At a glance
A data breach occurs when sensitive or personal information is accessed, shared or exposed by unauthorised people. This may be by accident, or because of a security breach. You can reduce the risk of unauthorised access to your accounts by using unique passwords and enabling multi-factor authentication.
If you’ve been affected by a data breach, find out how to recover.
What is a data breach
Data breaches are a common cyber threat that can affect anyone. They may happen by accident, such as when an email is sent to the wrong person, or because of a security breach.
Many organisations collect and store many personal details. The more systems that store your personal details the greater the chance of a data breach. The personal information you share may include your:
- address
- phone number
- identification documents
- date of birth
- credit card number
- health records.
If your information is exposed in a data breach, it can have serious impacts. It might allow cybercriminals to access your online accounts, including your bank account. Your information could also be used in scams or for identity theft.
Warning signs of a data breach
Signs your personal information may have been leaked or stolen:
- An organisation tells you there has been a data breach.
- There are attempts to log in to your accounts or misuse your information.
- You get more spam calls, emails or messages.
- You see news or online posts about a data breach involving a company you use.
- Your information shows up on breach-checking tools like Have I been Pwned.
How to reduce the risk of a data breach
There are things you can do to reduce the likelihood and impact of a data breach.
Only share information that an organisation really needs
If a field is optional, think carefully before filling it in. For example, you may not need to provide your home address for an online subscription.
Choose organisations that take cyber security seriously
Be careful with organisations that have a history of a poor cyber security.
Use passkeys
Use passkeys wherever possible. Passkeys are a more secure way to log in to your online accounts than using passwords.
Use a password manager
Use a password manager to help keep track of passwords. Password managers can automatically generate and store strong passwords, usually in the form of a random string of characters.
Avoid reusing passwords
Using different passwords for different accounts means a cybercriminal can’t use a stolen password to access other accounts. Refer to our personal cyber security handbook for advice about passwords.
Use multi-factor authentication (MFA) across accounts
MFA is one of the best ways to protect your accounts. MFA is when you need 2 or more different ways to verify you are the account owner before you can log in. Refer to our personal cyber security handbook for advice about MFA.
Back up important information
Keep backups of important information so you can recover it if an account or service becomes unavailable. Learn more about backups.
The Notifiable Data Breaches scheme
In Australia, organisations that are covered by the Notifiable Data Breaches scheme must tell you if your personal information is involved in a data breach that could put you at risk of serious harm. This can include physical, psychological, emotional, financial or reputational harm.
If an organisation contacts you about a data breach, they must also provide advice on how you can protect yourself.
Organisations covered by the scheme include:
- Australian Government agencies
- businesses and not-for-profits with an annual turnover of more than $3 million
- credit reporting bodies
- health service providers.
Visit the Office of the Australian Information Commissioner website to learn more about the Notifiable Data Breaches scheme.
Never miss a threat
Sign up to receive the latest cyber security alerts, along with information on emerging threats and how to stay secure online.