Skip to content

All articles

2 August 2026·David Libby

45% of Australians experienced cybercrime in 2025. Small business owners are one of the highest-risk groups.

The Australian Institute of Criminology has released its latest Cybercrime Survey, and the findings are a wake-up call for anyone running a business.

Cybersecuritycyber crimesmall businessmid-sized business
45% of Australians experienced cybercrime in 2025. Small business owners are one of the highest-risk groups.

Nearly Half of Australians Were Hit by Cybercrime in 2025: What It Means for Your Perth Business

If you run a small business in Perth, here's a number worth stopping on: 45.1% of Australian internet users experienced at least one form of cybercrime in 2025.

That's nearly one in two people. And according to the latest Australian Cybercrime Survey, conducted by Roy Morgan on behalf of the Australian Institute of Criminology (AIC), small to medium business owners and managers are specifically named as one of the highest-risk groups.

This isn't abstract. If you have staff, clients, systems, or data, and you do, your business is a target. Here's what the report found, what it means for you, and what you can do about it.

What the Report Actually Says

The AIC surveyed 10,593 Australian computer users and found that while overall cybercrime victimisation has fallen slightly from 47.8% to 45.1%, the problem is far from resolved. In some areas, it's getting worse.

Here are the key findings:

  • 45.1% of Australians experienced at least one form of cybercrime in the past 12 months (down from 47.8% in 2024).
  • Nearly two-thirds of Australians have experienced cybercrime at some point in their lives.
  • More than 20% of respondents were victims of two or more different types of cybercrime in the past year alone.
  • Online abuse and harassment remains the most common category, affecting 24.6% of respondents.
  • Identity crime and misuse affected 20.4% of respondents.
  • Fraud and scams are on the rise, increasing from 9.7% in 2024 to 11.1% in 2025.
  • Most incidents were never reported to police or ReportCyber.

The One Trend That Should Concern Every Business Owner

While it's encouraging that overall cybercrime rates have nudged down, there's a clear shift happening beneath that headline number.

Identity theft is declining, largely because banks and financial institutions have invested heavily in security controls in recent years. That's a genuine win.

But fraud and scams are filling the gap. Unlike malware or hacking, scams often don't require any technical sophistication to pull off. They target people through email, phone calls, fake invoices, and increasingly convincing impersonations of suppliers, staff, or even the business owner themselves.

For a small business, one successful scam can mean a significant financial loss, damaged client relationships, and hours of clean-up time you simply can't afford.

Why Small Business Owners Are in the Crosshairs

The AIC report specifically identifies SMB owners and managers as a high-risk group. It's not hard to understand why.

Small businesses often operate with limited IT resources. There's no dedicated security team, no enterprise-grade firewall, and no one whose sole job it is to watch for threats. The owner, you, is wearing five hats at once, and "check whether this email is a phishing attempt" isn't always at the top of the list.

At the same time, small businesses hold valuable data: client records, financial information, and login credentials for cloud tools. Cybercriminals are very interested in these assets. Because SMBs often interact with larger organisations as suppliers or contractors, compromising a small business can become a back door into a much bigger target.

You're not too small to be a target. You're exactly the right size. And that's a problem worth taking seriously.

The Underreporting Problem

One of the most striking findings in the report is that the majority of cybercrime incidents go unreported. Most victims don't contact police or use the government's ReportCyber tool.

There are a few reasons for this. Sometimes people don't realise they've been a victim until well after the fact. Sometimes they feel embarrassed. Sometimes they simply don't know who to report it to, or don't believe anything will come of it.

But underreporting has a real cost. It means the true scale of the problem is likely much larger than the numbers suggest. It also means businesses that experience an incident often suffer in silence, without the support or documentation that could help them recover or prevent the same thing from happening again.

What You Can Do Right Now

The good news is that most common cybercrimes are preventable with the right foundations in place. You don't need an enterprise IT budget. You need the right systems, the right habits, and someone you can call when something looks off.

Here's where to start:

Multi-Factor Authentication (MFA)

Enable it on every account that supports it: email, banking, cloud tools, everything. This single step blocks the vast majority of credential-based attacks.

Staff Awareness

Your team is your first line of defence, but they can also be your biggest vulnerability. Regular, short briefings on how to spot phishing emails and suspicious calls make a real difference.

Invoice Verification Process

Scammers are increasingly impersonating suppliers and requesting changes to payment details. A simple phone verification step before updating bank details can save you thousands.

Regular Backups

If ransomware hits, a recent backup is the difference between a bad day and a business-ending event. Make sure your backups are tested and stored securely off-site.

Keep Software Updated

Most successful attacks exploit known vulnerabilities in outdated software. Keeping everything patched and up to date closes those doors.

Have a Plan

Know who to call if something goes wrong. Having an IT partner you trust means you're not Googling in a panic at 10 pm when something breaks.

How Consider IT Can Help

At Consider IT, we've been helping Perth small businesses with their IT for years. We're not a faceless corporation. We're a small local team that genuinely cares about the businesses we work with.

We can help you assess where your business currently sits, identify the gaps, and put practical protections in place without the jargon, without the oversell, and without locking you into something you don't need.

Whether you're starting from scratch or want a second opinion on your current setup, we're happy to have a conversation.

Get in Touch

📍 1/45 Buckingham Drive, Wangara WA 6065

📞 08 9200 2230

📧 info@considerit.com.au

🌐 https://considerit.com.au

Source: Australian Cybercrime Survey 2025, Australian Institute of Criminology
https://www.aic.gov.au/publications/sr/sr59

Was this useful?

08 9200 2230Get in touch