Australians Are Safer Online Than Last Year — Unless They Run a Small Business

A new government survey found cybercrime fell across Australia in 2025, but small business owners are facing more legal and staffing fallout than ever before.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 3 min read
Illustration: a busy Australian high street at dusk, warm amber shopfront lights glowing against a deep blue evening sky
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • 45.1% of Australians surveyed reported being a cybercrime victim in 2025, down from 47.8% in 2024.
  • Fraud and scams rose from 9.7% to 11.1% of respondents in 2025, bucking the overall downward trend.
  • One in four small business owners said cybercrime hurt their business in some way during 2025.
  • Legal consequences for small business owners hit by cybercrime rose from 5.1% in 2024 to 7.9% in 2025.
  • Staffing costs tied to cyber incidents nearly doubled, climbing from 5.9% to 10% among affected small businesses.

Australia had a measurably better year online. That's the headline finding from a survey of 10,593 Australians published this week by the Australian Institute of Criminology, the government body that tracks crime patterns nationally. Overall cybercrime fell. Financial losses stayed modest. For ordinary consumers, the news was largely good.

For small business owners, it wasn't.

Why are small business owners getting hit harder?

Owning a business now carries real legal risk when a cyber incident hits. One in four respondents who owned or managed a small or medium-sized business said cybercrime disrupted their operations in 2025. That much isn't new. What is new is the legal and human cost sitting behind it.

Legal fallout from cyber incidents among small business owners jumped from 5.1% in 2024 to 7.9% in 2025. Staffing costs, money spent replacing or compensating staff after an incident, nearly doubled, rising from 5.9% to 10%. The Australian Institute of Criminology suggested people are losing jobs, or choosing to leave them, because of the pressure these incidents create.

The regulatory backdrop helps explain why. Australia's Cyber Security Act now requires businesses to report a ransomware attack, malicious software that locks a company's files until a payment is made, within 72 hours of discovery. Privacy law reforms have raised potential penalties for mishandling customer data. A 2022 lawsuit against health insurer Medibank signalled that companies can't assume post-incident reviews stay confidential. As Justin Allen, senior manager of security operations at Huntress, told Dark Reading: "That raises the stakes fast. Then you layer on the Cyber Security Act with the 72-hour ransomware reporting rule, plus the Privacy Act reforms and the possibility of much bigger penalties, and suddenly boards need to prove they were not asleep at the wheel." That pressure rolls into compliance work and staff burnout. We covered the threat environment feeding into this in our 26 June story on state actors pre-positioned inside Australian critical infrastructure.

On the consumer side, the picture was brighter. Online harassment fell from 27.1% to 24.6% of respondents. Identity-related crimes dropped from 22.1% to 20.4%. Between 76% and 86.5% of victims reported losing less than AU$1,000, roughly US$690.

These gains came even as Australians took fewer personal precautions. Fewer people ran antivirus software (down from 39.3% to 36.2%), used different passwords across accounts (50.9% to 47.7%), or avoided suspicious links (67.1% to 64.8%). Banks, phone providers and device makers have built more protection into the background, reducing the burden on individuals. It's a real shift, but it has limits.

Fraud and scams rose from 9.7% to 11.1%. Ransomware reports ticked up from 2.5% to 3.1%, a pattern consistent with the resurgence we reported on 3 July. When criminals can't break the technology, they go after the person.

Should you worry?

If you run a small business, the answer is a qualified yes. Review what your staff would do if they received a suspicious payment request or login alert. The legal and employment consequences of getting it wrong are growing faster than the headline numbers suggest.

© 2026 Threat Vectr