logo

Qantas Did Everything “Right” — And Got Breached Anyway. Regulators Say That’s the Point.

ID: 36a55c0d-5134-58c1-9a47-bf7eac80424d

STIX ID: report--36a55c0d-5134-58c1-9a47-bf7eac80424d

Feed Name: The Cyber Express

Threat Score
65/100

Date Published: 2026-07-16

Date Updated: 2026-07-16

Author: Mihir Bagwe

...
...

A June 2025 vishing/social-engineering attack against an overseas Qantas contact-center agent allowed a threat actor to connect to the agent's CRM session and exfiltrate ~5.67 million customer records; no credit card, passport, or login credentials were exposed, Qantas detected and contained the incident quickly, and the Australian privacy regulator (OAIC) declined to commence enforcement after finding the breach was facilitated by social engineering and a vendor default setting that has since been changed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.