From reports to device evidence: four Australian online crime developments this week

Australia's official online crime picture this week is not one story. It is a chain. Reports from the public and technology platforms create leads. Investigators identify and preserve devices. Forensic examination turns those devices into evidence that can be assessed. Courts then decide the matters that reach them.

Four Australian Federal Police releases published from 10 to 15 September 2026 show different points on that chain. Read together, they also show why report counts, charges, forensic findings and convictions must not be treated as interchangeable.

More than 100,000 reports, but not 100,000 proven offences

On 10 September, the AFP-led Australian Centre to Counter Child Exploitation said it had received 100,194 reports of online child sexual exploitation in the 2025-26 financial year. That is an average of 275 reports a day and an increase of roughly 21 per cent from the previous financial year.

The qualification in the AFP release matters. Commander Human Exploitation Joanne Cameron said the increase in reports did not necessarily mean offending had risen at the same rate. Stronger education and awareness can also produce more reporting.

That distinction is essential in cyber security and digital forensics. An incoming report is information to assess, not a finding of fact. It may identify a victim, an account, a platform, a device or a transaction. Investigators still need to test the information, determine whether an offence may have occurred, preserve relevant data and build an evidence trail that can withstand scrutiny.

The same release announced the ninth edition of the ThinkUKnow education program. Its prevention focus covers grooming, sexual extortion, offender tactics and other risks. Prevention and investigation are not competing responses. Better education can reduce harm, improve the quality and speed of disclosures, and help investigators receive information while digital evidence is still available.

Forensic examination can change the status of a device

Two releases later in the week place electronic devices at the centre of active criminal matters.

On 13 September, the AFP said a sixth Victorian man had been charged with offences relating to alleged violent extremist material. According to the release, electronic devices were seized during a search warrant in May. The AFP said a subsequent specialist forensic examination identified alleged ISIS-inspired violent extremist material.

The man was also charged with allegedly contravening a requirement in a court order to provide access to electronic devices. The matters remain before the courts. The allegations have not been determined by a court, and the official release should be read on that basis.

On 14 September, a joint AFP, Queensland Police Service and Australian Border Force release said a mobile phone had been seized for further forensic analysis after border officers allegedly located child abuse material on it. A Townsville man was charged and was expected to appear in Cairns Magistrates Court. That matter also remains an allegation.

These releases illustrate a practical point. A phone or computer is not simply a container to be searched. Its evidential value depends on lawful seizure, preservation, forensic handling, interpretation and a record of what was done. Relevant material may include files, metadata, application records, account identifiers and the relationships between them. The integrity of the process matters alongside the content found.

The two cases are different and should not be collapsed into one conclusion. One concerns alleged extremist material and an alleged failure to comply with a court order. The other concerns alleged child abuse material detected at the border. Their shared relevance is narrower: both show how a physical device can become part of a wider online investigation, and how specialist analysis may sit between seizure and any later court finding.

A court outcome is a different evidential stage

The fourth release shows the distinction between an allegation and an adjudicated result.

On 15 September, the AFP reported that a Canberra man was sentenced in the NSW District Court. The release states that the man had previously pleaded guilty to offences involving possession and transmission of child abuse material. It says the investigation began after Australian Border Force officers examined his baggage at Sydney Airport and located suspected material on his phone, which was referred to the AFP.

The AFP said its investigation identified that the man had posed online as a teenage girl and received and distributed about 50 files between 2022 and 2024. The sentencing outcome can be reported as a court result because the release records a guilty plea and sentence. That is materially different from the charged matters described above.

What organisations should take from the week

These developments are law enforcement matters, but the evidence principles travel further.

First, classification matters. A report, an alert, an allegation, a forensic observation and a court finding each describe a different level of certainty. Using the wrong label can mislead decision-makers and unfairly overstate what the evidence establishes.

Second, preserve before interpreting. When an incident may involve a phone, computer, cloud account or messaging platform, unplanned access can change timestamps, synchronise data or overwrite useful records. Organisations should have an escalation path that allows evidence to be preserved and assessed by appropriately qualified people.

Third, context is part of the evidence. A file viewed in isolation may not explain who created it, who received it, how it moved or whether an account was controlled by a particular person. Reliable conclusions usually depend on multiple artefacts and a documented method, not one screenshot or one search result.

Fourth, prevention improves evidence as well as safety. Clear reporting channels and informed staff, parents and carers can lead to earlier disclosures with better dates, account details and preserved communications. The ACCCE figures should therefore be read as both a measure of investigative demand and a reminder that reporting systems are part of the response.

The broader lesson matches the evidence discipline behind recent Australian cyber alerts: start with the precise official record, keep each claim within what that record supports, and act before volatile evidence disappears.

This article states the position as at 15 September 2026. It is general information, not legal advice, and does not express a view on any matter still before a court.