A data breach is an incident in which protected information is lost, accessed, disclosed, changed, or taken without authorisation. It can start with a targeted intrusion or something as ordinary as an email sent to the wrong person.
This article breaks down what a data breach means, how breaches happen, what attackers do with stolen data, and what Australian SMBs should know about notification duties and prevention.
Once you understand what happened, what information was involved, and who may be harmed, you can contain the incident and decide whether notification is required.
What is a Data Breach?
A data breach is an incident in which protected information is lost or subjected to unauthorised access, disclosure, modification, or theft.
The information may include names, contact details, login credentials, identity documents, health records, financial data, source code, contracts, or commercially sensitive files.
A breach can affect digital systems, paper records, removable storage, cloud platforms, email accounts, or third-party services.
A breach is not identical to every cyber incident but one incident can involve both. For example:
- Blocked malware may require investigation without becoming a breach.
- A service outage affects availability, while a breach concerns loss of control over information.
How Does a Data Breach Happen?
Data breaches commonly happen through four paths: lost or stolen devices and records, human error, insider threats, and malicious cyber attacks.
Some breaches involve more than one path. For example, an attacker may steal an employee’s credentials, exploit excessive access, and then extract customer data.
Lost or Stolen Devices and Records
Lost or stolen devices and records can cause a data breach when unauthorised people gain access to the information they contain.
In this case, several common examples include:
- Unlocked laptops
- Unencrypted USB drives
- Exposed paper files
- Missing backup media.
Device encryption, remote locking, access controls, secure storage, and disposal procedures can reduce the resulting exposure and potential harm.
Human Error
Human error causes breaches when someone accidentally sends, publishes, changes, or disposes of information unsafely.
Examples include emailing the wrong recipient, exposing a cloud folder, or publishing hidden personal data.
💡 According to OAIC’s Latest Notifiable Data Breach statistics for January to June 2025, human error caused 37% of notifications in January to June 2025.
Recipient checks, approval steps, access reviews, and clear reporting procedures are therefore practical safeguards.
Your staff also need a simple way to report mistakes quickly before the exposure grows.
Insider Threats
Insider threats arise when a trusted person misuses legitimate access or retains access they no longer need.
An insider may act maliciously or copy data carelessly into unsafe storage.
For this reason, you need to consider least-privilege access, activity logging, prompt offboarding, and reviews of unusual data movement to help reduce this exposure.
Malicious and Targeted Cyber Attacks
Malicious attacks become targeted cyber attacks when threat actors deliberately focus on your business, users, systems, or data.
They may use phishing, stolen credentials, ransomware, exposed services, application flaws, or cloud misconfigurations to gain access and extract information.
A vulnerability assessment helps identify weaknesses that could support these attack paths.
A penetration test then goes further by checking whether selected weaknesses can be exploited in practice.
Both giving your team clearer evidence for prioritising remediation and closing the most credible routes. Together, these two steps form the core of offensive security testing, which validates real-world exposure rather than theoretical risk.
What Can Attackers do With Stolen Data?
Attackers can use stolen data to impersonate people, take over accounts, commit fraud, pressure victims, or support further attacks.
The value depends on the information and how it can be combined. For example:
- Login details can support credential-stuffing attacks across other services, which is why consistent password management across accounts limits how far a single exposed credential can spread.
- Identity documents may enable identity theft.
- Contact, role, or supplier information can make social engineering more convincing.
As you know, the health, legal, or personal financial records can expose people to distress, discrimination, extortion, or reputational harm.
Business data creates another set of consequences. Source code, contracts, customer lists, pricing, or product plans may support competitive harm or follow-on attacks.
Even an older dataset can remain useful when it contains identity details that people cannot easily replace.
This is why response decisions should consider the data itself, the people affected, and the realistic ways it could be misused. A record count alone does not show the seriousness of a breach.
What are Some Notable Data Breaches in Australia?
Several large Australian data breaches show how identity, financial, contact, and health information can create long-lived consequences.
| Incident | Reported scale | Practical lesson |
|---|---|---|
| Optus, 2022 | About 9.5 million people | Large identity holdings increase potential harm and protection expectations. |
| Medibank, 2022 | About 9.7 million people | Sensitive health information can intensify personal harm. |
| Latitude, 2023 | About 14.1 million people in Australia and New Zealand | Retained historical records can expand the impact beyond current customers. |
The OAIC has taken civil penalty action involving Optus and Medibank, with the allegations subject to court processes. The OAIC has also investigated Latitude.
These examples do not mean every small business faces an incident of the same scale. They show why data inventory, retention, identity access, third-party access, and tested response processes matter.
How do You Prevent a Data Breach?
You can reduce data-breach risk by limiting the data you hold, controlling access, closing known weaknesses, detecting misuse, and preparing a tested response, the core elements of a broader cybersecurity strategy.
Usually, we suggest the starting point to prevent data breach is not buying a tool. Ideally, you can start with these practical prevention measures:
- Identify sensitive data, where it lives, and who can access it.
- Remove information and access the business no longer needs.
- Apply multi-factor authentication.
- Restrict administrative privileges.
- Patch applications and operating systems based on risk.
- Secure endpoints, email, cloud services, and backups.
- Train staff to recognise and report suspicious activity or mistakes through regular security awareness training.
- Monitor unusual logins, privilege changes, and large data transfers.
- Maintain a breach response plan with named decision-makers.
- Test security controls, restoration processes, and escalation paths.
And always remember that no single product can cover every breach path.
The ASD’s Essential Eight provides an Australian technical baseline for mitigating common cyber threats.
And for your information, the ASD describes the Essential Eight as a minimum set, so businesses may still need additional controls suited to their data and environment.
Meanwhile, SMB1001 helps smaller businesses organise broader controls, policies, staff responsibilities, and security evidence as their cybersecurity maturity develops.
Also, the data loss prevention adds a more data-focused layer to these baseline practices. It can help identify and control sensitive information as employees access, share, or move it across business systems.
What are Australia’s Data Breach Notification Laws?
Australia’s data breach notification laws are rules under the Privacy Act 1988 and its Notifiable Data Breaches scheme that require covered organisations to notify the OAIC and affected individuals about eligible breaches likely to cause serious harm.
These duties operate through the Notifiable Data Breaches (NDB) scheme. They do not automatically apply to every small business.
Most businesses with annual turnover of $3 million or less are exempt from the Privacy Act, although exceptions cover certain health service providers, credit providers, entities that trade in personal information, and tax file number recipients.
Even when the NDB scheme does not apply, a business may still face contractual, sector-specific, state-based, or customer notification expectations.
Privacy or legal advice may be necessary when coverage is unclear. Mapping these obligations against a wider cybersecurity compliance framework can help track requirements that fall outside the Privacy Act.
The reporting figures show why preparation matters. The OAIC received 532 notifications from January to June 2025.
Businesses therefore need technical controls and internal reporting procedures to identify and contain breaches.
What is the Notifiable Data Breaches (NDB) Scheme?
The NDB scheme requires covered entities to notify the OAIC and affected people when a personal-information breach is likely to result in serious harm.
An eligible data breach involves unauthorised access or disclosure or loss likely to lead to either outcome. It must also be likely to cause serious harm that remedial action has not prevented.
Serious harm is assessed in context. Relevant factors include the sensitivity of the information, existing protections, who obtained the data, and the possible consequences.
Notification allows affected people to take protective action. That may include changing credentials, contacting a bank, replacing identity documents, or monitoring for identity fraud.
When Must a Business Report a Data Breach?
A covered business must notify affected people and the OAIC promptly once it has reasonable grounds to believe an eligible data breach has occurred.
If the business only suspects an eligible breach, it must assess the incident. According to the OAIC guide for responding to data breaches, businesses need to complete that assessment within 30 calendar days after grounds for suspicion arise.
This is an assessment period, not a routine waiting period before notification.
The business should contain the incident, preserve evidence, identify the affected data and people, assess possible harm, and document its decision.
A required notification should describe the breach, the information involved, and the protective steps affected individuals should consider.
How Does a Data Breach Affect Australian Small Businesses?
Data breaches affect Australian small businesses by disrupting operations, creating recovery and notification costs.
💡 For reference, IBM’s 2025 Cost of a Data Breach Report places the global average breach cost at USD 4.4 million.
We can break down how data breaches affect Australian small businesses in two categories: direct and indirect. Both consuming limited staff time and weakening trust with customers and commercial partners.
Direct expenses of data breaches for small businesses may include:
- Forensic investigation
- Legal advice
- Customer notification
- Identity support
- System restoration
- Security remediation
Indirect consequences of data breaches to small business can include:
- Lost productivity
- Delayed sales
- Supplier scrutiny
- Insurance discussions
- Leadership distraction
This figure is not an Australian or small-business average, but it shows how detection and containment speed can influence the overall impact.
For a lean team, the hardest problem is often ownership. Someone must coordinate technical containment, privacy assessment, customer communication, remediation evidence, and after-hours decisions.
SMB1001 can help structure controls and responsibilities, while structured managed security services can provide ongoing monitoring and defined escalation when internal security coverage is limited.
Both can help you reduce delays when an incident requires immediate decisions from business leaders.
Strengthen Your Data Breach Defences with RedScale
Your data breach defences weaken when your team cannot see where sensitive information is stored, how it moves, or when someone handles it outside normal business rules.
Unusual data movement may go unnoticed until a user reports it or a wider incident reveals it.
That leaves your team reconstructing what happened when it should be containing the exposure and protecting affected information.
RedScale helps bring that visibility and control closer to the data itself.
With RedScale’s data loss prevention services, your team can identify sensitive information, define how it should be handled, and control risky movement across platforms.
You gain clearer oversight of the information that matters without applying the same restrictions to every user or file.
An end-to-end managed security service can also support those controls whenever you need continuous visibility across the wider security environment.
Contact RedScale to strengthen your data controls.
FAQ
What is the Difference Between a Data Breach and a Data Leak?
A data breach covers lost, accessed, disclosed, changed, or stolen protected information, while a data leak usually describes exposed information. A leak may result from a public cloud folder, misconfigured database, or accidental publication. A breach is broader and can include a leak, deliberate intrusion, theft, or internal misuse.
How Can I Check if My Personal Data Has Been Breached?
You can check if your personal data has been breached by reviewing official breach notices, checking your accounts for unusual activity, and searching your email address through a reputable breach-notification service. But a clean result does not guarantee your data is safe because not every breach becomes public or appears in searchable databases.
What Penalties Can Australian Businesses Face for a Data Breach?
A data breach does not automatically produce a penalty, but failures to meet Privacy Act obligations can lead to investigation, regulatory action, enforceable outcomes, or civil penalties. For serious or repeated privacy interference by a body corporate, the maximum can be the greater of $50 million, three times the benefit obtained, or 30% of adjusted turnover when the benefit cannot be determined.
How Does RedScale Help Businesses Prevent and respond to data breaches?
RedScale helps Australian businesses strengthen the controls and security operations that reduce exposure and support faster investigation. This may include data loss prevention, vulnerability management, monitoring, alert triage, escalation, remediation support, and response planning. These services reduce operational gaps but do not guarantee that a breach will never occur or replace the business’s legal and privacy responsibilities.






