Education clients face broader cyber exposure after Perth school breach
Long-retained records create coverage questions as affected populations extend beyond current students and existing client profiles
Education clients face broader cyber exposure after Perth school breach
CYBER
By Roxanne Libatique
17 Sep 2026

A cyberattack on a Perth private school has put the education sector’s risk profile into focus – and given brokers with schools on their books a concrete reason to review existing cyber programmes.

St James Anglican School, in Perth’s north, confirmed this month that hackers gained unauthorised access to its systems and extracted personal data belonging to current and former students dating back to 2015. According to The West Australian, the stolen records include names, addresses, email addresses, phone numbers, bank account details, student medical records, and photographs.

The school acted to contain the breach after discovery. The data had already left its systems.

Read next: Ransomware attack reaches Victorian business through external technology provider

A decade of records, a larger population at risk

“The investigation has identified that personal information relating to members of the school community was involved. The school has notified families and provided them with information about the incident and practical steps they can take to protect their information,” a school spokesman said.

The exposure window matters. Records going back to 2015 means former students – many now adults – are among those affected. A current enrolment count does not reflect the true population exposed when a school’s historical records are compromised.

The school has reported the incident to the Office of the Australian Information Commissioner (OAIC) and other relevant authorities.

“The school is continuing to work closely with its cyber security advisers and will provide further information directly to affected members of our community where appropriate,” the spokesman said.

Regulatory obligations apply to most private schools

Under the Privacy Act 1988, private schools are generally covered regardless of annual turnover when they hold health information or provide a health service. The OAIC’s position is that, in most instances, private schools fall within the Act’s scope – a threshold that encompasses student medical records, school nursing services, and physical education programs.

That means the $3 million small business exemption does not apply in most cases. Where a breach involves student medical records, as occurred at St James Anglican School, Notifiable Data Breach (NDB) scheme notification obligations apply.

Education is a documented breach sector

The OAIC recorded 1,205 data breach notifications across all sectors in 2025 – the highest annual total since mandatory reporting began in 2018, and an 8% rise on the prior year. Education ranked among the top five sectors by notification volume, with 81 reports filed across the year.

Australian Privacy Commissioner Carly Kind said the pattern is worsening. “The threat posed to Australian businesses and organisations by data breaches is substantial and rising year on year, with 2025 recording the highest number of notifications received in a year since the commencement of the NDB scheme,” she said.

The Australian Signals Directorate’s (ASD) Annual Cyber Threat Report 2024-25 placed education and training among the top 10 sectors by incident volume and found the average self-reported cost of cybercrime per business rose 50% to $80,850 per incident in FY2024-25.

The financial tail of a sensitive data breach

Bank account details and medical records – both present in this breach – carry long-tail risk. The Australian government’s Attorney-General’s Department puts the annual cost of identity crime to Australians at approximately $3.1 billion, with identity theft reports rising 13.1% in 2025.

Fraudulent transactions and misuse of medical identities can unfold well after initial notification, extending the claims lifecycle for affected individuals.

For SME-sized organisations, the cost exposure is documented. Emergence Insurance’s Cyber Claims Data Report 2025 found the average cost of a ransomware incident among SMEs in Australia and New Zealand nearly doubled between 2021 and 2024, reaching $207,600. Median claim costs have risen every year since 2021. “SMEs are particularly vulnerable – cyber insurance can be the difference between surviving an attack or going bust,” Emergence CEO Troy Filipcevic said.

Read next: Perth arrests reveal the supply chain blind spot in Australian cyber cover

What brokers should be asking

The Insurance Council of Australia (ICA), in a February 2026 submission to a parliamentary inquiry on cyber insurance, noted that take-up among small businesses remains low, and that smaller organisations are “hit much harder by cyber incidents… with severity of claims increasing and more and more small businesses targeted.”

That creates a practical window. For brokers with a school on their book, the St James Anglican School breach surfaces three questions worth raising now.

Does the policy respond to notification costs across a population that extends well beyond current enrolees? Does cover include identity monitoring services where financial credentials and medical records have been exposed? And does the sum insured reflect the actual volume of data the school holds – accumulated across years of enrolments – rather than just the size of the current student body?

A breach tends to answer those questions at the worst possible time.

Related Stories
Free newsletter

We'll keep you up-to-date with the latest breaking news, cutting edge opinion, and expert analysis affecting both your business and the industry as whole.

Free newsletter

Our daily newsletter is FREE and keeps you up - to - date with the world of Insurance. Please complete the form below and click on subscribe for daily newsletters from IB AU.