Customer Store Login Customer Service Portal
1300 428 248
andersenIT logo
Who We Are What We Do Who We Support Download the briefing 1300 428 248
OAIC Enforceable Undertaking  ·  Accepted 20 December 2024

A test database. Shared logins. 1.7 million supporter records exposed.

In January 2021 a copy of Oxfam Australia's live supporter data sat in a test database that shared logins could reach. Oxfam learned of the breach when up to 1.7 million records were advertised for sale on a public hacking forum. It was a cybersecurity failure with a privacy outcome, and in December 2024 the Privacy Commissioner accepted a binding enforceable undertaking from the charity. This free 3-page briefing covers what the undertaking now asks of the board, the eight control areas to test, and the questions your board should be asking about your own systems.

What you get in three pages
1
The control failures behind the breach, written for a board paper
2
The four control areas the undertaking covers, plus the board's own duty, each with a board question
3
Eight control areas mapped to the fix for an Australian NFP
Built on the OAIC's enforceable undertaking with Oxfam Australia
5-minute read with a clear action framework
Free 3-page briefing
After Oxfam: A Practical Guide for ACNC Responsible Persons
andersenIT  ·  2026

Get the free briefing

Written for a board paper. No cost and no obligation.

Loading the secure download form...

We will email you the briefing and a short follow-up series on what it means for your charity. Unsubscribe at any time.

1.7M
Supporter records exposed
in the 2021 breach
7 days
Between the intrusion and
Oxfam being alerted
7 yr
Of inactivity before supporter
records must be deleted
12 mths
Until an independent expert
reviews Oxfam's practices
Where it started

A copy of live supporter data was sitting in a test database

Charities copy production data into test environments for the most ordinary reasons: a CRM migration, a database upgrade, a supporter data cleanse, a new fundraising platform. Test, development and migration environments rarely carry production's controls, and a copy of production data inside one is a full copy of the risk. Oxfam's copy sat in a User Acceptance Testing database during a CRM migration. Page 2 of the briefing covers test environments and the board question to ask: does anyone know where every copy of our supporter data sits?

What Happened

A cybersecurity failure with a privacy outcome

In January 2021, during a CRM migration, an unknown IP address reached Oxfam Australia's User Acceptance Testing database, which held a copy of live supporter data. The database could be reached using shared credentials. In late January, up to 1.7 million Oxfam records were advertised for sale on RaidForums. Oxfam was alerted seven days after the intrusion and formally notified the OAIC on 26 February. On 20 December 2024 the Australian Privacy Commissioner accepted a binding enforceable undertaking from Oxfam Australia. The OAIC raised concerns about live supporter data in a UAT database, shared credentials, and how long supporter information was retained. The obligations are written in privacy language. The work of meeting them is cyber security, and responsibility for it sits with the board.

A board reviewing governance obligations together

A board and executive accountability issue.

ACNC Governance Standard 5 requires charities to take reasonable steps to ensure their Responsible People act with reasonable care and diligence. ACNC guidance ties that duty to how a charity manages people's information and data.

Are You Exposed?

This applies to your charity if

The Oxfam undertaking gives charity boards a practical warning: privacy obligations can become binding when basic cyber controls are not evidenced. If your organisation holds donor, beneficiary or staff personal information, the same questions apply to your board.

An ACNC-registered charity above $3M turnover
The Privacy Act generally applies above $3M turnover, with a maximum civil penalty of the greater of $50M, 3x the benefit or 30% of turnover. ACNC Governance Standard 5 requires your Responsible People to act with reasonable care and diligence.
A community services, health, aged care or disability NFP
You hold sensitive client and beneficiary data. Your board should be able to show adequate preparation in writing.
A charity using vendors that handle donor data
Third-party fundraising. Outsourced CRM. Cloud platforms. Any third party handling supporter data extends the charity's own risk, and responsibility stays with the charity and its board.
A charity planning a CRM migration or system change
Test and migration copies of supporter data rarely carry production's controls. Oxfam must now complete a privacy threshold assessment for any project that uses personal information for testing.

ACNC guidance ties Governance Standard 5's duty of care to how a charity manages people's information and data. Responsibility stays with the charity and its board, even when IT or an MSP does the work. Boards should be able to show adequate preparation in writing.

Take these to your next board meeting

Four questions this breach puts to your board

1
What is our retention policy, and who owns it?
2
Is every account that can access personal information named to an individual?
3
Is a privacy threshold assessment part of project intake?
4
Would we know if someone accessed supporter data outside business hours?

The OAIC has shown its hand. Has your board?

Download the briefing
Free Briefing

What is inside

A three-page executive briefing that breaks down the Oxfam undertaking and what it means for every Australian charity holding personal data. Written for boards, Responsible Persons, CEOs, CFOs and IT and risk leaders.

1
The Oxfam breach as a cybersecurity failure: what happened, what the OAIC named, and why meeting it is now a board responsibility
2
What the undertaking now asks of the board: data retention, identity and access, test environments and staff training, plus the board's own duty under ACNC Governance Standard 5, with a board question for each
3
The impacts of non-compliance today, from the $50M Privacy Act penalty ceiling to ACNC deregistration, and where regulatory pressure sits now
4
The technical controls: five from the undertaking and three recommended extensions, each with the gap and the fix for an Australian NFP
5
What andersenIT typically finds when reviewing Australian NFP environments, and the board conversation to have this quarter
From the Briefing
Privacy Act civil penalty ceiling $50M
First civil penalty under the Privacy Act, October 2025 $5.8M
Ransomware payment reporting 72 hrs
Rise in Australian ransomware leak-site victims, 2025 (PwC) 33%
OAIC breach notifications, 2025 1,205
Cost of compliance today << cost of breach

Applies to charities covered by the Privacy Act (generally over $3M turnover). Max penalty: greater of $50M, 3x benefit or 30% of turnover. Ransom reporting applies once paid.

The andersenIT team reviewing systems and controls

25 years of Australian IT, and we work with the NFP sector.

Everything in this briefing comes from what regulators have actually said, and from what we see inside charity IT environments every week.

Upcoming live session

A live session for charity boards

We are running an upcoming live session where Mark Andersen and a senior privacy lawyer take charity boards and executives through the eight control areas, what adequate evidence looks like, and the questions a Responsible Person should be asking. Dates are being confirmed now.

Want first access?

Pre-register for the upcoming webinar when you download the briefing, and we will send you the date and the registration link before it goes public.

Get early access
Free 3-page briefing

Get the briefing, and know where your board stands

Three pages, written for a board paper. It takes five minutes to read and it sets out the questions your board should be able to answer and the controls to test.

OAIC enforceable undertaking, accepted 20 December 2024
5-minute read with a clear action framework
25 years of Australian IT experience across NFP and regulated sectors
Get the free briefing

Takes 30 seconds. Sent straight to your inbox.

andersenIT logo
© 2026 andersenIT  |  1300 428 248  |  andersenit.com.au