Official post-incident audits confirmed a June cyber intrusion targeting the NSW State Transit Authority was an uncontained ransomware execution. The incident severely degraded internal operations and required the reconstruction of segmented scheduling servers.