Adaca Report · September 2026
What 4,769 data breach notifications reveal about how Australian organisations detect and report data breaches in the AI era – 2022-present.
Adaca received data breach notification figures from the Office of Australian Information Commissioner (OAIC) and combined this data with publicly available figures. It analysed figures from 2022 to present, representing 4,769 notifications submitted to the OAIC by Australian businesses during the AI era.
The volume of breaches has jumped by two-thirds. In light of the recent AI Medicare breach, one of the most concerning findings is government becoming the third-largest source of breaches and the slowest by a distance.
The only positive news is that Australian organisations are also armed with AI. Maybe this is why 2026 is the first year that reporting speed has genuinely improved.
2022 and 2023 were almost identical — 884 and 893 notifications, both around 74 a month. Then the line broke. 2024 came in at 1,108, 2025 at 1,205, and the first half of 2026 at 111.7 a month. Comparing like with like, the first six months of 2026 produced 69% more notifications than the first six months of 2022.
We are using a half-year comparison because the register has a strong summer dip in January every year.
Total notifications for the half year shown inside each column.
Australian Government notifications went from 37 in 2022 to 118 in 2025, a 219% rise, peaking at 161 in 2024. Over the period it is the third most-breached category in the register at 399 notifications, behind only health and finance.
It is also, by a wide margin, the slowest. Since 2022, only 7.0% of Australian Government breaches were reported within ten days of discovery, against 34.1% for non-government entities. 56.9% took more than 30 days.
For breach detection, the gap is worse still, as typified by the recent OpenAI news that it had breached multiple government sites including Medicare. 60.0% of government breaches took over a month simply to identify, against 20.5% elsewhere.
The median breach detection times are even worse.
Each square is one day. 166 notifications with a usable detection date. Months drawn as 30 days.
Each square is one day. 1,746 notifications, excluding government at all levels. Same scale.
| Sector | Within 10 days | Over 30 days | n |
|---|---|---|---|
| Australian Government | 7.0% | 56.9% | 399 |
| Insurance | 10.6% | 30.5% | 246 |
| Recruitment agencies | 15.0% | 22.0% | 227 |
| Finance (incl. super) | 22.0% | 30.2% | 536 |
| Mining & manufacturing | 26.0% | 37.5% | 104 |
| Business/prof. associations | 30.6% | 26.2% | 229 |
| Legal, accounting & mgmt | 32.2% | 23.1% | 295 |
| Retail | 35.3% | 21.3% | 207 |
| Information technology | 38.3% | 25.0% | 120 |
| Health service providers | 43.8% | 17.4% | 914 |
| Education | 46.6% | 15.9% | 352 |
| Personal services | 54.4% | 15.1% | 259 |
| All sectors | 31.7% | 25.4% | 4,769 |
Days from discovering the breach to notifying the OAIC. Sectors with fewer than 60 notifications since 2022 are excluded.
In better news, data breach detection and reporting figures have improved recently. This may be due to technology and security teams catching up. They are also leveraging AI to automate incident response processes. In theory, this should make Australian organisations faster at detecting, mitigating and reporting breaches. Although it does seem like many organisations choose to delay reporting to the last minute intentionally.
Through 2022 and 2023, the share of breaches notified within ten days of discovery was just 28.0%, the worst since the scheme’s inception in 2018. In 2026 so far, 38.4% of breaches are reported within ten days with only 18.6% taking over 30 days. Both are the best figures on record.
Detection improved on the same schedule. Nearly a third of breaches in 2024 were reported after 30 days or longer. This is down to 18.3% in 2026.
Ransomware was arguably the most concerning cyber threat in the early 2020s, and certainly the most lucrative for attackers. It has not disappeared, and the number of ransomware incidents has increased slightly, but attackers have diversified. Ransomware now makes up a lower percentage of attacks.
Hacking went from 2.4 notifications a month to 7.0, nearly tripling. As a percentage of all cyber attacks, it went from 7.6% to 15.8% between 2022 and 2026. Attackers are increasingly able to identify vulnerabilities and hack into systems, most likely leveraging AI to do so. Technology has significantly lowered the technical barrier for attackers to find weaknesses, and enabled sophisticated attackers to launch campaigns at scale.
Meanwhile, the data also shows a rise in incidents tagged as “other / not specified”. It may not have been possible to select this as an option when disclosing a breach to the OAIC prior to 2024, but the number of other or unknown cyber incidents has increased significantly in the last two years. They now make up 13% of all incidents. These are incidents that victims do not know the cause of, or believe do not fit the other descriptions listed. In either case, it says a lot about how attacks have changed.
| Method | 2022 | 2023 | 2024 | 2025 | 2026 |
|---|
Each column totals 100% of that year’s cyber incidents, not of all breaches.
Method is recorded for every cyber incident in both releases, so all five years are covered.
2026 covers 1 Jan – 2 Jul. Two records with no method recorded sit in “Other / not specified”.
“The Medicare breach has sent shockwaves through Australian public sector, but we have to be glad that it was OpenAI, not a malicious actor who wanted to cause genuine harm. A real attacker would have held that data for ransom, sold it on the dark web, or used it for financial gain. And this is definitely happening too.
“It’s scary how quickly an attacker can move now, at literally superhuman speed. AI makes it a lot easier to find vulnerabilities or exploit zero days. Using AI tools, they can navigate through a company’s most valuable assets and steal them before the target knows they’ve been hit. For a sector that typically only discovers a breach after 100 days, it is severely outmatched.”

This is a subset of a combined dataset built from two OAIC FOI disclosures covering consecutive, non-overlapping periods. Every extracted table reconciles to the total printed in its own source document.