top of page
Image of binary code on a red screen with the words data breach.

What Australia's Data Breach Figures Tell Us About Data Classification

26/8/12 9:00

Looking across five years of data breach reporting from the Office of the Australian Information Commissioner reveals where organisations continue to lose control of personal information through human error, and why those recurring failures deserve closer attention than the raw statistics.

Every six months, the Office of the Australian Information Commissioner (OAIC) publishes a fresh set of Notifiable Data Breaches (NDB) statistics. The headline numbers attract attention, but the longer-term trends tell the more valuable story. Looking across five years of reporting reveals where organisations continue to lose control of personal information through human error, and why those recurring failures deserve closer attention than the raw statistics.


Breaches due to human error are an ongoing trend, not a one-off


Human error has accounted for between 25% and 41% of all notifiable data breaches since 2021, with its share rising or falling in response to fluctuations in malicious and criminal attacks during each reporting period.


Graph showing the causes of data breaches in Australia split by human error and other causes.

More revealing than the overall percentage is the steady pattern beneath it. In every one of the past ten reporting periods, personal information sent to the wrong email recipient has been the leading cause of human-error breaches, followed by unauthorised disclosure through unintended release or publication. Together, these two categories have consistently accounted for around 50–75% of all reported human-error breaches in any given reporting period.


This isn’t a one-off. These same two reasons have stayed at the top of the leaderboard for five years, despite changes in overall breach volumes, cyberattack activity, and even the OAIC's reporting. It's also a pattern the Janusnet team has observed consistently through nearly three decades of helping organisations protect sensitive information. Simply put: humans are fallible.


Why the trend matters


At their core, the leading causes of Australian human error breaches are information-handling failures, not technology failures. A file is sent to the wrong recipient. A document is shared more broadly than intended. In most cases, the systems worked as designed, but a human didn't identify that information required additional protection before it left the organisation.


It's worth being precise about what the data does, and doesn't, show. OAIC figures identify the type of human error that caused a breach, but not whether classification or handling controls would have prevented it. However, the consistency of the pattern over five years is clear: misdirected and over-shared information is fundamentally a handling problem, and handling problems are exactly what data classification frameworks are designed to address.


When human error stops being embarrassing and becomes dangerous


Most of the incidents behind these statistics are, by any organisation's own account, mundane: a spreadsheet to the wrong inbox, a report published without full redaction. The consequences are usually reputational. But a small number of cases each year make clear that the same category of mistake, when the underlying data is sensitive enough, can put people in physical danger rather than just embarrassing an organisation.


Three recent examples from different countries illustrate the range:


  • A misdirected spreadsheet exposed 19,000 identities. In 2022, a UK Ministry of Defence official mistakenly emailed a spreadsheet containing sensitive details of thousands of Afghan nationals seeking relocation after supporting British forces. The breach went undetected for around 18 months.


  • A police workforce list accidentally published. In 2023, the Police Service of Northern Ireland inadvertently released a spreadsheet containing the names, ranks, and work locations of almost 10,000 officers and staff in response to a routine records request.


  • A public government dashboard that exposed confidential data. In June 2022, California’s Department of Justice launched a public analytics dashboard intended to display anonymous statistics. A misconfigured dataset made the underlying information publicly accessible for around a day, exposing names, addresses, dates of birth and criminal history records of approximately 192,000 people.


Alongside these, Australian regulators have documented a closely related pattern. The OAIC has taken enforcement action against a federal government agency and a telecommunications provider in recent years for disclosing a domestic violence victim's current address to their abuser, ordering compensation in each case. State and industry ombudsmen have separately dealt with comparable cases involving utility and telecommunications accounts, with one ombudsman receiving close to 300 domestic-violence-related complaints in a single year. And in a recent example from July 2026, abuse survivors who gave evidence to a Victorian parliamentary inquiry into cults and fringe groups say they feel exposed after their email addresses were shared with those they made submissions about.


As with the equivalent pattern seen internationally, none of these involved a sophisticated intrusion — each involved routine account or correspondence information that wasn't flagged, separated, or handled differently at the point it mattered.


These examples do not suggest the organisations involved were careless. In most cases, they had established security programs, responded appropriately once the issues were identified, and took steps to address the causes. For example, California’s DOJ commissioned an independent investigation and accepted its recommendations.


The broader lesson is that these incidents reflect the same human error pattern seen in breach reporting. The difference between an embarrassing mistake and a serious incident was not the sophistication of the attack; in many cases, there was no attack at all, but the sensitivity of the data involved.


Can your organisation stop its most sensitive data reaching the wrong person?


Cyberattacks understandably dominate the data breach conversation and remain the largest cause by volume. But five years of NDB reporting reveal a consistent secondary pattern: many breaches do not involve an attacker at all. Instead, they involve information that was not recognised as sensitive at the point it mattered.


Often, this results in a notification and remediation exercise. Sometimes, as the examples above demonstrate, the consequences are far more serious. For organisations reviewing their data security posture, the practical question is simple: if an employee sent your most sensitive document to the wrong person tomorrow, would anything stop it?


This is the gap that Janusnet's data-centric solutions address. By consistently prompting users to classify sensitive information at the point of creation (printing, saving, and prior to email transmission), organisations can apply controls that prevent everyday mistakes: warning users before external sharing, restricting distribution, or prompting review before publication. These controls target the routine mistakes that continue to drive human-error breaches.


Protect the information that matters most. Discover how Janusnet solutions enable accurate classification of whole or partial files, empowering people and systems to apply the right security controls throughout the information lifecycle. Request a demo today.

 

Sources:

https://www.oaic.gov.au/privacy/notifiable-data-breaches/notifiable-data-breach-statistics-dashboard

https://www.infomigrants.net/en/post/67791/uk-defense-ministry-data-breach-could-have-led-to-the-deaths-of-at-least-49-afghans

https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2024/10/what-price-privacy-poor-psni-procedures-culminate-in-750k-fine/

https://oag.ca.gov/news/press-releases/california-department-justice-releases-results-independent-investigation

https://privacy.org.au/2023/12/05/for-domestic-violence-victim-survivors-a-data-or-privacy-breach-can-be-extraordinarily-dangerous/

https://www.abc.net.au/news/2026-07-30/email-inadvertently-shares-identities-of-cult-survivors-victoria/106975620


bottom of page