A government cyber loss – and the policy question it leaves unanswered
How policies define a computer system now determines whether vendor-originated financial losses fall inside or outside cover
A government cyber loss – and the policy question it leaves unanswered
CYBER
By Roxanne Libatique
30 Sep 2026

A Queensland government department responsible for setting the state’s own cyber security policy lost $809,000 in public funds after a third-party telecommunications provider’s systems were accessed illegally – not through a direct breach of its own network.

That distinction is the most consequential detail in this story for brokers placing cyber cover on behalf of any organisation that relies on shared or outsourced platforms.

According to ABC News, the Customer Services, Open Data and Small and Family Business (CDSB) department – the agency that leads Queensland’s whole-of-government cyber security strategy – disclosed the loss in its latest annual report. The attack occurred in July 2025.

A department spokesperson confirmed no payment was made “to those responsible.”

“The systems of a third-party telecommunication provider were accessed illegally for financial gain. Immediate steps were taken to contain and investigate the incident, and security controls have been further strengthened,” the spokesperson said.

The department engaged an external party to contain any further exposure. No government data or sensitive information was compromised.

Read next: Cyber policies weren’t written for a world of stolen AI keys

The audit had already flagged the gap

The timing is notable. In March 2026 – just months before the loss was disclosed – the Queensland Audit Office tabled a report examining how effectively public sector entities manage third-party cyber security risks.

The audit, Managing third-party cyber security risks (Report 13: 2025-26), specifically included the Customer Services department as one of the central agencies assessed for its leadership role. The office audited three public sector entities – a state government department, a statutory body, and a local government – and gained the highest level of access to two of them.

The findings were direct: each entity had implemented some security controls, but auditors were still able to obtain passwords, access systems, and extract sensitive information beyond the intended scope of a third-party user.

The report also found that only two of 36 contracts reviewed required third parties to report cyber security incidents and vulnerabilities. The audit recommended all public sector entities and local governments review and update their policies to ensure appropriate guidance exists for identifying, assessing, and monitoring third-party cyber security risks.

The Customer Services department agreed to all relevant recommendations.

The coverage question this creates

The mechanism of this loss – a vendor’s systems exploited, financial damage flowing to the client entity – sits directly in contested territory within Australian cyber policy language.

MinterEllison’s 2026 Perspectives on Cyber Risk report found that 57% of Australian organisations that experienced a cyber incident were hit through a supplier or vendor. That figure, drawn from a survey of senior leaders, reflects how common vendor-originated losses have become.

Whether those losses are covered depends on wording that varies considerably across the market. Some policies expressly include third-party networks within the definition of the insured’s computer system. Others do not, and coverage gaps emerge where policy language does not clearly extend to outsourced or off-premises infrastructure.

For a loss structured like the Queensland one – where no internal system was directly breached – that distinction is not peripheral. It is the central coverage question.

The national cost trajectory

The Queensland incident is not isolated in scale or in kind.

The Australian Signals Directorate (ASD) Annual Cyber Threat Report 2024-25 identifies the IT supply chain as a structural vulnerability, noting that malicious cyber actors exploit trusted relationships between vendors and customers to steal information or deliver malware. The ASD’s Australian Cyber Security Centre (ACSC) received more than 42,500 calls to the Australian Cyber Security Hotline in FY2024-25 – a 16% increase – and responded to more than 1,200 cyber security incidents, up 11%.

Financial losses are also rising. The ASD report found the average self-reported cost of cybercrime to large Australian businesses reached $202,700 per report in FY2024-25, a 219% year-on-year increase. Medium businesses averaged $97,200, up 55%. The $809,000 Queensland loss sits well above both.

Separately, the Transport and Main Roads Department’s annual report revealed the agency reviewed more than 9,000 suspicious activities in the last financial year and investigated more than 3,000 cyber security events – a further indicator of the volume of threat activity across Queensland’s public sector alone.

Read next: When an AI does the hacking, does your client’s cyber policy respond?

Three questions for renewal

For brokers with public sector clients – or any client relying on outsourced technology platforms – the Queensland incident raises three specific points worth raising at the next renewal.

Does the policy respond to losses that originate in a vendor’s systems rather than the client’s own? Where the definition of “computer system” does not expressly include third-party networks, a loss structured like this may not be covered.

Does the policy contain systemic risk or widespread-event clauses that could limit or exclude coverage where the same attack affects multiple policyholders? Vendor compromises can cascade across many client organisations simultaneously, and aggregate limitations may apply.

Are coverage limits sized to actual loss exposure? The ASD benchmarks – $97,200 for medium businesses and $202,700 for large businesses per incident, before remediation – provide a starting reference. At $809,000, the Queensland loss exceeds both before any remediation or third-party engagement costs are counted.

“The Queensland government is committed to protecting the security and resilience of its systems and services,” the department spokesperson said.

That commitment does not settle the insurance question – and a policy that has not been reviewed against vendor-originated loss scenarios may not either.

Related Stories
Free newsletter

We'll keep you up-to-date with the latest breaking news, cutting edge opinion, and expert analysis affecting both your business and the industry as whole.

Free newsletter

Our daily newsletter is FREE and keeps you up - to - date with the world of Insurance. Please complete the form below and click on subscribe for daily newsletters from IB AU.