Regional Queensland Cyber Security Incident Tracker

Regional Queensland Cyber Security Incident Tracker

This tracker brings together the public reporting behind North Queensland Cyber Watch. I'm Nicholas O'Sullivan, a Townsville IT professional. The purpose is to make the sources, regional connections and gaps in the evidence easier to find.

Collection assembled 9 October 2026. Each entry shows the date of the account it summarises. These are historical evidence snapshots, not a claim that every investigation has been checked again today. A later company statement may change the picture.

How to read the tracker · Download the collection as CSV · Regional guides and resources

Cyber Watch source index: 8 entries. Scroll horizontally on smaller screens.
Date and basisOrganisationLocation and scopeIndustryIncident typeEvidence statusSourceArticle
17 August 2026
Claim date reported in the article
Westco Motors CairnsCairns
Regional organisation
AutomotiveRansomware and data theft allegationClaimed
Threat actor claim and samples described by Cyber Daily; no company confirmation identified in the August article.
Account dated 24 August 2026
Cyber Daily, 24 August 2026Read the westco motors account
August 2026
Disclosure month; exact intrusion date not established here
Oz Hair & BeautyNational platform; Townsville retail connection
National platform with regional relevance
RetailUnauthorised access to customer order dataConfirmed
Company statement confirms access to limited customer information; a regional victim count and the larger dataset claims are not established.
Account dated 21 August 2026
Company incident statementRead the oz hair beauty account
13 August 2026
ASX announcement date
Nick ScaliNational systems; Townsville, Cairns and Mackay retail connection
National platform with regional relevance
RetailSecurity incident and systems taken offlineConfirmed incident; data theft unconfirmed in cited notice
ASX notice confirms the incident and disruption, but says the company had no evidence of unauthorised customer-data access at that time.
Account dated 14 August 2026
ASX announcement, 13 August 2026Read the nick scali account
28–30 June 2026
Incident window in the College notice reproduced in the article
Townsville Christian CollegeTownsville
Regional organisation
EducationRansomware; unauthorised network access and encryptionConfirmed
College notice describes the attack. Potential exposure of information does not establish that every record was stolen.
Account dated 2 August 2026
College notice, retained imageRead the townsville christian college account
June 2026
Incident month covered in the article
Mackay SugarMackay region
Regional organisation
Sugar and agricultureCyber incident affecting operations; ransomware reportedConfirmed incident; ransomware attribution reported
Company notice confirms an incident and response. Ransomware attribution and detailed mill and grower impacts come from secondary reporting.
Account dated 19 June 2026
Mackay Sugar incident noticeRead the mackay sugar account
June 2026
Notification month; forwarding predates disclosure
Townsville Catholic EducationTownsville / North Queensland
Regional organisation
EducationCorporate email forwarded to personal accountsConfirmed
Organisation published an eligible data breach notification. This was a disclosure risk from forwarding, not a confirmed malicious intrusion.
Account dated 3 July 2026
TCE eligible data breach notificationRead the townsville catholic education account
6 June 2026
Townsville Bulletin publication date
Strand Fitness North Shore members / third-party-held informationBurdell, Townsville
Regional connection; third-party data
FitnessPersonal information breach involving a third partyReported; police and business statements quoted
The Bulletin quotes police and the gym confirming an incident. Detailed exposure claims remain dependent on that reporting; the gym is not accused of wrongdoing.
Account dated 30 August 2026
Townsville Bulletin, 6 June 2026 (subscription)Read the burdell gym account
May 2026
Disclosure month covered in the article
Instructure Canvas / regional education usersGlobal platform; Townsville and Queensland school connections
Global platform with regional relevance
Education technologyLearning platform breach and extortion claimsBreach reported; institution list unverified
Local reporting describes government and school responses. The threat actor list is not proof that every named institution or record was affected.
Account dated 13 May 2026
Townsville Bulletin (subscription)Read the canvas account

How to read the tracker

Confirmed means the organisation's notice confirms the described incident, within the limits stated. Reported identifies attributed journalism, including statements quoted by a publication. Claimed identifies an allegation, including a threat actor's claim, that the cited account has not established as a confirmed breach. An incident can be confirmed while its cause, attribution or alleged data theft remains unconfirmed.

The date column identifies whether it is an incident window, disclosure date or report date. It does not silently substitute an article's publication date for the day an attack happened. Month-only dates mean this collection does not establish a more precise date.

One row represents an incident covered by this series, not one victim, one city or one successful attack. National and global platform incidents are labelled separately from incidents at regional organisations. A retailer having a regional store does not establish how many local customers were affected. Repeated reporting about the same incident belongs in the existing row.

The initial collection covers Townsville, Cairns and Mackay connections. It has no dedicated incident entry yet for Rockhampton, Mount Isa or the Whitsundays. Missing entries reflect the limits of this collection, not evidence that those places have had no incidents. It cannot support a city risk ranking, a trend in attack frequency or an estimate of total regional losses.

Sources, updates and corrections

The table links to company notices where the articles provide them and to attributed reporting otherwise. Some reporting requires a subscription; the College notice is a retained image already reproduced in its article. The linked articles carry fuller context. No stolen datasets or criminal leak sites are linked here.

For a correction or a new public source, contact me with the entry, the source and what it changes. Please do not send personal records or stolen material. Updates should retain the distinction between the original account and later findings.

When citing an entry, link to its organisation row using the permanent fragment, for example Mackay Sugar, and include the account date and your access date. Cite the original source for the underlying incident facts. This index is compiled by Nicholas O'Sullivan; see the editorial disclaimer for disclosure and reuse information.

Read the Townsville, Cairns, Mackay and Rockhampton guides for regional context.