A Queensland government department responsible for leading the state's cybersecurity strategy has disclosed a financial loss of $809,000 following a cyberattack that occurred in July 2025. The incident was revealed in the department's annual report, published on 30 September 2026, raising questions about cybersecurity risks affecting government systems and third-party service providers. ABC News +1

The Department of Customer Services, Open Data and Small and Family Business plays a central role in developing cybersecurity policies, providing guidance and strengthening digital security across Queensland's public sector. Despite its responsibilities in protecting government systems, the department itself was affected by an external attack targeting a third-party telecommunications service.

According to the department's annual report, unauthorised access to a third-party service was used for financial gain. Further information reported by the department indicates that a messaging service used by the Queensland Government was misused to generate an inflated number of unauthorised SMS messages. This resulted in a financial loss of $809,000 to the department.

The department stated that no payment was made directly to the attackers and that no government data or sensitive information was compromised. Officials said the attack was blocked, immediate steps were taken to contain and investigate the incident, and additional security measures were introduced to reduce the risk of further exposure. A third-party organisation was also engaged to help mitigate potential vulnerabilities. ABC News +1

The disclosure has drawn attention to the risks associated with relying on external technology providers for government operations. Telecommunications, messaging and other digital services are often integrated into public-sector systems, making it important for agencies to monitor access, review service arrangements and maintain appropriate safeguards.

The incident also comes amid broader concerns about the growing frequency and sophistication of cyber threats targeting public institutions. Queensland's Transport and Main Roads Department reported reviewing more than 9,000 suspicious activities and investigating more than 3,000 cybersecurity events during the previous financial year, illustrating the ongoing scale of digital security work across government.

A Queensland Audit Office report released in March 2026 also identified areas where government entities needed to improve their management of third-party cybersecurity risks. The audit recommended stronger policies, oversight and monitoring to help agencies identify vulnerabilities and strengthen their protections. The Customer Services department said it had agreed to relevant recommendations and was progressing improvements to its cybersecurity capabilities. ABC News +1

The department has reaffirmed its commitment to protecting Queensland's digital infrastructure and strengthening security controls. While the incident did not result in the reported compromise of sensitive government information, the financial loss demonstrates how misuse of third-party services can still create significant costs for public agencies.

The disclosure provides an example of the importance of cybersecurity monitoring, third-party risk management and rapid incident response as Queensland continues to expand its digital services.