38.9 Million Records. Four Breaches.
Is there anything left to steal?

If the identity data is already gone, what is the attacker actually coming for now? A passive external assessment is where the honest answers begin: what you expose to the outside world, and who owns that risk.

Assess Your Exposure →

It is a question we now hear regularly, usually with a shrug attached: everyone’s data is already out there, so what does another breach actually change?

It deserves a serious answer, because the premise is largely correct and the conclusion drawn from it is wrong.

The scale, before we argue about it
0
records exposed in four Australian breaches alone
0
people in Australia
0
OAIC breach notifications in 2025 — an all-time high
0
of those from malicious or criminal attack
Sources: OAIC Notifiable Data Breaches CY2025; ACMA and OAIC proceedings; public reporting on Latitude Financial and Qantas. Record counts overlap — the same person appears in several.

The premise: yes, the identity data is mostly gone

The Australian record does not require exaggeration.

Four breaches, one recurring cause
Optus
September 2022 · exposed unauthenticated API
9.5mcurrent and former customers
~35%of the Australian population
APIroot cause
Share of national population~35%

A coding error in the access controls for a dormant, internet-facing API that required no authentication. Names, addresses, dates of birth, phone numbers, passport numbers, driver licence numbers and Medicare identifiers.

The asset was dormant. Nobody was using it. Nobody had removed it either — and it was visible from outside the organisation the entire time.

Medibank
October 2022 · stolen contractor credentials
9.7mcustomers
Healthclaims data included
Credsroot cause
Share of national population~36%

A contractor’s username and password, synced to a personal computer and extracted by malware. No VPN multi-factor authentication, and multiple endpoint detection alerts that were not acted on.

Health claims data made this the most personally damaging Australian breach on record. It also established the pattern that has defined every year since: the attacker logged in.

Latitude Financial
March 2023 · one set of employee credentials
~14mpeople across AU and NZ
2005oldest records held
Credsroot cause
Share of AU + NZ population~42%

One set of stolen employee credentials. Identity documents including driver licences, some dating back to 2005 — which drew scrutiny over why records were retained well beyond any operational need.

Retention is the variable most organisations never revisit. Data you no longer need is pure liability, and Latitude is the clearest Australian illustration of it.

Qantas
June 2025 · third-party contact centre platform
~5.7mcustomers
3rd partyroot cause
Socialengineering vector
Share of national population~21%

A third-party contact centre platform, reached through social engineering. Names, email addresses, phone numbers, dates of birth and frequent flyer numbers.

No Qantas system was breached. The exposure sat entirely outside its own walls — which is where a growing majority of 2025 and 2026 incidents have originated.

Select a breach to compare scale and root cause
Sources: ACMA and OAIC proceedings concerning Optus and Medibank; public reporting on Latitude Financial and Qantas. Population share is indicative only; individuals appear across multiple breaches.

Against a national population of around 27 million, and adding HWL Ebsworth, Service NSW, MyDeal, the superannuation credential-stuffing wave and several hundred incidents that never made a headline, the conclusion is unavoidable: for most adult Australians, the core identity dataset has been exposed at least once, and for many, several times over.

And it has not slowed. The OAIC recorded 1,205 breach notifications in calendar year 2025 — an eight per cent increase and an all-time high, with 59 per cent attributed to malicious or criminal attack.

So the honest answer to the headline question is: mostly, no.There is not much left in the “name, address, date of birth, licence number” category that has not already been taken. If that were the whole threat model, we could reasonably conclude the worst is behind us. It is not the whole threat model, and it is no longer even the interesting part.

What attackers are actually coming for now

1. Freshness

A 2022 record tells an attacker where you lived four years ago. A 2026 record tells them where you live now, who you bank with now, what you bought last week and who your employer is today.

Freshness is what converts a data record into a successful social engineering call. “I’m calling about your policy” fails. “I’m calling about the claim you lodged on Tuesday” succeeds. The value is not in the data being secret. It is in the data being current, because currency is what makes the caller sound legitimate.

2. Correlation

No single breach produces a complete profile. Combining them does.

One breach gives an email address and a password. Another gives a phone number and date of birth. A third gives an employer and a role. A fourth gives a health condition. Individually, four partial records. Combined, an operationally complete profile of a specific person — and the correlation is done at scale, automatically, by anyone who buys the aggregated corpora.

June 2026 produced a concrete example: an 8.3 terabyte database aggregating thirty-six separate sources — infostealer logs, criminal channels, prior breach collections and exports from live servers — containing usernames, emails, login URLs and plaintext passwords. That is the correlation layer, productised.

3. Access, not data

This is the significant shift, and the June 2026 enterprise breaches make it plain.

An attacker no longer primarily wants your record. They want your session. Credentials, tokens, cookies and multi-factor bypasses are the product now, because access is renewable and a stolen record is not. Vidar Stealer — the payload in the ClickFix campaign ASD warned Australian organisations about in May 2026 — targets exactly this: saved credentials, browser data, cryptocurrency wallets and MFA tokens.

A staff member’s home machine is infected. The stealer harvests the saved corporate SSO session. The log is sold, aggregated and resold. No corporate system was touched, no alert fired, and the organisation has no visibility at all — unless someone is deliberately looking from outside.

4. Data categories that were never in the first wave

The big Australian breaches were largely identity and financial. Several categories were barely touched and are now being actively collected:

  • Health and sensitive information — the June 2026 OAIC determinations against Medmate and Monash IVF concerned tracking pixels transmitting sensitive health information, and a regulator sweep found multiple Australian health websites doing the same covertly.
  • Source of funds and beneficial ownership — from 1 July 2026, Tranche 2 requires tens of thousands of small professional services firms to collect and retain exactly this for seven years.
  • Corporate and operational data — contracts, pricing, board papers, legal advice. Not identity data at all, and often far more commercially damaging.
  • Behavioural and location data — which is continuously generated and therefore never fully “spent”.
So what are they actually coming for?
A current record beats a complete one
Why 2026 data is worth more than 2022 data
2022tells them where you lived
2026tells them where you live

Freshness is what converts a data record into a successful social engineering call. “I’m calling about your policy” fails. “I’m calling about the claim you lodged on Tuesday” succeeds. The value is not in the data being secret — it is in the data being current, because currency is what makes the caller sound legitimate.

Four partial records make one complete person
The aggregation layer, productised
8.3terabytes in one June 2026 corpus
36separate sources merged
Plaintext passwords included

One breach gives an email and a password. Another gives a phone number and date of birth. A third gives an employer. A fourth gives a health condition. Individually, four partial records. Combined, an operationally complete profile.

June 2026 produced the concrete example: an 8.3 terabyte database aggregating thirty-six sources — infostealer logs, criminal channels, prior breach collections and exports from live servers.

They want your session, not your record
The significant shift
Renewableaccess
Spenta stolen record
MFAtokens now targeted

Credentials, tokens, cookies and multi-factor bypasses are the product now, because access is renewable and a stolen record is not. Vidar Stealer — the payload in the ClickFix campaign ASD warned Australian organisations about in May 2026 — targets exactly this.

A staff member’s home machine is infected. The stealer harvests the saved corporate SSO session. No corporate system was touched, no alert fired, and the organisation has no visibility at all.

Data the first wave never touched
Being actively collected now
HealthOAIC determinations, June 2026
7 yrsTranche 2 retention from 1 July 2026
Corporatecontracts, pricing, advice

The big Australian breaches were largely identity and financial. Health and sensitive information, source-of-funds and beneficial ownership records, corporate and operational data, and continuously generated behavioural data were barely touched — and are now the categories being actively gathered.

Four answers — select each

5. Integrity and availability — the category that never depletes

This is the answer that most changes the threat model.

Everything above concerns confidentiality — who has a copy. Confidentiality is a resource that depletes: once your date of birth is public, it cannot be stolen again. Integrity and availability do not deplete. An attacker who alters or destroys data is unaffected by whether that data was previously exposed.

In July 2026 an attacker used valid credentials to enter Romania’s national land registry agency, mapped the network, attempted extortion, failed, and then deleted the database and its backups. The national property market stopped. Notaries could not authenticate sales or register mortgages. Nobody could obtain proof of property ownership for over a week.

No amount of prior breach made that attack less effective. If anything, the credential exposure of the preceding decade made it easier — Romania’s national cyber director indicated the attack combined known unpatched vulnerabilities with previously leaked credentials.

The same logic covers the two Mackay sugar mills that halted operations in June 2026 after a cyber incident. Nothing was stolen that mattered. Production stopped, and that was the damage.

The reframeIf your risk register still treats “data breach” as the primary cyber scenario, it is describing 2022. The scenarios that should now sit alongside it are: our records are altered and we cannot prove which are correct; our systems and our backups are destroyed; and we cannot operate for three weeks. None of those are mitigated by the fact that the data was already exposed.

What this means practically

  • Stop reasoning about identity data as though it were secret. Build processes that do not assume knowledge of a date of birth or a licence number proves identity, because it no longer does. Any control that relies on shared secrets that have already leaked is decorative.
  • Treat credentials as the primary asset. Multi-factor authentication everywhere, phishing-resistant where it matters, session lifetimes that expire, and active monitoring for corporate credentials appearing in published infostealer corpora. This is checkable from outside, today.
  • Test whether your backups survive an attacker who has your administrator credentials. Romania recovered because an offline copy existed. That is the whole difference between a bad fortnight and a national crisis. Immutable or genuinely offline — and restore-tested, not merely present.
  • Add integrity scenarios to the risk register. Ask what would happen if your authoritative records were altered rather than copied, and how you would detect it.
  • Protect the new pools. Health data, source-of-funds records under Tranche 2, and behavioural data are the categories being actively collected now. They are also the categories held by the organisations least equipped to defend them.

The short answer

Is there anything left to steal from the Australian population? In the narrow sense — not much, and that horse left some years ago.

But the question quietly assumes theft is the threat. The next decade of Australian cyber incidents will be defined less by what is copied and more by what is altered, encrypted, destroyed or simply switched off. Those attacks work perfectly well against a population whose data is already public, and they cannot be defended by any control aimed at confidentiality.

Passive only — no systems accessedBlackFlag Advisory assesses what your organisation exposes externally — access paths, credential exposure, and the interfaces through which an attacker would reach the systems that hold your authoritative records. Exclusively passive OSINT, publicly available data, no systems accessed.
SourcesOAIC Notifiable Data Breaches reporting for CY2025 and prior periods; ACMA and OAIC proceedings concerning the Optus and Medibank incidents; public reporting on the Latitude Financial and Qantas breaches; ASD ACSC advisory on ClickFix and Vidar Stealer (7 May 2026); ASD Annual Cyber Threat Report 2024-25; reporting on the ANCPI land registry incident (July 2026) including Romania’s National Directorate for Cyber Security; OAIC determinations concerning Medmate and Monash IVF (June 2026). Analysis by BlackFlag Advisory.

The Threat Model Has Moved.
Has Your Assessment?

A BlackFlag Advisory passive assessment covers what actually matters now — exposed access paths, credential reuse, and the interfaces that would let an attacker alter or destroy rather than merely copy.

Request an Assessment →
Passive Only — No Systems Accessed

All BlackFlag Advisory assessments use exclusively passive OSINT techniques and publicly available data sources. No systems, networks, or accounts are accessed, probed, or tested at any time. Board-ready output delivered within three to seven business days.