Regional Queensland Cyber Security Incident Tracker
This tracker brings together the public reporting behind North Queensland Cyber Watch. I'm Nicholas O'Sullivan, a Townsville IT professional. The purpose is to make the sources, regional connections and gaps in the evidence easier to find.
Collection assembled 9 October 2026. Each entry shows the date of the account it summarises. These are historical evidence snapshots, not a claim that every investigation has been checked again today. A later company statement may change the picture.
How to read the tracker · Download the collection as CSV · Regional guides and resources
| Date and basis | Organisation | Location and scope | Industry | Incident type | Evidence status | Source | Article |
|---|---|---|---|---|---|---|---|
| 17 August 2026 Claim date reported in the article | Westco Motors Cairns | Cairns Regional organisation | Automotive | Ransomware and data theft allegation | Claimed Threat actor claim and samples described by Cyber Daily; no company confirmation identified in the August article. Account dated 24 August 2026 | Cyber Daily, 24 August 2026 | Read the westco motors account |
| August 2026 Disclosure month; exact intrusion date not established here | Oz Hair & Beauty | National platform; Townsville retail connection National platform with regional relevance | Retail | Unauthorised access to customer order data | Confirmed Company statement confirms access to limited customer information; a regional victim count and the larger dataset claims are not established. Account dated 21 August 2026 | Company incident statement | Read the oz hair beauty account |
| 13 August 2026 ASX announcement date | Nick Scali | National systems; Townsville, Cairns and Mackay retail connection National platform with regional relevance | Retail | Security incident and systems taken offline | Confirmed incident; data theft unconfirmed in cited notice ASX notice confirms the incident and disruption, but says the company had no evidence of unauthorised customer-data access at that time. Account dated 14 August 2026 | ASX announcement, 13 August 2026 | Read the nick scali account |
| 28–30 June 2026 Incident window in the College notice reproduced in the article | Townsville Christian College | Townsville Regional organisation | Education | Ransomware; unauthorised network access and encryption | Confirmed College notice describes the attack. Potential exposure of information does not establish that every record was stolen. Account dated 2 August 2026 | College notice, retained image | Read the townsville christian college account |
| June 2026 Incident month covered in the article | Mackay Sugar | Mackay region Regional organisation | Sugar and agriculture | Cyber incident affecting operations; ransomware reported | Confirmed incident; ransomware attribution reported Company notice confirms an incident and response. Ransomware attribution and detailed mill and grower impacts come from secondary reporting. Account dated 19 June 2026 | Mackay Sugar incident notice | Read the mackay sugar account |
| June 2026 Notification month; forwarding predates disclosure | Townsville Catholic Education | Townsville / North Queensland Regional organisation | Education | Corporate email forwarded to personal accounts | Confirmed Organisation published an eligible data breach notification. This was a disclosure risk from forwarding, not a confirmed malicious intrusion. Account dated 3 July 2026 | TCE eligible data breach notification | Read the townsville catholic education account |
| 6 June 2026 Townsville Bulletin publication date | Strand Fitness North Shore members / third-party-held information | Burdell, Townsville Regional connection; third-party data | Fitness | Personal information breach involving a third party | Reported; police and business statements quoted The Bulletin quotes police and the gym confirming an incident. Detailed exposure claims remain dependent on that reporting; the gym is not accused of wrongdoing. Account dated 30 August 2026 | Townsville Bulletin, 6 June 2026 (subscription) | Read the burdell gym account |
| May 2026 Disclosure month covered in the article | Instructure Canvas / regional education users | Global platform; Townsville and Queensland school connections Global platform with regional relevance | Education technology | Learning platform breach and extortion claims | Breach reported; institution list unverified Local reporting describes government and school responses. The threat actor list is not proof that every named institution or record was affected. Account dated 13 May 2026 | Townsville Bulletin (subscription) | Read the canvas account |
How to read the tracker
Confirmed means the organisation's notice confirms the described incident, within the limits stated. Reported identifies attributed journalism, including statements quoted by a publication. Claimed identifies an allegation, including a threat actor's claim, that the cited account has not established as a confirmed breach. An incident can be confirmed while its cause, attribution or alleged data theft remains unconfirmed.
The date column identifies whether it is an incident window, disclosure date or report date. It does not silently substitute an article's publication date for the day an attack happened. Month-only dates mean this collection does not establish a more precise date.
One row represents an incident covered by this series, not one victim, one city or one successful attack. National and global platform incidents are labelled separately from incidents at regional organisations. A retailer having a regional store does not establish how many local customers were affected. Repeated reporting about the same incident belongs in the existing row.
The initial collection covers Townsville, Cairns and Mackay connections. It has no dedicated incident entry yet for Rockhampton, Mount Isa or the Whitsundays. Missing entries reflect the limits of this collection, not evidence that those places have had no incidents. It cannot support a city risk ranking, a trend in attack frequency or an estimate of total regional losses.
Sources, updates and corrections
The table links to company notices where the articles provide them and to attributed reporting otherwise. Some reporting requires a subscription; the College notice is a retained image already reproduced in its article. The linked articles carry fuller context. No stolen datasets or criminal leak sites are linked here.
For a correction or a new public source, contact me with the entry, the source and what it changes. Please do not send personal records or stolen material. Updates should retain the distinction between the original account and later findings.
When citing an entry, link to its organisation row using the permanent fragment, for example Mackay Sugar, and include the account date and your access date. Cite the original source for the underlying incident facts. This index is compiled by Nicholas O'Sullivan; see the editorial disclaimer for disclosure and reuse information.
Read the Townsville, Cairns, Mackay and Rockhampton guides for regional context.