logo

AU: Regulator’s preliminary findings did not indicate Qantas breached privacy obligations

ID: c7e70aa5-30fb-5ba4-9921-ebab7da480f7

STIX ID: report--c7e70aa5-30fb-5ba4-9921-ebab7da480f7

Feed Name: DataBreaches.Net

Threat Score
75/100

Date Published: 2026-07-16

Date Updated: 2026-07-16

Author: Dissent

...
...

The report describes a 2025 breach of Qantas customer data in which attackers socially engineered a contractor employee to open a CRM session, enabling exfiltration of 5.67 million records later released by criminals; the Australian regulator’s preliminary inquiry did not find a likely privacy law breach, noted existing controls and a problematic default CRM setting (now changed), and a NSW Supreme Court injunction limits distribution of the stolen data.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.