New research from an Australian software consultancy has shed light on the rising volume of data breaches in the country, which sectors are the slowest to discover them – and the news isn’t great for the government sector.
Adaca obtained data breach figures from the Office of the Australian Information Commissioner (OAIC) under Freedom of Information laws, and discovered that while, on average, data breaches impacting Australian organisations took three days to discover, breaches of government data were another thing entirely.
According to the data, it takes government entities, on average, 108 days to discover a data breach.
Adaca’s founder, Lambros Photios, thinks he knows why.
“The government is clearly relying on third parties to notify them of an incident. There is an absence of internal systems or controls to monitor for bad actors, and the Australian government is therefore relying on their hackers to, in good faith, notify them when there is a breach,” Photios told Cyber Daily.
“Having vulnerabilities and no monitoring means the door is being left wide open to hackers, which, as a country collecting only more of our data each year with new systems, is completely unacceptable.”
Photios said that breach reporting was clearly a challenge for many sectors, but that “pales in comparison to government data breaches”.
“In total, just 7 per cent of government breaches were notified within 10 days against 34 per cent from the private sector. This signals a mishandling of data breach reporting processes by the Australian government,” Photios said.
He also noted that not all breaches are the result of malicious cyber activity such as hacking.
“The OAIC data also includes breaches that were the consequence of human error and system malfunctions,” Photios said.
“But we need the government to detect and report incidents much faster than it is doing already.”
Government organisations are also the third-largest source of breaches, behind only health and finance.
Data breaches, regardless of the source, are also rising, with 117 breaches reported each month in the first half of 2026 – a rise of 69 per cent compared with 2022. Breaches caused by malicious hacking have doubled, however, while ransomware-related breaches have dropped from 29 per cent in 2022 to 22.3 per cent in 2026.
Photios said he hopes the data will be seen as a “wake-up call”.
“However, it is clear the Medicare incident is the most recent of a long list of breaches that the government is failing to catch on their own,” Photios said.
“Rather than innovating with investment in data centres for big tech, they should be looking internally to tighten their own cyber security controls.”
In all, Adaca analysed 4,769 breaches, all reported since 2022. You can read the full report here.
Want to see more stories from trusted news sources?Make Cyber Daily a preferred news source on Google.