It is a question we now hear regularly, usually with a shrug attached: everyone’s data is already out there, so what does another breach actually change?
It deserves a serious answer, because the premise is largely correct and the conclusion drawn from it is wrong.
The premise: yes, the identity data is mostly gone
The Australian record does not require exaggeration.
A coding error in the access controls for a dormant, internet-facing API that required no authentication. Names, addresses, dates of birth, phone numbers, passport numbers, driver licence numbers and Medicare identifiers.
The asset was dormant. Nobody was using it. Nobody had removed it either — and it was visible from outside the organisation the entire time.
A contractor’s username and password, synced to a personal computer and extracted by malware. No VPN multi-factor authentication, and multiple endpoint detection alerts that were not acted on.
Health claims data made this the most personally damaging Australian breach on record. It also established the pattern that has defined every year since: the attacker logged in.
One set of stolen employee credentials. Identity documents including driver licences, some dating back to 2005 — which drew scrutiny over why records were retained well beyond any operational need.
Retention is the variable most organisations never revisit. Data you no longer need is pure liability, and Latitude is the clearest Australian illustration of it.
A third-party contact centre platform, reached through social engineering. Names, email addresses, phone numbers, dates of birth and frequent flyer numbers.
No Qantas system was breached. The exposure sat entirely outside its own walls — which is where a growing majority of 2025 and 2026 incidents have originated.
Against a national population of around 27 million, and adding HWL Ebsworth, Service NSW, MyDeal, the superannuation credential-stuffing wave and several hundred incidents that never made a headline, the conclusion is unavoidable: for most adult Australians, the core identity dataset has been exposed at least once, and for many, several times over.
And it has not slowed. The OAIC recorded 1,205 breach notifications in calendar year 2025 — an eight per cent increase and an all-time high, with 59 per cent attributed to malicious or criminal attack.
What attackers are actually coming for now
1. Freshness
A 2022 record tells an attacker where you lived four years ago. A 2026 record tells them where you live now, who you bank with now, what you bought last week and who your employer is today.
Freshness is what converts a data record into a successful social engineering call. “I’m calling about your policy” fails. “I’m calling about the claim you lodged on Tuesday” succeeds. The value is not in the data being secret. It is in the data being current, because currency is what makes the caller sound legitimate.
2. Correlation
No single breach produces a complete profile. Combining them does.
One breach gives an email address and a password. Another gives a phone number and date of birth. A third gives an employer and a role. A fourth gives a health condition. Individually, four partial records. Combined, an operationally complete profile of a specific person — and the correlation is done at scale, automatically, by anyone who buys the aggregated corpora.
June 2026 produced a concrete example: an 8.3 terabyte database aggregating thirty-six separate sources — infostealer logs, criminal channels, prior breach collections and exports from live servers — containing usernames, emails, login URLs and plaintext passwords. That is the correlation layer, productised.
3. Access, not data
This is the significant shift, and the June 2026 enterprise breaches make it plain.
An attacker no longer primarily wants your record. They want your session. Credentials, tokens, cookies and multi-factor bypasses are the product now, because access is renewable and a stolen record is not. Vidar Stealer — the payload in the ClickFix campaign ASD warned Australian organisations about in May 2026 — targets exactly this: saved credentials, browser data, cryptocurrency wallets and MFA tokens.
A staff member’s home machine is infected. The stealer harvests the saved corporate SSO session. The log is sold, aggregated and resold. No corporate system was touched, no alert fired, and the organisation has no visibility at all — unless someone is deliberately looking from outside.
4. Data categories that were never in the first wave
The big Australian breaches were largely identity and financial. Several categories were barely touched and are now being actively collected:
- Health and sensitive information — the June 2026 OAIC determinations against Medmate and Monash IVF concerned tracking pixels transmitting sensitive health information, and a regulator sweep found multiple Australian health websites doing the same covertly.
- Source of funds and beneficial ownership — from 1 July 2026, Tranche 2 requires tens of thousands of small professional services firms to collect and retain exactly this for seven years.
- Corporate and operational data — contracts, pricing, board papers, legal advice. Not identity data at all, and often far more commercially damaging.
- Behavioural and location data — which is continuously generated and therefore never fully “spent”.
Freshness is what converts a data record into a successful social engineering call. “I’m calling about your policy” fails. “I’m calling about the claim you lodged on Tuesday” succeeds. The value is not in the data being secret — it is in the data being current, because currency is what makes the caller sound legitimate.
One breach gives an email and a password. Another gives a phone number and date of birth. A third gives an employer. A fourth gives a health condition. Individually, four partial records. Combined, an operationally complete profile.
June 2026 produced the concrete example: an 8.3 terabyte database aggregating thirty-six sources — infostealer logs, criminal channels, prior breach collections and exports from live servers.
Credentials, tokens, cookies and multi-factor bypasses are the product now, because access is renewable and a stolen record is not. Vidar Stealer — the payload in the ClickFix campaign ASD warned Australian organisations about in May 2026 — targets exactly this.
A staff member’s home machine is infected. The stealer harvests the saved corporate SSO session. No corporate system was touched, no alert fired, and the organisation has no visibility at all.
The big Australian breaches were largely identity and financial. Health and sensitive information, source-of-funds and beneficial ownership records, corporate and operational data, and continuously generated behavioural data were barely touched — and are now the categories being actively gathered.
5. Integrity and availability — the category that never depletes
This is the answer that most changes the threat model.
Everything above concerns confidentiality — who has a copy. Confidentiality is a resource that depletes: once your date of birth is public, it cannot be stolen again. Integrity and availability do not deplete. An attacker who alters or destroys data is unaffected by whether that data was previously exposed.
In July 2026 an attacker used valid credentials to enter Romania’s national land registry agency, mapped the network, attempted extortion, failed, and then deleted the database and its backups. The national property market stopped. Notaries could not authenticate sales or register mortgages. Nobody could obtain proof of property ownership for over a week.
No amount of prior breach made that attack less effective. If anything, the credential exposure of the preceding decade made it easier — Romania’s national cyber director indicated the attack combined known unpatched vulnerabilities with previously leaked credentials.
The same logic covers the two Mackay sugar mills that halted operations in June 2026 after a cyber incident. Nothing was stolen that mattered. Production stopped, and that was the damage.
What this means practically
- Stop reasoning about identity data as though it were secret. Build processes that do not assume knowledge of a date of birth or a licence number proves identity, because it no longer does. Any control that relies on shared secrets that have already leaked is decorative.
- Treat credentials as the primary asset. Multi-factor authentication everywhere, phishing-resistant where it matters, session lifetimes that expire, and active monitoring for corporate credentials appearing in published infostealer corpora. This is checkable from outside, today.
- Test whether your backups survive an attacker who has your administrator credentials. Romania recovered because an offline copy existed. That is the whole difference between a bad fortnight and a national crisis. Immutable or genuinely offline — and restore-tested, not merely present.
- Add integrity scenarios to the risk register. Ask what would happen if your authoritative records were altered rather than copied, and how you would detect it.
- Protect the new pools. Health data, source-of-funds records under Tranche 2, and behavioural data are the categories being actively collected now. They are also the categories held by the organisations least equipped to defend them.
The short answer
Is there anything left to steal from the Australian population? In the narrow sense — not much, and that horse left some years ago.
But the question quietly assumes theft is the threat. The next decade of Australian cyber incidents will be defined less by what is copied and more by what is altered, encrypted, destroyed or simply switched off. Those attacks work perfectly well against a population whose data is already public, and they cannot be defended by any control aimed at confidentiality.