The common way Australians have their data stolen — and what it's costing

The average financial losses from cybercrimes, both for Australians and businesses, continue to rise annually.

A woman in a black jacket worn over a white shirt, leaning on her hand, looking down at her computer while on the phone.

The ASD received 84,700 cybercrime reports in 2024-25, an average of one report every six minutes. Credit: Moodboard

The agency responsible for detecting and disrupting malicious cyber threats wants certain password habits to be "over", as the amount of money lost to cybercrimes continues to rise.

According to the Australian Signals Directorate (ASD), relying on a username and password system only, without additional steps for verification, can leave Australians' data vulnerable to hacking.

Last year, individual victims of cybercrimes across Australia lost an average of $33,000, an 8 per cent increase.

On Tuesday, the ASD will release its annual cyber threat report, revealing businesses suffered even higher losses, doubling to roughly $202,000 per crime.

ASD director-general Abigail Bradshaw told SBS News it's time to move past passwords.

"I hope it [using passwords] is over. What we need is more technologies that enable multi-factor authentication, so that you are never solely reliant on a username and a password," she said.
An infographic detailing how cyber incidents have risen to 1,200 in the last year, along with an increase in cybercrime reports, 84,700.
ASD responded to more than 1,200 cybersecurity incidents, an 11 per cent increase from 2023-24. Source: SBS News
"We need anything, all accounts, must have multi-factor authentication. You need to roll your creds, that's the language we use, change your passwords increasingly regularly. Don't use it across multiple devices," Bradshaw said.

She said Australia is increasingly targeted by both cybercriminals and state-sponsored cyber actors.

Although she notes that the way they are gaining access to organisations, critical infrastructure, and businesses is changing.

"Networks are increasingly not being hacked, but are being breached through compromised or stolen credentials to gain unauthorised access," she said.

In almost half of the incidents impacting large organisations, access was gained using real usernames and passwords, often stolen or bought by cybercriminals on the dark web.

Given that the access is genuine, instead of a hack, it is harder to track.

"Once access is gained, they mimic legitimate user behaviour to steal sensitive personal or corporate information, install ransomware or malware and take over accounts," she said.
A man in a suit stands in front of an Australian flag and a dark blue curtain, speaking.
Cybersecurity Minister Tony Burke urged Australians to keep software up to date and enable multifactor authentication to keep themselves safe. Source: AAP / Lukas Coch
Cybersecurity Minister Tony Burke acknowledged work by the signals directorate "protects Australians every day", but also said there are steps users can take to keep themselves safe online.

"Most cyber incidents are preventable, and basic defensive measures make a huge difference," he said.

How to keep yourself safe from cybercrime

Passwords and usernames remain the biggest vulnerability for safety, with home office routers often also targeted by cybercriminals and used to conceal their activities.

The ASD advised that the basics are still the best form of defence from cybercrime, encouraging multi-factor authentication, which requires at least two forms of identity verification.

Stephanie Crowe, head of ASD's Australian Cyber Security Centre, said 42 per cent of the incidents reported through ASD in the last financial year involved an element of stolen credentials.

"What that enables them [cyber criminals] to do is use a username and password to get onto an individual's device, or, if they're lucky enough, they've also been able to take usernames and passwords for people's corporate accounts," he told SBS News.
An infographic detailing the annual average cost of cybercrime attacks on individuals, $33,000, and small businesses, $56,000.
The average self-reported cost of cybercrime per report for small businesses rose by 14 per cent to $56,600, while the cost to individuals rose 8 per cent to $33,000. Source: SBS News
When using passwords, the phrases need to remain unique, while reputable password managers can ensure passwords are not reused.

Other tips include regularly updating software on devices, backing up important data and staying alert to phishing messages and scams.

Last year, the ASD responded to 1,200 incidents and blocked access to 334 million malicious domains.

Businesses issued warning ahead of 2030

The ASD warns the environment will grow increasingly challenging for businesses, with the development of post-quantum cryptography, anticipated by 2030.

Whenever communication is exchanged between users, whether via websites or emails, encryption is applied to the messaging in transit to protect the data.

The technology anticipated will be able to unscramble this messaging quickly, making businesses more susceptible to data decryption or hacking.
ASD urged businesses to invest and prepare for this technology, as the cost of a hack could ultimately be greater.

It also includes three other changes: implementing effective logging, replacing legacy IT and effectively managing third-party risk.

Critical infrastructure emerged as the key concern in 2024-25, with malicious activity impacting networks over 190 times, a rise of 111 per cent.

"This highlights the ongoing need for vigilance and action to mitigate against persistent threats," Bradshaw said.

The agency collects and analyses data from communications systems, radio frequencies and electronic transmissions.

It answered over 42,500 calls to the Australian Cyber Security Hotline last year.


For the latest from SBS News, download our app and subscribe to our newsletter.

Share
4 min read

Published

Updated

By Ewa Staszewska
Source: SBS News


Share this with family and friends


Get SBS News daily and direct to your Inbox

Sign up now for the latest news from Australia and around the world direct to your inbox.

By subscribing, you agree to SBS’s terms of service and privacy policy including receiving email updates from SBS.

Download our apps
SBS News
SBS Audio
SBS On Demand

Listen to our podcasts
An overview of the day's top stories from SBS News
Interviews and feature reports from SBS News
Your daily ten minute finance and business news wrap with SBS Finance Editor Ricardo Gonçalves.
A daily five minute news wrap for English learners and people with disability
Get the latest with our News podcasts on your favourite podcast apps.

Watch on SBS
SBS World News

SBS World News

Take a global view with Australia's most comprehensive world news service
Watch the latest news videos from Australia and across the world