
A new AIC survey shows individual Australians are safer online than a year ago, even as they’ve grown less careful. Small and medium businesses aren’t so lucky.
Source: Australian Institute of Criminology, Cybercrime in Australia 2025 (Statistical Report No. 59) · Survey of 10,593 Australians
The headline from the Australian Institute of Criminology’s newest survey sounds like good news: cybercrime against individual Australians dropped in 2025, and the financial damage when it did happen stayed low. Dig one layer deeper, though, and the picture splits in two. Ordinary Australians are doing better. Small and medium business owners are doing worse — and the numbers explain why that split matters.
The Good News for Individuals
Nearly half of the 10,593 people surveyed — 45.5% — reported being a victim of some form of cybercrime in the past 12 months. That’s still a lot of people, but most categories moved in the right direction compared with 2024:
| Cybercrime type | 2024 | 2025 |
|---|---|---|
| Online abuse & harassment | 27.1% | 24.6% |
| Identity crime & misuse | 22.1% | 20.4% |
| Financial account compromise | 17.7% | 15.8% |
| Unsolicited sexual material | 7.6% | 6.3% |
| Impersonation | 7.8% | 6.9% |
| Fraud & scams | 9.7% | 11.1% (up) |
Financial losses stayed modest too: depending on the type of crime, 76% to 86.5% of victims lost less than AU$1,000 (roughly US$690), and only a small fraction lost more than AU$10,000.
The One Category Moving the Wrong Way: Scams
Fraud and scams were the exception to the downward trend, rising from 9.7% to 11.1% of respondents. The AIC points to the nature of the scams driving this: consumer and seller scams made up 37.7% of all fraud cases reported, reflecting how “low value, high volume” online purchases give scammers constant opportunities to exploit urgency and anonymity, one transaction at a time.
The Odd Part: People Got Less Careful
Here’s what makes the overall drop genuinely surprising — it happened despite Australians practicing worse cyber hygiene than the year before.
39.3% → 36.2%Used antivirus/firewall
20.5% → 17.8%Used spam filtering
50.9% → 47.7%Used unique passwords
67.1% → 64.8%Avoided suspicious links
Why didn’t laxer habits lead to more victims? Industry voices quoted in coverage of the report point to one likely explanation: protection has shifted “upstream.” Banks, telcos, browser makers, and platforms are increasingly catching threats in the background — before they ever reach the end user — making individual vigilance somewhat less decisive than it used to be.
Where the Pain Moved: Small & Medium Businesses
This is the part of the report that doesn’t fit the “things are getting better” narrative. One in four SMB owners or operators said cybercrime negatively affected their business in 2025. The most common consequence was disruption to everyday operations (28.7%) — but two other numbers stand out for moving sharply upward:
5.1% → 7.9%SMBs reporting legal issues from cybercrime
5.9% → 10%SMBs reporting staffing costs/fallout
Both figures roughly doubled or came close to it. The AIC suggests people have been quitting or losing jobs as a direct result of these incidents, and businesses are facing legal and regulatory consequences at rates higher than in any previous year of the survey.
Security researchers point to a specific mechanism behind the rising legal exposure: courts are increasingly unwilling to let companies treat post-breach reviews as private. Australia’s 2022 Federal Court case against health insurer Medibank is cited as a precedent — a signal that internal cyber incident reviews can no longer be assumed to stay confidential, raising the legal stakes of every breach that follows.
What This Split Actually Means
Put together, the report tells a fairly clear story: individual protection is increasingly handled for people, by the platforms and institutions they use every day, regardless of how careful they personally are. Businesses don’t have that same safety net — when something goes wrong, the business itself absorbs the operational disruption, the legal exposure, and now, increasingly, the staffing fallout.
In other words, the risk hasn’t disappeared. It’s been redistributed — away from individuals and onto the organizations responsible for protecting them.
Bottom Line
Fewer Australians are being victimized, and when they are, most walk away with limited financial damage — a genuinely encouraging trend, even if it’s driven more by institutional defenses than personal caution. But for the small and medium businesses that keep the economy running, 2025 was measurably harder: more legal exposure, more staffing disruption, and a growing sense that a single cyber incident can now follow a business well past the day it happened.Analysis based on AIC Statistical Report No. 59, “Cybercrime in Australia 2025,” and related industry commentary · July 2026