AU: Regulator’s preliminary findings did not indicate Qantas breached privacy obligations
ID: c7e70aa5-30fb-5ba4-9921-ebab7da480f7
STIX ID: report--c7e70aa5-30fb-5ba4-9921-ebab7da480f7
Feed Name: DataBreaches.Net
Threat Score
The report describes a 2025 breach of Qantas customer data in which attackers socially engineered a contractor employee to open a CRM session, enabling exfiltration of 5.67 million records later released by criminals; the Australian regulator’s preliminary inquiry did not find a likely privacy law breach, noted existing controls and a problematic default CRM setting (now changed), and a NSW Supreme Court injunction limits distribution of the stolen data.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
