The outage that took down about 45 per cent of Telstra's calls and data sessions on 8 July, and left more than 600 Triple Zero calls unsuccessful, happened because the company had never treated the system that keeps its network clocks in step as a critical capability. Telstra published that finding on Wednesday.
The finding is the work of Technology Audit Partners, an external firm Telstra commissioned after the outage. Telstra released the findings report alongside a post from chief executive and managing director Vicki Brady.
Start with the calls. Telstra had reported 604 Triple Zero calls that did not get through. The review identified eight more. Of those eight, five were non-emergency calls or misdials, one connected through another carrier's network, one succeeded when the caller tried again, and one has not been identified. Telstra says it carried out welfare checks and has reported no adverse outcomes.
The review also moved the start of the outage. It began at 2:50am, close to an hour earlier than Telstra said at the time.
The system at the centre of it is network timing. Mobile networks need every element to agree on what time it is, to a fraction of a second, or handsets and base stations cannot hand calls between each other. Telstra takes that time from GPS receivers and distributes it using Network Time Protocol, the same standard that sets the clock on a laptop. During planned maintenance a software update was not applied to a GPS card. The card reset its date to 2006, and the wrong date spread through parts of the mobile network.
Technology Audit Partners found that ownership of the timing function was not sufficiently defined, so the risk attached to it was never treated properly. The architecture supporting timing had grown over years without anyone holding an end-to-end view of it. Telstra did not have enough specialist expertise in the system, and the review identified weaknesses in change management, configuration control, incident management and documentation.
Two of the engineers involved in the upgrade were on mandatory stand-down leave when the network failed. The alarms that would have told staff something was wrong were monitored only during business hours, by a small number of people.
There had been a warning nine months earlier. In October 2025, Telstra staff saw a clock connectivity problem between Melbourne and Sydney set off timing alarms. No investigation ticket was raised. Commonwealth cyber agencies had also issued public alerts in 2024 and again in October 2025 about vulnerabilities in positioning and timing systems.
“We did not prioritise our timing system inside our networks at the highest level as a critical capability," Brady said.”
Telstra says it has since moved services onto its strategic timing systems at all sites, expanded monitoring and widened its testing. It says it will now check whether other network functions are ranked at the right priority, look at how vendor alerts reach it, and review its platform alarms and service assurance arrangements.
About 30,000 customers contacted Telstra about the outage. They received credits totalling close to $1 million, most of them $15. In the same financial year, Telstra reported a net profit of $2.4 billion on revenue of $22.9 billion and cut 1,200 jobs. The board docked Brady's short-term bonus by $607,000, or 20 per cent, and eight other executives lost a collective $1.3 million. Brady's total pay for the year still rose 11 per cent, to $6.8 million.
What is not settled is the penalty. The Australian Communications and Media Authority is still running its own investigation, which can lead to fines of up to $30 million. Communications Minister Anika Wells said in July that the ACMA would conduct a full investigation and that Telstra's response was not good enough. The review Telstra published on Wednesday examined the company's engineering and its processes. It does not decide the regulatory question, and the ACMA has not said when it will.




