phishing
Qantas Lost 5.7M Records to a Vishing Call and Broke No Rules
2026-07-17

Australia's Privacy Commissioner has closed the file on the 2025 Qantas breach with a verdict you don't see often: the airline lost personal data belonging to 5.7 million customers, and it broke no rules doing so.
The report, out this week, finally lays out how the thing actually happened. Someone rang a Qantas contact centre claiming to be from "Qantas IT help" and walked an agent through what sounded like the steps to close out a support ticket. The steps instead connected the CRM to a data extraction tool, and the attackers helped themselves to customer records at their leisure.
What Qantas had already done
This is where the story gets uncomfortable for anyone who assumed the breach was a governance failure. Before the incident, Qantas had:
- Audited the contact centre operator.
- Tested staff on security awareness in the months prior.
- Run mandatory recurring training on handling personal data.
- Enforced role-based access controls.
- Followed its data retention schedules.
Commissioner Carly Kind concluded that nothing Qantas could reasonably have done would have stopped a well-executed vishing call from working. On that basis, the regulator declined to open a formal investigation.
The parts still unresolved
Class actions are still circling. The identity of the attackers remains officially unconfirmed, although Scattered Spider is the name most people keep saying out loud, given the group's busy run at the aviation sector around the same time.
What's striking about the Commissioner's finding is not that Qantas got off lightly. It's the acknowledgement that a company can do the training, run the audits, tighten the access, keep the retention windows honest, and still lose millions of records to one convincing phone call. The bar for "reasonable steps" was met. The data went anyway.
Why vishing keeps working
Voice-based social engineering has quietly become the preferred way into large service organisations. It works because contact centre staff are paid to be helpful, they're often under handle-time pressure, and the attacker on the line has usually done their homework, knowing the internal lingo, the tools, the ticket format, the names of real IT staff. A well-run pretext doesn't feel like an attack. It feels like Tuesday.
The Qantas finding is a useful data point for anyone running security awareness inside a large operation. The training worked, in the sense that the programme existed, was current, and covered the right ground. It just didn't work on this particular call, with this particular agent, against this particular pitch. Which is the honest reality of awareness work. It's not a certificate you hang on the wall in March and forget about until next March. The person on the other end of the line is always getting better at the pitch, and the only defence that keeps up is one that assumes the same of itself.
Qantas will pay for this in court, in customer trust, and in the quiet cost of rebuilding a contact centre culture where "IT support" on the phone is treated as a suspect until proven otherwise. But the regulator's verdict is worth reading carefully. Compliance was met. The breach still happened. Those two facts are meant to sit together uncomfortably.