Daily brief at 7am Melbourne. Unsubscribe any time.

Friday 17 July 2026

Qantas Leaked 5.7 Million People's Data Via a Phone Scam — and Faced Zero Formal Consequences

A tech support scam exposed 5.7 million Qantas passengers' data — and Australia's privacy watchdog just let the airline walk away clean.

Lead story

Qantas Leaked 5.7 Million People's Data Via a Phone Scam — and Faced Zero Formal Consequences

A scammer called a Qantas contact centre, convinced an employee they were legitimate tech support, and walked away with personal information belonging to 5.7 million people. That's the core of a breach first reported in 2025 — and this week we learned how Australia's privacy regulator handled it: with a finding of no wrongdoing and no formal investigation.

The Office of the Australian Information Commissioner concluded that Qantas did not fail to take reasonable steps to protect personal information. The OAIC's reasoning, as reported by iTnews and The Register, appears to centre on the fact that the attack was a sophisticated social engineering exercise — a vishing call — rather than a technical breach the airline should have foreseen or prevented through better system controls.

That conclusion will raise eyebrows. Vishing — voice phishing, where an attacker impersonates IT support or a vendor over the phone — is not a novel attack vector. It has been well-documented for years and sits squarely within the threat models that large organisations are expected to plan for. The technique is so common that Scattered Spider, the group behind the Transport for London hack sentenced yesterday, used a near-identical playbook.

Why this matters beyond Qantas. The OAIC decision sets a quiet precedent: if an attacker successfully impersonates tech support and an employee is deceived, that may not constitute a failure to protect data under Australia's Privacy Act. For every other large organisation holding millions of Australians' personal records — banks, health funds, telcos — the message is ambiguous at best.

Australia's Privacy Act reform has been grinding through parliament, with proposals to strengthen the "reasonable steps" test and introduce a direct right of action for individuals. This outcome will almost certainly be cited in that debate, both by advocates arguing the current framework lacks teeth and by industry arguing it already works.

What Qantas exposed. The breach involved names, contact details, frequent flyer membership numbers, and booking information. For 5.7 million people, that's a meaningful trove — enough to fuel targeted phishing and loyalty fraud campaigns. There's no public evidence the data has been weaponised at scale, but that's a cold comfort given the breach is now well over a year old and the data is presumably still in circulation somewhere.

What to watch. Parliament resumes in August and the Privacy Act reform bill is expected back before the Senate. Watch for the OAIC's Qantas decision to be raised in committee hearings. Also watch whether other carriers and large consumer-facing companies quietly update their "we take your privacy seriously" posture — or conclude they don't need to.

The regulator had an opportunity to draw a clear line on social engineering as a foreseeable risk. It didn't. That line will now need to be drawn somewhere else.

Also today

Australian Medical Clinic Chain Partnered Health Hit by Data Theft

Partnered Health, which operates medical clinics across Australia, has disclosed a data breach involving the theft of sensitive personal information. Details of the scope — how many patients, what categories of data — have not been fully disclosed publicly. Healthcare breaches carry particular weight under Australia's Privacy Act and the Notifiable Data Breaches scheme, given the sensitivity of medical records. The incident adds to a string of Australian healthcare sector breaches in recent years, following high-profile cases at Medibank and MedSecure. The OAIC will be watching, and affected patients should be alert to targeted phishing attempts leveraging their health information.

iTnews

Scattered Spider Duo Sentenced to 5.5 Years for the TfL Hack

Owen Flowers, 18, and Thalha Jubair, 20, were sentenced to five and a half years each at Woolwich Crown Court for the 2024 cyberattack on Transport for London. The attack took down 148 systems and forced all 27,000 TfL staff to physically attend offices to reset their passwords — a logistical nightmare that cost tens of millions of pounds. The NCA described the sentencing as a landmark result. Scattered Spider's methods — social engineering and SIM swapping — are the same techniques behind a wave of attacks on MGM Resorts, Caesars Entertainment, and others. The sentences are among the stiffest handed down for cybercrime in the UK.

The Record

Russia's Sandworm Is Now Using ClickFix to Target Ukrainians

Sandworm — Russia's most capable offensive cyber unit, linked to attacks on power grids and the NotPetya wiper — has adopted ClickFix, a social engineering technique previously favoured by financially motivated criminals. In this campaign, Ukrainian targets are served a fake CAPTCHA page that instructs them to paste a PowerShell command into their Windows machine rather than ticking a box to prove they're human. It's a clever inversion of a trusted UI pattern. The shift signals that nation-state actors are actively borrowing low-cost, high-effectiveness techniques from the criminal ecosystem when they work — and ClickFix has been working consistently since it emerged in 2024.

The Record

Zoom Patches a Critical CVSS 9.8 Account Takeover Flaw on Windows

Zoom has pushed a fix for CVE-2026-53412, a critical improper input validation vulnerability scoring 9.8 on the CVSS scale, affecting Zoom Desktop Client, VDI Client, and Meeting SDK for Windows. A successful exploit could allow an attacker to take over a user's account. With Zoom deeply embedded in enterprise and government workflows — including across Australian federal and state agencies — prompt patching is essential. Splunk also patched critical flaws in the same window, including bugs that could allow credential theft and privilege escalation. Both vendors have published updated versions; check your deployment tooling has picked them up.

SecurityWeek

A Researcher Poisoned an Open-Weight AI Model for Under $100

A security researcher has demonstrated that open-weight AI models — the kind anyone can download and run locally — can be poisoned with malicious backdoor behaviour for less than $100 in compute costs. The attack works by fine-tuning the model on a small dataset designed to trigger specific harmful outputs when it encounters a particular input pattern, while behaving normally the rest of the time. The finding underscores a structural problem with the open-weight ecosystem: unlike a hosted API, there's no central operator to audit what a downloaded model actually does. As Australian enterprises increasingly experiment with locally-run models to keep data on-premises, this threat model deserves attention.

The Register

HuggingFace Discloses a Security Incident — July 2026

Hugging Face, the platform that hosts hundreds of thousands of open-source AI models and datasets, has published a security incident disclosure for July 2026. Details in the post are sparse, but the disclosure follows a pattern of increasing attacker interest in ML supply chains — including model-poisoning attacks, malicious datasets, and compromised inference pipelines. Given that Hugging Face sits upstream of a vast number of enterprise and research AI deployments worldwide, any compromise to its model-hosting infrastructure has the potential to propagate downstream at significant scale. The full scope and affected accounts had not been publicly confirmed at the time of writing.

Hugging Face

EU Orders Google to Open Android AI to Rivals — and Google Is Quietly Fine With It

The European Commission has formally ordered Google to grant competitors greater access to Android's AI integrations and share search data under the Digital Markets Act. On paper it sounds like a loss for Google. The Verge's analysis argues the opposite: Google spent years building a regulatory compliance posture in Brussels that Apple largely ignored, and now Apple faces far more disruptive DMA obligations around Siri and its AI stack than Google does. The ruling will force Android to surface rival AI assistants more prominently, but Google's underlying model distribution advantage — Gemini is already embedded everywhere — remains intact.

Ars Technica

Uber Is Buying Delivery Hero for $14.8 Billion

Uber has agreed to acquire Delivery Hero — the German food delivery giant behind brands including Foodpanda, Glovo, and Pedidos Ya — in an all-stock deal valuing the transaction at $14.8 billion. The deal would roughly double Uber Eats' global footprint outside China, creating one of the world's two largest food delivery platforms. Foodpanda has a significant presence across Southeast Asia and parts of the Asia-Pacific region. For Australian regulators, the deal will likely attract ACCC scrutiny given Uber Eats' existing market position domestically — though Delivery Hero has no direct Australian operation, the combined entity's market power in adjacent regions is relevant context.

TechCrunch

Old UEFI Shim Bootloaders Are Still Trusted — and Still Exploitable

Researchers have found that nearly a dozen revoked UEFI shim bootloaders — signed by Microsoft and used by Linux distributions to pass Secure Boot checks — remained in trusted firmware databases for years after known vulnerabilities were disclosed. An attacker with the right access can load one of these old, vulnerable shims and use it to bypass Secure Boot entirely, undermining a foundational layer of boot-time integrity checking. The issue affects any system running a Linux distribution that relies on UEFI Secure Boot, regardless of the OS version. Organisations with large Linux server estates — common in Australian cloud and government environments — should verify their firmware revocation lists are current.

Dark Reading

54% of Enterprises Have Already Had an AI Agent Security Incident

A VentureBeat survey of 107 enterprises found that more than half have already experienced a confirmed AI agent security incident or a near-miss — yet most organisations still allow agents to share credentials rather than assigning each a scoped identity. Only three in ten isolate their highest-risk agents. The findings paint a picture of an industry deploying agentic AI into production environments faster than it can build the access controls and monitoring needed to contain those agents when something goes wrong. The gap is structural: most security tooling being used to govern agents is borrowed from model providers and cloud hyperscalers rather than purpose-built for agentic workloads.

VentureBeat AI

Japan's KFC Runs Out of Chicken After Cyberattack on Cold-Chain Logistics Giant

A cyberattack on Nichirei Logistics Group — Japan's largest cold-chain operator — has disrupted food supply chains across the country, forcing KFC Japan to suspend online ordering and warn of potential store closures due to ingredient shortages. Major supermarket chains are also struggling with deliveries. The incident is a sharp illustration of how cyberattacks on logistics infrastructure translate directly into physical-world disruption, and how a single upstream supplier can become a single point of failure for an entire distribution network. Cold-chain logistics is classified as critical infrastructure in several jurisdictions; Australia's SOCI Act covers food and grocery supply chains, and this incident is a useful reference point for third-party risk assessments in that sector.

The Record

Sources consulted