adds mandatory ransomware payment reporting for entities with annual turnover above $3M. Critical infrastructure entities have additional reporting obligations under the SOCI Act.

How can CISOs and CIOs prevent a Medibank or Optus-scale breach?

Treat the four common root causes as a checklist: (1) authenticate and rate-limit every internet-facing API, (2) enforce phishing-resistant MFA on all administrative, remote and third-party privileged access, (3) minimise retention of identity documents and sensitive datasets, and (4) segment networks and data stores so a single compromised credential cannot reach crown-jewel data. Validate quarterly with red-team or purple-team exercises.

What are the financial penalties for a serious data breach in Australia?

The strengthened Privacy Act allows civil penalties for serious or repeated privacy interferences of up to the greater of $50M, three times the value of any benefit obtained, or 30% of adjusted turnover during the breach period. Class-action litigation (e.g. the Medibank class action) and ASX share-price impact frequently exceed the regulatory penalty itself.

Related

Don't be the next case study.

Two free missions. Pressure-test your current posture against the same root causes that put five Australian household names on the breach register.