Australia’s privacy regulator said the 2025 Qantas breach that exposed personal data for 5.7 million customers began with a fake IT support call to a contact center. According to the report, the caller posed as “Qantas IT help” and tricked an agent into using the airline’s customer relationship management system in a way that linked it to a data-extraction tool, allowing customer records to be siphoned out. The regulator said Qantas had role-based access controls, audits, and recurring staff training in place and decided not to open a formal privacy investigation.
Why it matters: This gives both travelers and defenders a clearer picture of how a large airline breach happened: a voice-based social engineering attack, not a software flaw. Organizations should review help-desk and contact-center procedures, especially any workflow that lets staff connect business systems to external tools or act on unsolicited support calls.
2026.07.16
100% relevant
This article establishes a distinct trackable story by adding the regulator's findings, the specific vishing-based attack path through the contact center and CRM, and the decision not to pursue a formal privacy probe.
← Back to all stories