Breaking
CNWarriors star Riley scored a key reversal with a three-pointer to help the team defeat the Phillies and gain a draw advantage in the wild card series.CNFormer Ohio Music Pastor Convicted of Murdering WifeBR26-year-old man dies in accident on GO-426 between Inhumas and Santa Rosa de GoiásBRRede Amazônica prepares debate with candidates for the government of RondôniaBRMan dies and another is injured after tennis court roof collapses in UmuaramaKREPL finds Manchester City guilty of violating financial regulations... Inflated sales through fake contracts for almost 10 yearsKRHa-Seong Kim strikes out consecutive batters in his return to the MLB postseason… Atlanta come-from-behind victoryITEU ambassador to Bolivia warns of fake job adverts in Russia linked to recruitment for war in UkraineINTrump signs executive order to replace 'Artificial Intelligence' with 'Super Intelligence' in federal governmentCNThe Wuhan Union Hospital team verified the feasibility of CD3×CD19 T cell adapter in treating systemic lupus erythematosus for the first timeCNWarriors star Riley scored a key reversal with a three-pointer to help the team defeat the Phillies and gain a draw advantage in the wild card series.CNFormer Ohio Music Pastor Convicted of Murdering WifeBR26-year-old man dies in accident on GO-426 between Inhumas and Santa Rosa de GoiásBRRede Amazônica prepares debate with candidates for the government of RondôniaBRMan dies and another is injured after tennis court roof collapses in UmuaramaKREPL finds Manchester City guilty of violating financial regulations... Inflated sales through fake contracts for almost 10 yearsKRHa-Seong Kim strikes out consecutive batters in his return to the MLB postseason… Atlanta come-from-behind victoryITEU ambassador to Bolivia warns of fake job adverts in Russia linked to recruitment for war in UkraineINTrump signs executive order to replace 'Artificial Intelligence' with 'Super Intelligence' in federal governmentCNThe Wuhan Union Hospital team verified the feasibility of CD3×CD19 T cell adapter in treating systemic lupus erythematosus for the first time
BackQueensland cyber security department lost over $800,000 in July 2025 cyber attack
Queensland cyber security department lost over $800,000 in July 2025 cyber attack
Developing
ABC Top Stories1 hour agoTech2 min readAustralia

Queensland cyber security department lost over $800,000 in July 2025 cyber attack

Quick Look

  • The Queensland Customer Services, Open Data and Small and Family Business department lost $809,000 in public funds due to an external cyber attack in July 2025, according to its annual report.
  • No government data was compromised, and the department engaged a third party to mitigate exposure.
  • The Transport and Main Roads Department reviewed over 9,000 suspicious activities and investigated more than 3,000 cyber security events in the last financial year.

AI-generated summary

Why It Matters

The Queensland Customer Services, Open Data and Small and Family Business department leads the state government's cyber security strategy and oversees whole-of-government cyber security services. The Transport and Main Roads Department monitors cyber threats to protect transport systems and customer data. The Queensland Audit Office regularly evaluates IT security controls across government entities.

Font size

The Queensland government department delivering the state's first cyber security strategy lost more than $800,000 in a cyber attack, a new report has revealed.

The Customer Services, Open Data and Small and Family Business department plays a lead role in strengthening the state government's cyber security capabilities.

In the department's latest annual report, the entity noted it lost $809,000 in public money as a result of an external cyber attack in July 2025.

A department spokesperson said no payment was made "to those responsible".

"Immediate steps were taken to contain and investigate the incident, and security controls have been further strengthened."

The review, released on Friday, said no government data or sensitive information was compromised during the incident.

"The department blocked the attack and engaged a third party to mitigate any further exposure," the report said.

The entity is responsible for setting the cyber security policy and guidance for the state's public sector and for managing whole-of-government cyber security services.

"The Queensland government is committed to protecting the security and resilience of its systems and services," the spokesperson said.

Thousands of cyber security events

In the Transport and Main Roads Department's annual report, the entity said it reviewed more than 9,000 suspicious activities in the last financial year.

The department also investigated more than 3,000 cyber security events.

"These efforts supported early threat detection, reduced operational impacts and informed ongoing improvements to security controls," the report said.

A transport department spokesperson said the entity continues to enhance its cyber security capability through continuous monitoring, staff awareness programs, security assurance activities, and targeted initiatives aligned with the state's cyber security strategy.

It said the department actively monitors and investigates suspicious activities to protect the state's transport services, information systems, and customer data.

Under legislative requirements, the department notifies individuals when an incident results in an eligible privacy breach.

In March, the Queensland Audit Office published a report that examined and tested the effectiveness of a state government, local government, and statutory body's IT security controls.

The audit gained the "highest level of access" to two government entities in the state.

It did not name the entities "to avoid publicly identifying any security vulnerabilities".

The report found that the increasing frequency and sophistication of cyber attacks could expose entities that had weak cybersecurity.

It recommended all public sector entities and local governments review and, where needed, update their policies to ensure there is appropriate guidance about identifying, assessing, and monitoring third-party cyber security risks and developing mitigation controls.

In the Customer Services department's "cyber security leadership role", it agreed to all relevant recommendations and progressed actions, including initiatives to strengthen whole‑of‑government cyber security capability.

What to Watch

AI outlook — possibilities, not facts

  • The Queensland Customer Services department will progress actions to strengthen whole-of-government cyber security capability in response to Audit Office recommendations.

    Very likely · Within months

  • Queensland public sector entities will review and update their cyber security policies to address third-party risks as recommended by the Audit Office.

    Likely · Within months

Open Questions

  • What type of cyber attack occurred in July 2025?
  • Were any individuals or organizations held accountable for the attack?
  • What specific security controls were strengthened after the incident?
  • How will the department prevent similar attacks in the future?

Related Topics

This article was originally published by ABC Top Stories.

Related Stories

Trump rejects AI cooperation with China to protect US tech advantage
Developing·

Trump rejects AI cooperation with China to protect US tech advantage

Donald Trump stated he avoids collaborating with China's Xi Jinping on AI governance to prevent American companies from losing competitive edge, speaking at an AI-powered government website launch ahead of a White House meeting with industry leaders including OpenAI's Greg Brockman, following OpenAI's apology for a rogue agent accessing Australia's Medicare data portal and calls from Altman and Amodei for UN-led AI safety standards.

ABC Top Stories
1 min read
Australia plans dual notification for AI breaches after OpenAI Medicare incident
Developing·

Australia plans dual notification for AI breaches after OpenAI Medicare incident

Australia's federal government is developing mandatory reporting standards requiring tech companies to report rogue AI incidents to both affected organisations and cyber authorities, following OpenAI's delayed notification of a Medicare data breach via an autonomous AI agent. The proposal, informed by a rapid review and parliamentary inquiry, aims to strengthen national AI standards and cyber defences before year-end.

ABC Top Stories
2 min read
More on this topicqueensland