
Nearly Half of Australians Were Hit by Cybercrime in 2025: What It Means for Your Perth Business
If you run a small business in Perth, here's a number worth stopping on: 45.1% of Australian internet users experienced at least one form of cybercrime in 2025.
That's nearly one in two people. And according to the latest Australian Cybercrime Survey, conducted by Roy Morgan on behalf of the Australian Institute of Criminology (AIC), small to medium business owners and managers are specifically named as one of the highest-risk groups.
This isn't abstract. If you have staff, clients, systems, or data, and you do, your business is a target. Here's what the report found, what it means for you, and what you can do about it.
What the Report Actually Says
The AIC surveyed 10,593 Australian computer users and found that while overall cybercrime victimisation has fallen slightly from 47.8% to 45.1%, the problem is far from resolved. In some areas, it's getting worse.
Here are the key findings:
- 45.1% of Australians experienced at least one form of cybercrime in the past 12 months (down from 47.8% in 2024).
- Nearly two-thirds of Australians have experienced cybercrime at some point in their lives.
- More than 20% of respondents were victims of two or more different types of cybercrime in the past year alone.
- Online abuse and harassment remains the most common category, affecting 24.6% of respondents.
- Identity crime and misuse affected 20.4% of respondents.
- Fraud and scams are on the rise, increasing from 9.7% in 2024 to 11.1% in 2025.
- Most incidents were never reported to police or ReportCyber.
The One Trend That Should Concern Every Business Owner
While it's encouraging that overall cybercrime rates have nudged down, there's a clear shift happening beneath that headline number.
Identity theft is declining, largely because banks and financial institutions have invested heavily in security controls in recent years. That's a genuine win.
But fraud and scams are filling the gap. Unlike malwareAny nasty software designed to damage or break into your systems, including viruses and ransomware. or hacking, scams often don't require any technical sophistication to pull off. They target people through email, phone calls, fake invoices, and increasingly convincing impersonations of suppliers, staff, or even the business owner themselves.
For a small business, one successful scam can mean a significant financial loss, damaged client relationships, and hours of clean-up time you simply can't afford.
Why Small Business Owners Are in the Crosshairs
The AIC report specifically identifies SMB owners and managers as a high-risk group. It's not hard to understand why.
Small businesses often operate with limited IT resources. There's no dedicated security team, no enterprise-grade firewallA barrier that filters traffic coming in and out of your network to block threats., and no one whose sole job it is to watch for threats. The owner, you, is wearing five hats at once, and "check whether this email is a phishingFake emails or messages that trick you into giving up passwords or clicking dangerous links by pretending to be someone you trust. attempt" isn't always at the top of the list.
At the same time, small businesses hold valuable data: client records, financial information, and login credentials for cloud tools. Cybercriminals are very interested in these assets. Because SMBs often interact with larger organisations as suppliers or contractors, compromising a small business can become a back door into a much bigger target.
You're not too small to be a target. You're exactly the right size. And that's a problem worth taking seriously.
The Underreporting Problem
One of the most striking findings in the report is that the majority of cybercrime incidents go unreported. Most victims don't contact police or use the government's ReportCyber tool.
There are a few reasons for this. Sometimes people don't realise they've been a victim until well after the fact. Sometimes they feel embarrassed. Sometimes they simply don't know who to report it to, or don't believe anything will come of it.
But underreporting has a real cost. It means the true scale of the problem is likely much larger than the numbers suggest. It also means businesses that experience an incident often suffer in silence, without the support or documentation that could help them recover or prevent the same thing from happening again.
What You Can Do Right Now
The good news is that most common cybercrimes are preventable with the right foundations in place. You don't need an enterprise IT budget. You need the right systems, the right habits, and someone you can call when something looks off.
Here's where to start:
Multi-Factor AuthenticationA second check on top of your password, such as a code on your phone, that stops most account break ins. (MFA)
Enable it on every account that supports it: email, banking, cloud tools, everything. This single step blocks the vast majority of credential-based attacks.
Staff Awareness
Your team is your first line of defence, but they can also be your biggest vulnerabilityA weak spot in software or systems that an attacker could take advantage of.. Regular, short briefings on how to spot phishing emails and suspicious calls make a real difference.
Invoice Verification Process
Scammers are increasingly impersonating suppliers and requesting changes to payment details. A simple phone verification step before updating bank details can save you thousands.
Regular Backups
If ransomwareMalware that locks up your files and demands a payment to unlock them. Good backups are your best defence. hits, a recent backupA spare copy of your data kept somewhere safe so you can recover it if something goes wrong. is the difference between a bad day and a business-ending event. Make sure your backups are tested and stored securely off-site.
Keep Software Updated
Most successful attacks exploit known vulnerabilities in outdated software. Keeping everything patched and up to date closes those doors.
Have a Plan
Know who to call if something goes wrong. Having an IT partner you trust means you're not Googling in a panic at 10 pm when something breaks.
How Consider IT Can Help
At Consider IT, we've been helping Perth small businesses with their IT for years. We're not a faceless corporation. We're a small local team that genuinely cares about the businesses we work with.
We can help you assess where your business currently sits, identify the gaps, and put practical protections in place without the jargon, without the oversell, and without locking you into something you don't need.
Whether you're starting from scratch or want a second opinion on your current setup, we're happy to have a conversation.
Get in Touch
📍 1/45 Buckingham Drive, Wangara WA 6065
📞 08 9200 2230
📧 info@considerit.com.au
🌐 https://considerit.com.au
Source: Australian Cybercrime Survey 2025, Australian Institute of Criminology
https://www.aic.gov.au/publications/sr/sr59
Was this useful?
Enjoyed this article? Join our newsletter for more.
We respect your inbox. Unsubscribe anytime.



