Lessons from Major Australian Data Breaches for Small Businesses
Over the past few years, Australia has seen some of the largest data breaches in its history. Big names made the headlines, but the causes were rarely sophisticated: a stolen password, a missing security control, a supplier with too much access, or a slow response. Those same weaknesses exist in thousands of small businesses.
This article looks at what major Australian breaches teach us, how the Notifiable Data Breaches scheme works, and the practical steps a small or medium business can take now.
Major Australian breaches at a glance
- Optus (September 2022): personal information of around 9.5 million people affected.
- Medibank (late 2022): personal information of around 9.7 million current and former customers compromised, including health information.
- Latitude Financial (March 2023): more than 14 million records stolen, including around 7.9 million driver licence numbers.
- MediSecure (2024): a cyber attack on the electronic prescription provider affected around 12.9 million people.
- Qantas (July 2025): data on around 5.7 million customers exposed through a third-party platform.
Lesson 1: Stolen logins are the front door
In its Federal Court case against Medibank, the OAIC alleges that a contractor’s IT worker saved his Medibank credentials in a personal browser profile, which synced them to his personal computer, where they were stolen by malware. The OAIC also alleges that Medibank’s VPN did not require multi-factor authentication, so the stolen username and password were enough to get in.
For a small business, the equivalent is a staff member’s Microsoft 365 password being phished or stolen. With MFA turned on, a stolen password alone is usually not enough. Our guide to implementing MFA walks through it.
Lesson 2: Your suppliers are part of your security
In the Latitude breach, staff login details were used to access two third-party service providers. The Qantas incident involved a third-party platform. Both show that your data is only as safe as every business that can reach it.
Ask your suppliers how they protect your data, give them only the access they need, remove access when work finishes, and keep a list of who holds what.
Lesson 3: How you respond matters as much as the breach
In October 2025, the Federal Court ordered Australian Clinical Labs to pay $5.8 million in civil penalties over a 2022 data breach at its Medlab Pathology business, which affected more than 223,000 people. They were the first civil penalties ordered under the Privacy Act. The penalties covered not only failing to take reasonable steps to protect personal information, but also failing to properly assess the breach and failing to notify the Information Commissioner as soon as practicable.
In other words, a slow or disorganised response can be a breach of the law in its own right.
Lesson 4: Do not keep data you no longer need
Several of these breaches exposed information about former customers, sometimes from many years earlier. Every old record you keep is something that can be stolen. Set a retention period for personal information, and securely delete what you no longer need.
Lesson 5: Human error is a big part of the picture
The OAIC received 532 data breach notifications from January to June 2025. Malicious or criminal attacks caused 59% of them, but human error caused 37%, up from 29% in the previous six months. Emails sent to the wrong person, files shared with the wrong link and lost devices all count. Training and simple processes reduce these mistakes.
How the Notifiable Data Breaches scheme works
The Notifiable Data Breaches (NDB) scheme has applied to breaches since 22 February 2018. It covers organisations that have obligations under the Privacy Act, which generally includes businesses with an annual turnover of more than $3 million, plus some smaller businesses such as health service providers.
- An eligible data breach is unauthorised access to, disclosure or loss of personal information that is likely to result in serious harm to one or more individuals, where remedial action has not prevented that harm.
- If you suspect a breach, you must assess it quickly and within 30 calendar days.
- If it is eligible, you must notify the OAIC and affected individuals as soon as practicable.
Even if your business sits under the turnover threshold, your clients may expect the same standard, and their contracts may require it.
A practical checklist for small businesses
- Turn on MFA for email, remote access and every cloud system.
- Keep operating systems and applications patched.
- Review supplier access and remove what is no longer needed.
- Delete personal information you no longer need to keep.
- Keep separate, tested backups. See our simple backup and recovery plans.
- Write a short data breach response plan: who decides, who to call, and how to assess and notify.
- Train staff to spot phishing and to report mistakes quickly.
- Report cybercrime through ReportCyber at cyber.gov.au.
Most of these steps line up with the ASD’s Essential Eight. Our managed IT security service helps businesses put them in place and monitors for threats around the clock.
Key takeaways
- Most major breaches started with basic weaknesses, not cutting-edge hacking.
- MFA, supplier controls and data minimisation would reduce the risk for most businesses.
- A fast, organised response is a legal obligation, not just good practice.
Would your business be ready if a data breach happened tomorrow?
Our free IT Health Check reviews your logins, supplier access, backups and response plans so you can close the gaps behind most data breaches.
Or call 1300 133 770.




