Australia's privacy regulator found that the 2025 Qantas breach affecting about 5.67 million customers began with a sophisticated tech-support vishing scam against a contact center agent. An attacker posing as Qantas IT support persuaded the employee to visit a malicious site and take actions inside the airline's CRM environment, linking the platform to a data-extraction tool and enabling the theft of customer records.
The Office of the Australian Information Commissioner said Qantas had taken reasonable steps to protect personal information and declined to pursue a formal privacy investigation or find the airline in breach of the Australian Privacy Principles. The regulator cited prior audits of the contact center, recurring privacy and security awareness training, and role-based access controls, while noting the incident depended on an uncommon social-engineering technique and a default CRM setting. Exposed data included customer names, phone numbers, email addresses, and for some individuals addresses and dates of birth; no financial data or passwords were reported compromised.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Australia's Office of the Australian Information Commissioner concluded its preliminary inquiry into the Qantas breach and decided not to open a formal privacy investigation or hold Qantas responsible. The regulator found Qantas had taken reasonable protective steps, including audits, training, awareness testing, and role-based access controls, and said the attack was not reasonably foreseeable or preventable through stronger existing role-based access controls alone.
In June 2025, a threat actor used a sophisticated vishing or fake IT support social-engineering attack against a Qantas contact center agent, leading to access to the airline's CRM platform and theft of customer data. The breach affected about 5.67 to 5.7 million customers and exposed details including names, phone numbers, email addresses, and for some customers, addresses and dates of birth; no financial information or passwords were compromised.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
teiss.co.uk
Open sourcescworld.com
Open sourcetheregister.com
Open sourceoaic.gov.au
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.