
A fraudulent tech support call was the trigger behind the 2025 data breach at Qantas that exposed personal information belonging to roughly 5.7 million customers, Australia’s privacy regulator has found, while also clearing the airline of any breach of its privacy obligations and declining to open a formal investigation.
The Office of the Australian Information Commissioner published findings detailing how a caller claiming to represent "Qantas IT help" contacted a company contact center and instructed an agent to take steps meant to close a support ticket. Those instructions instead granted access to a data extraction tool connected to Qantas’ customer relationship management system, allowing the attacker to pull customer records from the platform.
Commissioner Carly Kind concluded that Qantas could not have reasonably anticipated or stopped the breach given how it unfolded. She stated that the method used to gain access, a vishing attack, was not something that tighter role-based access controls at Qantas would have prevented.
Regulators examined whether Qantas complied with the Australian Privacy Principles, the legal standards governing how organizations must protect personal information, and found no shortfall. Investigators noted that Qantas had audited its contact center operator and evaluated staff security awareness in the months leading up to the attack, alongside running mandatory, recurring training on handling personal information. The airline’s practices around transferring data across borders were found to meet the same standards.
On data retention, the regulator noted Qantas carried out scheduled annual purges of customer records from its CRM system, and no data that should have been deleted remained in the system at the time of the attack. That record factored into the decision not to pursue a deeper probe.
The regulator’s findings left open the possibility of revisiting the matter later, and separate class-action lawsuits tied to the breach remain active. The report did not identify who carried out the attack. Pundits have suggested the Scattered Spider gang was responsible, pointing to the group’s targeting of the aviation sector in the weeks preceding the Qantas incident.
Roughly 4 million of the affected records contained names, phone numbers and email addresses, while an additional 1.7 million included more sensitive details such as home addresses and dates of birth. No financial information or passwords were among the data exposed. Investigators determined the breach relied on an uncommon social engineering method not typically addressed in standard staff training, combined with a default configuration setting within the CRM system.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543