DarkReading

CDSB Cyberattack Costs Queensland Department $809K


The Queensland government department in charge of the state’s cybersecurity efforts has disclosed a loss of roughly $800,000 from a cyberattack during the last financial year. Details of the CDSB cyberattack, which involved a third-party messaging service being “misused” for financial gain, appear in the QLD cybersecurity department’s latest annual report, released on Friday. 

The Customer Services, Open Data, and Small and Family Business department (CDSB) directs the Queensland government’s cybersecurity strategy, governance, policy and investment. According to its annual report, the department lost $809,000 during the 2025-26 financial year as “a result of an external cyberattack for financial gain.” 

How the CDSB Cyberattack Unfolded?

The report said the breach did not reach sensitive records. No government data or sensitive information was compromised during the incident,” it stated. “The department blocked the attack and engaged a third party to mitigate any further exposure.” 

A CDSB spokesperson told Information Age that the attackers had not been paid. 

“In July 2025, a third-party messaging service used by the Queensland government was misused to generate an inflated number of unauthorised SMS messages for financial gain,” the spokesperson said in a statement. 

“… Immediate steps were taken to contain and investigate the incident, and security controls have been further strengthened.” 

The spokesperson added that the Queensland government “is committed to protecting the security and resilience of its systems and services.” 

Audit Found the QLD Cybersecurity Department ‘Needs to Do More’ 

The incident follows a Queensland Audit Office report, released in March, which found that CDSB “needs to do more” to help the state’s public sector manage third-party cybersecurity risks. 

Auditors found the QLD cybersecurity department was “not actively assessing and monitoring third-party cyber capability across the public sector,” although improvements were in progress. 

“The Queensland government has been slow to develop a framework to help entities manage their third-party cybersecurity risks,” the audit said. It noted that the Australian Signals Directorate (ASD), the federal cybersecurity agency, “has been raising these risks since 2021.” 

During testing, auditors gained the “highest level of access” to two Queensland government entities. They did not name either entity, to “avoid publicly identifying any security vulnerabilities.” 

CDSB addressed the audit in its annual report. “In our cybersecurity leadership role, we agreed to all relevant recommendations and progressed actions during the reporting period, including initiatives to strengthen whole‑of‑government cybersecurity capability,” it said. 

The report described cybersecurity as something that “remains a daily discipline” for CDSB and the wider Queensland government. 

“Investing in, and securing Queensland’s digital assets remains important, as cyber threats become more complex, and national incident data shows that malicious actors continue to target all sectors of the economy,” it added. 

Queensland Tops Cybercrime Reports 

The CDSB cyberattack comes against a broader backdrop of cybercrime in the state. ASD’s latest Annual Cyber Threat Report found that Queensland reported the highest share of Australia’s cybercrime incidents in the 2024-25 financial year. 

Queensland accounted for 28 per cent of national cybercrime reports. Victoria followed with 26 per cent and New South Wales with 22 per cent. ASD found these figures were “disproportionately higher” than the three states’ respective populations when compared with other jurisdictions. 

Average losses were highest elsewhere. “The Australian Capital Territory reported the highest average self-reported financial losses – around $37,700 per cybercrime report – followed by those in New South Wales, with around $33,000,” the report said. 



Source link