A Senate inquiry into client privacy in the Australian public sector has heard that the agency responsible for making welfare payments to millions of people has been subjected to 89 data breaches in just 2025.
That’s up from the 50 in 2024, and the 10 in 2023.
There have also been over 400 investigations into unauthorised internal access or misuse of data, with 11 considered sufficiently serious to refer to the Commonwealth Director of Public Prosecutions.
“The agency operates in an environment of sustained privacy and security threat, particularly from phishing, impersonation-based scams and third-party data breaches involving government-related identifiers,” Services Australia said in its submission.
Auditor General Caralee McLiesh told the Joint Committee of Public Accounts and Audit on July 28 that its most recent audit of the agency ranked it as only “partly effective” in managing the privacy of client information.
McLiesh said that while the agency had developed contingencies, it still fell short of dealing with the rising volume of cyber attacks.
“The audit recommended that the Australian government review existing data matching activities to assess whether the current frameworks are appropriate for use with contemporary data matching and information sharing practices, and also provide sufficient transparency and accountability,” she said.
Asked by committee deputy chair, Senator Scott Buchholz, why malacious actors would target Services Australia, Chris Birrer, its deputy chief executive, pointed to accessing myGov logins.
This way malicious actors can change bank details of welfare recipients and divert payments into scammer accounts.
“I saw one scheme where somebody was pretending on Facebook to be a Centrelink interest-free car loan scheme, which of course doesn’t exist, and they wanted people to enter that information so that then they could use it to access the records they have with the agency,” he explained.
Too Slow to Report
Ian Goodwin, group executive director with the Australian National Audit Office (ANAO), told the committee that the audit had found that Services Australia had reported notified data breaches to the Office of the Australian Information Commissioner outside the required timeframes.
“We felt coming in externally that there could be more rigour at the agency level in terms of identifying, assessing, and then managing data-related risks and privacy-related risks, and Services Australia has kind of accepted that, and I believe is undertaking some work,” added Nathan Callaway, ANAO executive director.
It was removed from AusTender as an approved supplier on March 19.







