Australian Cybercrime Statistics 2024–25
Verified figures from official Australian Government reports. All statistics on this page are sourced exclusively from the Australian Cyber Security Centre (ACSC), the Australian Competition and Consumer Commission (ACCC), the National Anti-Scam Centre (NASC), and the Australian Signals Directorate (ASD). No estimates or third-party projections are included.
Methodology & Scope
This page compiles statistics from three primary Australian Government publications covering the 2024–25 financial year (1 July 2024 – 30 June 2025) and the 2025 calendar year:
Note on scam vs cybercrime figures: Scam statistics (ACCC) and cybercrime statistics (ACSC) are collected by separate agencies using different definitions and methodologies. Overlap is possible; figures should not be added together. The ACSC reports on unauthorised computer access, malware, and fraud facilitated by technology. The ACCC reports on scam-type fraud across all reporting channels.
Key Figures at a Glance
Cybercrime Reports & Incidents (ACSC 2024–25)
The following figures are drawn from the ASD's ACSC Annual Cyber Threat Report 2024–25, covering 1 July 2024 to 30 June 2025.
Report Volume
| Metric | 2024–25 Figure | Change |
|---|---|---|
| Total cybercrime reports to ACSC | 84,700+ | — |
| Average reports per day | ~232 | — |
| Average frequency | 1 every 6 minutes | — |
| ASD cyber security incidents responded to | 1,200+ | ↑ 11% from 2023–24 |
| ACSC Cyber Security Hotline calls | 42,500+ | ↑ 16% from 2023–24 |
| Malicious activity notifications sent by ASD | 1,700+ | ↑ 83% from 2023–24 |
Financial Impact on Businesses
| Business Size | Avg. Cost per Cybercrime Report (2024–25) | Year-on-Year Change |
|---|---|---|
| All businesses (average) | $80,850 | ↑ 50% |
| Small business | $56,600 | ↑ 14% |
| Medium business | $97,200 | ↑ 55% |
| Large business | $202,700 | ↑ 219% |
Financial Impact on Individuals
| Metric | 2024–25 Figure | Year-on-Year Change |
|---|---|---|
| Average cost per cybercrime report (individuals) | $33,000 | ↑ 8% |
Top Cybercrime Types (Businesses, 2024–25)
| Crime Type | Share of Business Reports |
|---|---|
| Email compromise | 19% |
| Business email compromise (BEC) fraud | 15% |
| Identity fraud | 11% |
Top Cybercrime Types (Individuals, 2024–25)
| Crime Type | Share of Individual Reports |
|---|---|
| Identity fraud | 30% |
| Online shopping fraud | 13% |
| Online banking fraud | 10% |
Critical Infrastructure Incidents (2024–25)
| Metric | 2024–25 Figure | Change |
|---|---|---|
| Critical infrastructure as share of all ASD incidents | 13% | ↑ from 11% |
| Critical infrastructure entities notified by ASD | 190+ | ↑ 111% |
| DDoS incidents against critical infrastructure | 200+ | ↑ 280%+ |
| Sector | Share of CI Incidents |
|---|---|
| Financial services | 32% |
| Transport | 26% |
| Information media & telecommunications | 16% |
| Attack Type | Share |
|---|---|
| Reconnaissance | 41% |
| Distributed Denial of Service (DDoS) | 31% |
| Phishing | 20% |
Scam Losses by Agency (2025 Calendar Year)
The following figures are drawn from the ACCC/NASC Targeting Scams Report 2025, published March 2026. This report consolidates data from five reporting agencies across calendar year 2025.
Total Losses
| Metric | 2025 Figure | Change from 2024 |
|---|---|---|
| Total reported scam losses (all agencies) | $2.18 billion | ↑ 7.8% |
| Total scam reports (all agencies) | 481,523 | ↓ 2.7% |
| Median loss per report | $400 | ↓ from $500 |
Reports and Losses by Reporting Agency (2025)
| Agency | Reports | Losses Reported |
|---|---|---|
| Scamwatch (ACCC) | 200,675 | $334.8 million |
| ReportCyber (AFP/ASD) | 58,876 | $774.2 million |
| AFCX (Australian Financial Crimes Exchange) | 202,943 | $842.3 million |
| ASIC | 1,565 | $135.0 million |
| IDCARE | 47,589 | $535.8 million* |
| *IDCARE figures may involve multiple victimisation events and should not be aggregated with other agency totals. The $2.18 billion total is derived by the ACCC/NASC after accounting for overlap. | ||
Top 5 Scam Types by Losses (2025)
| Rank | Scam Type | Total Losses (2025) |
|---|---|---|
| 1 | Investment scams | $837.7 million |
| 2 | Payment redirection scams | $166.8 million |
| 3 | Romance scams | $139.9 million |
| 4 | Phishing scams | $97.6 million |
| 5 | Remote access scams | $69.9 million |
Five-Year Scam Loss Trend (Australia)
| Year | Total Reported Scam Losses |
|---|---|
| 2021 | $1.8 billion |
| 2022 | $3.1 billion |
| 2023 | $2.7 billion |
| 2024 | $2.0 billion |
| 2025 | $2.18 billion |
Demographic Impact (Scamwatch 2025)
| Demographic | Finding |
|---|---|
| Older Australians (65+) as share of population | 17.1% |
| Older Australians as share of Scamwatch losses | 26.5% |
NASC Disruption Actions (2025)
| Action | 2025 Figure |
|---|---|
| Scam websites assessed by NASC | 8,400+ |
| Scam URLs removed | 7,500+ |
| Scam phone calls blocked by telcos | 492.7 million |
| Scam SMS messages blocked by telcos | 153.5 million |
Government Entity Cyber Security Posture (ASD 2025)
The following figures are drawn from The Commonwealth Cyber Security Posture in 2025, ASD's annual report to Parliament, published November 2025. The report covers 194 Australian Government entities as at 30 June 2025 and is based on the ASD Cyber Security Survey (participation rate: 94%).
Essential Eight Maturity
| Metric | 2025 | 2024 | Change |
|---|---|---|---|
| Entities reaching Essential Eight overall Maturity Level 2 | 22% | 15% | ↑ 7 pp |
Cyber Security Planning & Governance
| Indicator | 2025 | 2024 |
|---|---|---|
| Entities with a cyber security strategy | 82% | 75% |
| Entities with BCP/DR addressing cyber disruptions | 92% | 86% |
| Entities with a funded cyber improvement work plan | 83%† | — |
| Entities with an incident response plan | 90% | 86% |
| †Of the 91% with a planned body of cyber security improvement work, 83% had funded that work. | ||
Training & Reporting
| Indicator | 2025 | 2024 |
|---|---|---|
| Entities providing annual cyber security training | 87% | 78% |
| Entities providing annual privileged user training | 45% | 51% |
| Entities performing supply chain risk assessments | 70% | 74% |
| Entities reporting ≥50% of observed incidents to ASD | 35% | — |
| ASD notifications to gov entities of malicious activity | 223 | — |
References
- Australian Signals Directorate. ASD's ACSC Annual Cyber Threat Report 2024–25. Canberra: Australian Government, 2025.cyber.gov.au
- Australian Signals Directorate. ASD's ACSC Annual Cyber Threat Report 2024–25: Factsheet for Businesses and Organisations. Canberra: Australian Government, 2025.cyber.gov.au
- Australian Signals Directorate. ASD's ACSC Annual Cyber Threat Report 2024–25: Factsheet for Individuals. Canberra: Australian Government, 2025.cyber.gov.au
- Australian Signals Directorate. ASD's ACSC Annual Cyber Threat Report 2024–25: Factsheet for Critical Infrastructure. Canberra: Australian Government, 2025.cyber.gov.au
- Australian Competition and Consumer Commission; National Anti-Scam Centre. Targeting Scams Report 2025. Canberra: ACCC, March 2026.accc.gov.au
- Australian Signals Directorate. The Commonwealth Cyber Security Posture in 2025: Report to Parliament. Canberra: Australian Government, November 2025.cyber.gov.au
This page was last updated in September 2026 based on reports published through March 2026. Statistics will be updated when new reports are published by the relevant government agencies. To report suspected inaccuracies, contact Melbits.
Ready to Simplify Your IT?
Join 200+ Melbourne businesses who've upgraded their IT experience with Melbits. Book a free consultation and get a clear picture of where your technology stands — no jargon, no pressure.