US National Wire
Tech

Qantas Tech Support Scam Leaked PII on 5.7 Million Customers; No Privacy Breach Found

Portrait of Chloe Winslow
Chloe Winslowretail & e-commerce techJul 19AI
Qantas Tech Support Scam Leaked PII on 5.7 Million Customers; No Privacy Breach Found

AI-generated image · US National Wire

Australia's Privacy Commissioner finds Qantas didn't breach privacy rules despite a social engineering attack that leaked PII for 5.7 million customers.

As The Register first reported, a report from Australia's Privacy Commissioner has detailed the mechanics of a massive 2025 data breach at Qantas, revealing that the vulnerability lay not in the software, but in the human element of the airline's support operations.

The breach was the result of a social engineering attack targeting a contact center. A threat actor posing as "Qantas IT help" contacted a center agent and instructed them to perform specific actions within a CRM system to resolve a support ticket. These actions, however, served to connect the CRM to a data extraction tool, which the attackers used to siphon off the personally identifiable information (PII) of 5.7 million customers.

Despite the scale of the leak, Privacy Commissioner Carly Kind concluded that Qantas did not breach its privacy obligations under the Australian Privacy Principles (APPs). The Commissioner's report found that Qantas had implemented role-based access controls and conducted mandatory, recurring training on the handling of PII. Furthermore, the airline had audited the contact center operator and tested employee security awareness in the months preceding the incident.

Regarding data retention, Qantas informed the Privacy Commissioner that it performed annual data removal runs from its CRM, and no records that should have been deleted were present during the attack.

Commissioner Kind stated that it did not appear Qantas could have reasonably foreseen or prevented the breach as it occurred, noting that the "vishing" attack could not have been stopped by strengthening the existing role-based access controls. Consequently, the regulator decided not to open a formal privacy probe, stating that inquiries did not identify omissions in Qantas' steps that would have prevented the incident.

While the official report does not identify the attackers, The Register notes that pundits have suggested the Scattered Spider gang may be responsible, following a series of attacks on the aviation industry shortly before the Qantas breach. Although the regulator has cleared the airline, Qantas still faces potential class-action lawsuits.

Sources

More from Chloe Winslow