Cybercrime Law in Australia
Australia addresses computer crime at the Commonwealth level through its Criminal Code, supplemented by state and territory laws and, since 2024, by a dedicated cyber security statute.
Key laws
- Criminal Code Act 1995 (Cth), Part 10.7 — Computer offences. Division 477 contains the serious computer offences: unauthorised access, modification or impairment with intent to commit a serious offence (s 477.1), unauthorised modification of data to cause impairment (s 477.2), and unauthorised impairment of electronic communication (s 477.3). Division 478 covers the other computer offences, including unauthorised access to or modification of restricted data (s 478.1) and possessing, producing or supplying data with intent to commit a computer offence (ss 478.3–478.4). Division 476 supplies the definitions, including the meaning of “unauthorised access, modification or impairment”.
- Cybercrime Act 2001 (Cth) (No. 161, 2001) — the amending Act that inserted Part 10.7 into the Criminal Code and modernised investigative powers. It is a historical amending Act; the operative offences are read out of the Criminal Code, not out of this Act.
- Criminal Code, ss 474.17C and 474.17D — the “doxxing” offences: using a carriage service to make available, publish or otherwise distribute the personal data of an individual, or of members of certain groups. Inserted by the Privacy and Other Legislation Amendment Act 2024.
- Privacy Act 1988 (Cth) — privacy obligations for covered entities, including the Notifiable Data Breaches scheme. Amended by the Privacy and Other Legislation Amendment Act 2024, which among other things created a statutory tort for serious invasions of privacy.
- Cyber Security Act 2024 (Cth) (No. 98, 2024) — mandatory ransomware and cyber-extortion payment reporting for certain entities, security standards for connectable (“smart”) products, and a Cyber Incident Review Board.
- Security of Critical Infrastructure Act 2018 (Cth) — risk-management, reporting and government-assistance obligations for critical infrastructure assets.
Enforcement
The Australian Federal Police (AFP) investigates Commonwealth cybercrime. The Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) leads national cyber defence and receives incident reports. The Office of the Australian Information Commissioner (OAIC) regulates the Privacy Act and the Notifiable Data Breaches scheme.
Plain-language overview, not legal advice. Laws change — read the primary sources linked above and seek qualified advice for any specific situation.
Sources verified 9 August 2026 against the Federal Register of Legislation.