It seems like barely a month goes by without another headline announcing that a major organisation has suffered a cyberattack or data breach. Today, news broke that a major Australian energy provider is investigating a security incident that may have exposed customer information. While investigations are still underway, it's yet another reminder that even large, reputable organisations entrusted with our personal information are not immune.
For many people, the first reaction is frustration. The second is often resignation.
"Here we go again."
After breaches involving telecommunications companies, airlines, financial institutions, health providers, retailers and now another major utility, it's only natural to ask:
The uncomfortable truth is that our identity no longer exists in just one place.
Years ago, your personal information might have been stored in a filing cabinet at your bank or in paper records at your doctor's surgery. Today, it exists in hundreds of databases scattered across government agencies, banks, insurers, airlines, energy providers, online retailers, loyalty programs, streaming services, social media platforms and countless other businesses you've interacted with over the years.
Every time we sign up for a new service, we make a small trade. We exchange convenience for personal information.
Sometimes it's only an email address. Other times it's our home address, phone number, date of birth or even copies of our driver's licence and passport. Individually, those decisions seem insignificant. Collectively, they mean our identity is duplicated across organisations we have little visibility or control over.
That doesn't mean companies shouldn't be held accountable. They absolutely should.
If an organisation collects our personal information, it has a responsibility to protect it using every reasonable safeguard available. Customers shouldn't be expected to bear the consequences of poor security practices.
At the same time, we also have to accept another reality.
Even organisations with enormous cybersecurity budgets continue to experience attacks. Cybercriminals are becoming more sophisticated, attacks are increasingly automated, and every connected organisation represents another potential target.
The question is no longer whether companies should improve their security—they must.
The more important question for the rest of us is:
One of the biggest misconceptions is that hackers are only interested in credit card numbers. In reality, your personal information has value long before anyone reaches your bank account.
A name, address, date of birth, email address and phone number can be combined with information stolen from other breaches to impersonate you, bypass identity checks or launch highly convincing phishing attacks. Criminals rarely rely on a single breach. Instead, they build a profile over time, piecing together information from multiple sources until they have enough to exploit.
That's why protecting your digital identity has become just as important as locking your front door or securing your wallet.
The good news is that while we can't eliminate the risk of data breaches, we can significantly reduce the damage they cause by adopting a few simple habits before they're ever needed.
Create a unique, randomly generated password for every website and app you use. A reputable password manager allows you to securely store every password, meaning you only need to remember one strong master password. Because your password manager holds the keys to your digital life, make sure it is also protected with Multi-Factor Authentication (MFA) using an authenticator app or passkey wherever possible.
This is one of the most important habits you can develop. Imagine entering a local raffle, signing up to a community website or buying something from a small online store using the same password as your email or internet banking. If that small organisation suffers a breach, criminals will immediately try those same credentials across hundreds of other services. One compromised account can quickly become many.
Where available, enable MFA using an authenticator app or passkey rather than SMS if possible. Spend a few minutes learning how it works before you actually need it. Even if someone steals your password, they still won't be able to access your account without that second layer of protection.
Your email account is often the master key to your digital life. It's used to reset passwords for banking, shopping, social media and countless other services. If you only secure one account exceptionally well, make it your email.
Check your bank accounts, credit cards, superannuation and investment accounts for transactions or activity you don't recognise. Detecting fraud early can significantly reduce the damage.
If you're notified that an organisation holding your information has experienced a data breach, take it seriously. Read the company's advice carefully, understand what information may have been exposed and act promptly if they recommend changing passwords or taking other protective measures.
After a data breach, scammers often take advantage of the situation by sending convincing emails and text messages pretending to be from the affected organisation, your bank or even a government agency. They may ask you to reset your password, verify your identity or click a link to "secure your account". Always check that the message has come from an official sender before taking any action. If you're unsure, don't click any links. Instead, visit the organisation's official website directly or contact them using the phone number published on their website.
If you're notified that your information has been involved in a data breach, don't wait. Change the password for the affected account immediately—and if you've reused that password elsewhere, change those passwords too. This is one of the biggest reasons never to reuse passwords across multiple services.
If documents such as your driver's licence have been exposed, contact your state's licensing authority as soon as possible. Request a replacement licence and advise that your previous licence details have been compromised in a data breach. This helps ensure the old licence number can no longer be relied upon for future identity verification and reduces the risk of identity fraud.
If you believe someone is actively using your identity, report it to your local police and the relevant government agencies. Keep copies of all reports, as they may assist when dealing with banks, lenders, insurers or government departments if fraudulent activity occurs.
Install security updates for your computer, phone and tablet as soon as they're available. Many updates patch vulnerabilities that cybercriminals actively exploit.
Most people whose information is involved in a data breach never become victims of identity theft. The key is to respond quickly, stay informed and make sensible security decisions. Panic rarely helps—but preparation almost always does.
Unfortunately, I don't think we'll ever reach a point where data breaches disappear completely. As technology evolves, so do the methods used by those trying to exploit it.
That doesn't mean we should accept poor security from organisations entrusted with our personal information. They have a duty to protect it, invest in modern security practices and respond transparently when incidents occur.
But it also means we need to change the way we think about our own identity.
Our personal information has become one of our most valuable assets. Just as we lock our homes, insure our cars and protect our passports, we now need to take the same care with our digital identity.
The reality is that we cannot control whether an organisation experiences a data breach. What we can control is how well prepared we are before it happens and how quickly we respond if it does.