Queensland Government Department Loses $809,000 in Cyber Attack
A Queensland government department has lost over $800,000 in a cyber attack, despite taking immediate steps to contain and investigate the incident. The department plays a key role in strengthening the state's cyber security capabilities.
Queensland's Customer Services, Open Data and Small and Family Business department has revealed it lost $809,000 in public money due to an external cyber attack in July 2025. The department plays a key role in strengthening the state government's cyber security capabilities.
A department spokesperson confirmed that no payment was made "to those responsible". "The systems of a third-party telecommunication provider were accessed illegally for financial gain," the spokesperson said in a statement. "Immediate steps were taken to contain and investigate the incident, and security controls have been further strengthened."
The department's annual report noted that no government data or sensitive information was compromised during the incident. "The department blocked the attack and engaged a third party to mitigate any further exposure," the report said.
The entity is responsible for setting cyber security policy and guidance for the state's public sector and managing whole-of-government cyber security services. "The Queensland government is committed to protecting the security and resilience of its systems and services," the spokesperson said.
Thousands of cyber security events
In a separate report, the Transport and Main Roads Department reviewed over 9,000 suspicious activities in the last financial year and investigated more than 3,000 cyber security events. A transport department spokesperson said the entity continues to enhance its cyber security capability through continuous monitoring, staff awareness programs, security assurance activities, and targeted initiatives aligned with the state's cyber security strategy.
"These efforts supported early threat detection, reduced operational impacts and informed ongoing improvements to security controls," the report said. The department actively monitors and investigates suspicious activities to protect the state's transport services, information systems, and customer data.
Under legislative requirements, the department notifies individuals when an incident results in an eligible privacy breach. In March, a report by the Queensland Audit Office examined and tested the effectiveness of a state government, local government, and statutory body's IT security controls.
The audit gained the "highest level of access" to two government entities in the state, but did not name them "to avoid publicly identifying any security vulnerabilities". The report found that the increasing frequency and sophistication of cyber attacks could expose entities with weak cybersecurity and recommended all public sector entities and local governments review and update their policies.
In its "cyber security leadership role", the Customer Services department agreed to all relevant recommendations and progressed actions, including initiatives to strengthen whole‑of‑government cyber security capability.