28 May 2025

Cyber security gets stuffed!


GILES RAFFERTY, Corporate Communication and Media Advisor.


The recent ‘credential stuffing’ cyber attack on Australia’s super funds sector once again highlights the growing cyber threat to business. ‘Credential stuffing’ is when usernames and passwords sourced from hacks on lower value websites or the dark web are used to gain access to higher value targets such as super fund accounts. Last month’s cyber attack on several large super funds, is reported to have resulted in the theft of at least half a million dollars. And the threat from cyber criminals continues to grow.

New statistics from the Office of the Australian Information Commissioner (OAIC) reveal 2024 was a record year for the reporting of cyber security breaches, with 1,113 data breach notifications. The largest number in a single year since since mandatory data breach notification requirements started in 2018.



First half surge

2024 represented another first. The number of cyber security incidents in the first six months of 2024 (518), exceeded the number for the final six months of 2023 (483), the first time that notifications in the first half of a year have exceeded the second half of the preceding year.

The established trend of a greater number of breaches being recorded in the second half of each year since 2018 has persisted, with a further 595 breaches between July and December 2024. The total mandatory data breach notifications since 2018 now stands at over 6,500.



Malicious and criminal attacks

The most recent data available from the OAIC, the July to December 2024 period, shows malicious or criminal attacks up 14% from the first half of the year and the largest source of data breaches at 69%. Within that, cyber security breaches accounted for the majority of the malicious or criminal attacks.

The OAIC also notes that phishing scams were the leading cause of cyber security breaches. Phishing scams are where cyber criminals pretend to be acting for reputable companies and send email or text messages designed to trick their targets into handing over personal information.


“The threat of data breaches, especially through the efforts of malicious actors, is unlikely to diminish, and the risks to Australians are only likely to increase. Businesses and government agencies need to step up privacy and security measures to keep pace.”

Carly Kind, Australian Privacy Commissioner

Close to a third of incidents reported were the result of human errors, including email blunders such as copying in the wrong e-mail address, unintended publication of data or the failure to redact sensitive information.

As a percentage of total breaches, those caused by human error in the second half of 2024 made up 29% compared to 30 % in the first half. System faults made up 2% of the notifiable data breaches in the second half down from 3% in the first.



Health sector leads on breaches 

Once again, in the July to December 2024 period the health sector had the most reported data breaches (20%), with Australian Government agencies reporting the second most (17%). This reporting period also saw a significant increase in data breaches caused by social engineering and impersonation, which is the manipulation of people into carrying out specific actions or divulging information.



A question of ‘When’ not ‘If’

The number of cyber security incidents being reported under the Notifiable Data Breaches scheme inexorably rises. As it does, the question moves towards ‘When’ rather than ‘If’ a company, which relies on collecting sensitive data, will experience a data breach.

Should a breach occur it is small comfort that the OAIC does not take regulatory action in response to every incident reported. It is looking to act where enforcement would have the greatest impact and to where there is the largest risk of harm to the community. One recent example of regulatory action in response to a data breach report is the OAIC’s acceptance of an enforceable undertaking offered by Oxfam Australia.

Against this backdrop of ever increasing cyber risk, it is more important than ever that Companies have a cyber-incident response plan in place. That plan should be regularly tested, include the advice of external advisers and incorporate a well thought out communication strategy. FIRST Advisers’ experience of crisis communications means we are well positioned to help a Company’s internal resources prepare for and manage cyber breaches.


Source: www.oaic.gov.au


26 June 2024

What to do if you suffer a cyber security data breach


GILES RAFFERTY, Corporate Communication and Media Advisor It feels more like ‘when’ and not ‘if’ companies will face data breaches. In the last week, reports are emerging of a hacker trying to sell data from 30 million Ticketek customers following the announcement of a data breach by Ticketek on 31 May 2024.  With the growing […]

Read More
29 February 2024

Managing Cyber security risks


GILES RAFFERTY, Corporate Communication and Media Advisor Cybersecurity is back at the top of the news agenda. The Albanese Government is seeking to tackle ‘Doxing’, which is publicly revealing identifying material about someone without their consent; the AFP has helped to smash global ransomware gang Lockbit and the hacker claimed to behind the massive Medibank […]

Read More
28 February 2023

CEOs need to drive social change to build trust


GILES RAFFERTY, Corporate Communications and Media The findings of 2023 Edelman Trust Barometer were revealed at Davos in January, with the Australian cut of the data made public at the start of February. The Edelman global survey highlights concern around “severe polarisation” among respondents, which the PR firm interprets as people believing their society is […]

Read More
12 December 2022

Travelling at the speed of change, 2022 in review


GILES RAFFERTY, Corporate Communications and Media US founding father, Benjamin Franklin, said “nothing is certain except death and taxes”. Had he been in a more expansive mood he may have included ‘change’ as another certainty. 2022 has been a year of change. We welcomed Queen Elizabeth’s Platinum Jubilee and mourned her passing. We celebrated the […]

Read More
30 August 2022

Accessing new media opportunities


GILES RAFFERTY, Corporate Communications and Media Adviser It is well understood that the media industry has been experiencing significant technological disruption with the emergence of digital, online and social media platforms. The recent 2022 Digital News Report, by the Reuters Institute and the University of Oxford, indicates the various shocks of the last few years, […]

Read More
28 February 2022

Distrust threatens societal stability


GILES RAFFERTY, Corporate Communications and Media Adviser One of the findings from the annual Edelman Trust Barometer survey is a cycle of distrust that is threatening societal stability both here in Australia and globally. The survey results were published on February 16th, a little over a week before Russia invaded the Ukraine. Australia trapped in […]

Read More
4 March 2021

Locking in the Trust premium


GILES RAFFERTY, Corporate Communication and Media Advisor Trust in Australian Institutions has surged during the Coronavirus pandemic to reach all-time highs.  This resurgence of trust means, in Australia,  the institutions of Business, Government, Media and NGO’s are all now viewed as competent where just 12 months ago only Business was seen to be so. Two institutions, […]

Read More
6 November 2017

Communicating in a Crisis


Geoff Michels, Senior Corporate Communications Adviser A crisis is an event or a series of events that adversely affects the health or well-being of employees, the environment, a community or the wider public, the integrity of a product or the reputation of an organisation.  A crisis can be operational (fire, an accident) or non-operational (workplace discrimination, […]

Read More
10 April 2017

Presentation Techniques for Senior Executives


Geoff Michels, Senior Adviser – Corporate Communications At FIRST Advisers we are frequently asked to coach senior business executives or managers on presentation techniques.  Generally it’s about coming across well at an AGM, or at a roadshow event or in presenting to audiences large and small.  There is also a significant demand for advice and […]

Read More
5 July 2016

Short Attacks: The new wolf pack


VICTORIA GEDDES, ECECUTIVE DIRECTOR Those who have been on the receiving end of a short attack describe the process as akin to being at war, or being pursued by a pack of wolves, with the company’s very destruction their opponent’s goal. A short or bear attack, to make the distinction clear, is not the same […]

Read More
12 November 2015

Why someone on the outside should draft that press release


FIRST Advisers Corporate Communications Some see it as axiomatic that the people within a company are best placed to draft a press release or other piece of external communication. After all, who better to write the news than those on the inside: the people who were responsible for it, were there from the beginning and […]

Read More

Archives