RESOURCE · GUIDE FOR BOARDS & IT LEADERS

Biggest Data Breaches in Australia: A Guide for Boards and IT Leaders

What the largest Australian data breaches actually tell board directors and IT leaders — the root causes, the regulatory shift since 2022, and the decisions that prevent the next incident on the list.

Run your first mission free

Why this guide exists

Australia's largest data breaches are no longer rare events. Between 2022 and 2024, breaches at Optus, Medibank, Latitude Financial, HWL Ebsworth, MediSecure and several SaaS providers collectively exposed records belonging to more individuals than the adult population. The attacks were not technically sophisticated. The controls that would have stopped them are well understood. The job of boards and IT leaders is to make sure they are in place — and provably so.

The biggest data breaches in Australia (2022–2024)

Optus — September 2022

Records:
~9.8 million customer records
Data:
Names, dates of birth, addresses, driver licence and passport numbers.
Root cause:
Unauthenticated, publicly exposed API endpoint with enumerable customer IDs.
Lesson:
Every internet-facing API is in scope. Authenticated-by-default, rate-limited, tested against the OWASP API Security Top 10 before exposure.

Medibank — October 2022

Records:
~9.7 million current and former customers
Data:
Sensitive health claims data, later published on the dark web after a ransom refusal.
Root cause:
Stolen privileged credentials from a third-party IT contractor; insufficient MFA on high-privilege access.
Lesson:
Phishing-resistant MFA on every admin, remote and third-party privileged access path — no exceptions, no legacy carve-outs.

Latitude Financial — March 2023

Records:
~14 million records
Data:
Driver licence and passport numbers — the largest exposure of government-issued identifiers in Australian history.
Root cause:
Credential compromise at a service provider; lateral movement across two providers before reaching Latitude systems.
Lesson:
Data minimisation is a security control. Do not retain identity documents beyond regulatory necessity.

HWL Ebsworth — April 2023

Records:
Files for ~65 Commonwealth agencies and dozens of corporates
Data:
Confidential legal matter files leaked by the ALPHV/BlackCat ransomware crew.
Root cause:
Compromised employee credentials; flat network with broad access to client matter files.
Lesson:
Segment client and customer data by matter, business unit and clearance — not by convenience.

MediSecure — May 2024

Records:
~12.9 million prescriptions
Data:
eScript prescription data offered for sale; the company subsequently entered administration.
Root cause:
Third-party vendor compromise; legacy data retained beyond contract expiry.
Lesson:
Retention policy is a security control. Data that no longer needs to exist cannot be stolen.

Ticketmaster Australia — May 2024

Records:
~560 million records globally (Australian customers included)
Data:
Names, contact details and partial payment data exfiltrated via a third-party cloud tenant.
Root cause:
Credential compromise of a Snowflake tenant without enforced MFA.
Lesson:
SaaS tenants are part of your attack surface. Enforce MFA at the identity provider, not the application.

ClubsNSW / Outabox — May 2024

Records:
~1 million club patron records
Data:
Driver licences, signatures, club sign-in scans and facial recognition data.
Root cause:
Third-party visitor management vendor exposure; sensitive biometric data retained without proportionate controls.
Lesson:
Biometric and identity data require purpose limitation. If you collect it, you own the breach risk for its full retention life.

Five lessons for boards and IT leaders

1. Treat retention as a control, not a compliance line item

Optus, Latitude and MediSecure all retained sensitive data beyond business need. Boards should ask for a retention scorecard against crown-jewel datasets every quarter — and approve the deletion budget.

2. Make MFA coverage a board metric

Medibank, Ticketmaster Australia and most third-party-origin breaches share the same root cause: a privileged path without phishing-resistant MFA. Coverage percentages on administrative, remote and vendor access should appear on every board cyber dashboard.

3. Hold third parties to the same standard as employees

Five of the seven breaches above started inside a supplier. Parity controls — identity, monitoring, segmentation — applied to vendor access close the most common attack path in the Australian register.

4. Pre-authorise the first 24 hours

Isolation, customer notification, OAIC engagement and ransom-position decisions should be pre-authorised at the board level. The companies that handled disclosure well did so because the playbook existed before the incident.

5. Report outcomes, not activities

Mean time to detect, percentage of crown-jewel data with phishing-resistant MFA, tabletop coverage of top scenarios, third-party residual risk movement — these are defensible board metrics. "We patched X systems" is not.

The regulatory backdrop

What changed for Australian directors after Optus and Medibank

  • Privacy Act reforms (2024–2025): tiered civil penalties up to the greater of $50M, three times the benefit obtained, or 30% of adjusted turnover during the breach period.
  • Cyber Security Act 2024: mandatory ransomware payment reporting for entities with annual turnover above $3M.
  • SOCI Act amendments: expanded critical infrastructure definitions, mandatory risk management programmes and incident reporting.
  • APRA CPS 234: regulator-led control testing and board attestation of information security capability.
  • ASIC RG 271/272 and case law: directors are personally accountable for cyber resilience oversight.

PRESSURE-TEST YOUR POSTURE

"Could Optus, Medibank or Latitude happen to us?"

FORTE/CYBERx runs the question through 7 specialist AI advisors and a 3-director board — returning three ranked strategic options with a tactical plan in under 60 seconds.

Start a free mission

FAQ

What is the biggest data breach in Australian history?

By record count, the Latitude Financial breach (March 2023) exposed approximately 14 million records, including driver licence and passport numbers — the largest exposure of government-issued identifiers in Australia. By systemic impact, Optus (2022) and Medibank (2022) reshaped regulator expectations and director accountability.

How many Australians have been affected by data breaches?

Between 2022 and 2024, publicly disclosed Australian breaches collectively exposed records belonging to more individuals than the adult population — with significant overlap as the same individuals appeared in multiple incidents (Optus, Medibank, Latitude, MediSecure and others).

What are the common root causes of the biggest Australian data breaches?

Four recurring root causes: over-retention of sensitive data, third-party privileged access without parity controls, inconsistent MFA on administrative paths, and flat data architectures where one compromised credential reaches crown-jewel data. None require exotic attacker capability.

What should boards ask after a major data breach?

Five questions: could this attacker have reached our data the same way; what single control would have broken the kill chain earliest; do we retain data we would not want stolen; which third parties have privileged access to crown-jewel systems; could we defend our public position within 24 hours?

What are the penalties for a serious data breach in Australia?

Civil penalties under the strengthened Privacy Act can reach the greater of $50M, three times the benefit obtained, or 30% of adjusted turnover during the breach period. Class-action litigation and share-price impact frequently exceed the regulatory penalty itself.

Related resources

Don't be the next case study.

Two free missions. Pressure-test your posture against the same root causes behind Australia's biggest data breaches.