What to Do If You've Been Caught in a Data Breach
Key takeaways:
- If your data has been breached, act quickly: change passwords, enable multi-factor authentication, and monitor accounts
- Companies must notify you under the Notifiable Data Breaches (NDB) scheme if your personal information is involved in a breach
- If identification documents were compromised, contact the issuing agencies and consider a credit ban
- The OAIC can investigate serious breaches and has the power to impose penalties of up to $50 million
Your Rights Under Australian Law
Under Australia's Notifiable Data Breaches (NDB) scheme, which has been in effect since February 2018, any organisation covered by the Privacy Act 1988 must notify affected individuals and the Office of the Australian Information Commissioner (OAIC) when a data breach is likely to result in serious harm. This includes breaches involving your personal information such as your name, address, Tax File Number, or financial account details. You have the right to be told what information was exposed and what the organisation is doing about it.
First Steps After a Breach Notification
If you receive a data breach notification, act quickly. First, confirm which information was exposed. If your passwords were compromised, change them immediately — especially for email, banking, and superannuation accounts. Enable multi-factor authentication wherever available. If your Tax File Number, Medicare number, or driver's licence was exposed, contact the relevant agency for guidance. The ATO, Services Australia, and state driver licensing authorities have specific processes for data breach victims.
AdviserCheck puts no paywall on its guides. If you value independent consumer information, a small contribution helps us keep publishing.
Secure payment via Stripe. No account needed.
Monitor Your Financial Accounts
Keep a close eye on your bank accounts, credit cards, and superannuation for any unusual activity. Check your credit report for any unauthorised credit applications. You can request a free copy of your credit report from agencies like Equifax, illion, or Experian. Consider placing a temporary ban on your credit report to prevent fraudulent applications for credit in your name.
Protect Your TFN and Super
If your Tax File Number was exposed, notify the ATO. They can place additional security measures on your tax and super accounts. Check your super fund's contact details are up to date so you receive notifications of any changes. Scammers may attempt to access your super using stolen personal information. Report any suspicious activity to your super fund and the ATO immediately.
What to Check in Your Financial Documents
After a data breach, review your most recent financial statements, SOA, and super statements for any unauthorised changes. If your adviser holds personal information about you, ask them how it is stored and whether it was affected. Under Australian privacy law, you have the right to know what personal information an organisation holds about you and how it is protected.
Immediate Steps After a Data Breach
When you receive a data breach notification from a company, take these steps immediately. First, change your password for the affected account and any other accounts that use the same password. Use a strong, unique password. Second, enable multi-factor authentication (MFA) on all accounts that support it. MFA provides an extra layer of protection even if your password is compromised.
Third, monitor your financial accounts and credit report for unusual activity. Check your bank and credit card statements regularly for unauthorised transactions. Consider placing a credit ban with the major credit reporting agencies if sensitive information (such as your driver's licence or passport number) was exposed.
Your Rights Under the NDB Scheme
The Notifiable Data Breaches (NDB) scheme, administered by the Office of the Australian Information Commissioner (OAIC), requires organisations covered by the Privacy Act to notify affected individuals when a data breach is likely to result in serious harm. The notification must include: a description of the breach, the types of information involved, and recommendations about the steps you should take in response.
If the organisation does not adequately protect your data, you can complain to the OAIC. The OAIC can investigate the breach, require the organisation to take corrective action, and seek civil penalties of up to $50 million for serious or repeated breaches under the strengthened privacy laws effective from December 2022.
Long-Term Protection After a Breach
After a data breach, your personal information may be compromised for years. Scammers often use stolen data long after the initial breach. Maintain enhanced vigilance: use a password manager to generate and store unique passwords, monitor your credit report annually, keep your software and devices updated, and be cautious of unsolicited communications.
Consider using the IDCARE service (Australia's national identity and cyber support service) for free, confidential support. IDCARE can provide a tailored response plan based on the type of data that was exposed. If your Medicare card or passport was compromised, contact Services Australia and the Australian Passport Office respectively.
Frequently Asked Questions
How do I know if my data was in a breach?
The organisation experiencing the breach must notify you if your data was involved and the breach is likely to result in serious harm. You can also check the OAIC's website for major breach notifications.
Can I sue a company for losing my data?
Yes, you may have legal options if a company's negligence led to your data being breached and you suffered loss as a result. This could include financial loss from identity theft or emotional distress. Class actions have been successfully brought against companies following major data breaches in Australia.
What is the difference between a data breach and a cyber attack?
A data breach is the unauthorised access to or disclosure of personal information. A cyber attack is the method used to cause the breach (such as hacking, phishing, or malware). Not all data breaches result from cyber attacks — some are caused by human error or system failures.
AFCA Complaints — What to Know
If you have a dispute with your financial adviser, AFCA provides free independent dispute resolution. In 2023-24, AFCA received 3,559 complaints about investments and advice. The most common issues were inappropriate advice, fees disputes, and poor disclosure. AFCA can award compensation of up to $1 million (with a $5.36 million cap for superannuation complaints). Complaints must be lodged within 6 years of the issue arising.
Where AdviserCheck Fits In
Not every money decision involves an adviser, but when a document recommends borrowing, switching, or investing under pressure, the stakes are real. AdviserCheck reviews any SOA, ROA or CAR for missing disclosures, internal contradictions and unsuitable recommendations, and flags high-pressure language patterns worth questioning. Your file is masked and deleted after analysis. Start a free check.
Check your financial documents for any unusual changes.
Try AdviserCheck FreeLast updated: 2026-09-12. This guide is for informational purposes only and does not constitute financial or legal advice.