Queensland's $809,000 vendor breach tests how far cyber cover reaches
A government department's cyber loss exposes a coverage question that turns on the attack mechanism – and whether cyber or crime cover applies
Queensland's $809,000 vendor breach tests how far cyber cover reaches
CYBER
By Roxanne Libatique
30 Sep 2026

A Queensland government department responsible for setting the state’s cyber security policy lost $809,000 in public funds after a third-party telecommunications provider’s systems were accessed illegally – not through a direct breach of the department's own network.

According to ABC News, the Customer Services, Open Data and Small and Family Business (CDSB) department – the agency that leads Queensland's whole-of-government cyber security strategy – disclosed the loss in its latest annual report. The attack occurred in July 2025.

A department spokesperson confirmed no payment was made “to those responsible.”

“The systems of a third-party telecommunication provider were accessed illegally for financial gain. Immediate steps were taken to contain and investigate the incident, and security controls have been further strengthened,” the spokesperson said.

The department engaged an external party to contain any further exposure. No government data or sensitive information was compromised.

As a Queensland Government department, CDSB is covered by the Queensland Government Insurance Fund (QGIF), the state’s self-insurance scheme, rather than a commercial cyber policy. The lessons drawn from this incident apply to how commercial cyber and crime policies would respond to a comparable loss in the private sector.

Read next: Cyber policies weren’t written for a world of stolen AI keys

What the loss mechanism suggests and what it does not confirm

The department’s description – a third-party provider’s systems accessed illegally “for financial gain,” with no payment made to those responsible – is consistent with payment diversion or funds transfer fraud, rather than a traditional data breach or ransomware event. The full mechanism has not been publicly disclosed.

That distinction matters for brokers, because the relevant coverage question may not be how a cyber policy defines a “computer system” at all. It may be whether the loss falls under crime cover or a social engineering extension – both of which carry their own sublimits, conditions, and exclusions that differ markedly across the market.

Coalition’s 2025 Cyber Claims Report found that business email compromise and funds transfer fraud (FTF) together accounted for 60% of global cyber insurance claims in 2024, with an average funds transfer fraud loss of $290,000 globally. The Queensland loss of $809,000 sits well above that benchmark.

Both covers – cyber and crime – may be relevant depending on the policy structure and the precise mechanism of the loss. Brokers should not assume one responds to the exclusion of the other.

What the audit confirmed – after the fact

In March 2026 – eight months after the loss occurred – the Queensland Audit Office tabled a report examining how effectively public sector entities manage third-party cyber security risks.

The audit, Managing third-party cyber security risks (Report 13: 2025-26), specifically assessed CDSB in its leadership role across Queensland’s public sector. The office audited three entities and gained the highest level of access to two of them.

The findings confirmed the kind of weakness the Queensland incident exposed. Each entity had implemented some security controls, but auditors were still able to obtain passwords, access systems, and extract sensitive information beyond the intended scope of a third-party user.

The report also found that only two of 36 contracts reviewed required third parties to report cyber security incidents and vulnerabilities – a structural gap in visibility across the supply chain.

The audit recommended all public sector entities and local governments review and update their policies to identify, assess, and monitor third-party cyber security risks. CDSB agreed to all relevant recommendations.

The audit did not prevent the loss. It documented, after the fact, that the conditions for it existed broadly across Queensland's public sector.

The national cost trajectory

The Queensland incident sits within a documented pattern of rising vendor-related cyber losses across Australia.

MinterEllison’s 2026 Perspectives on Cyber Risk report found that 57% of Australian organisations that experienced a cyber incident were hit through a supplier or vendor.

The Australian Signals Directorate (ASD) Annual Cyber Threat Report 2024-25 identifies the IT supply chain as a structural vulnerability, noting that malicious cyber actors exploit trusted relationships between vendors and customers to steal information or deliver malware. The ASD’s Australian Cyber Security Centre received more than 42,500 calls to the Australian Cyber Security Hotline in FY2024-25, up 16%, and responded to more than 1,200 cyber security incidents, up 11%.

The ASD report found the average self-reported cost of cybercrime to large Australian businesses reached $202,700 per report in FY2024-25, a 219% year-on-year increase. Medium businesses averaged $97,200, up 55%.

Read next: When an AI does the hacking, does your client’s cyber policy respond?

Three questions for renewal

For brokers with clients relying on outsourced or shared technology platforms, the Queensland incident raises questions that go beyond which policy section responds.

Does the client hold both cyber and crime cover, and has the broker confirmed how each policy responds to a loss originating in a vendor's systems? Where a cyber policy’s definition of “computer system” does not extend to third-party infrastructure, and where crime cover carries a sublimit or social engineering condition, a gap between the two may be where the loss falls.

Does the policy contain systemic risk or widespread-event clauses that could limit coverage where the same attack vector affects multiple policyholders simultaneously? Vendor compromises can cascade across many client organisations, and aggregate limitations may apply.

Are coverage limits calibrated to reflect actual loss exposure? The ASD’s benchmarks – $97,200 for medium businesses and $202,700 for large businesses per incident – provide a floor, not a ceiling. The Queensland loss of $809,000 exceeds both before any remediation costs are counted.

“The Queensland government is committed to protecting the security and resilience of its systems and services,” the department spokesperson said.

That commitment does not resolve the coverage question for commercial clients – and neither will a policy that has not been reviewed against the specific mechanics of a vendor-originated loss.

Related Stories
Free newsletter

We'll keep you up-to-date with the latest breaking news, cutting edge opinion, and expert analysis affecting both your business and the industry as whole.

Free newsletter

Our daily newsletter is FREE and keeps you up - to - date with the world of Insurance. Please complete the form below and click on subscribe for daily newsletters from IB AU.