Lead story
Qantas Leaked 5.7 Million People's Data Via a Phone Scam — and Faced Zero Formal Consequences
A scammer called a Qantas contact centre, convinced an employee they were legitimate tech support, and walked away with personal information belonging to 5.7 million people. That's the core of a breach first reported in 2025 — and this week we learned how Australia's privacy regulator handled it: with a finding of no wrongdoing and no formal investigation.
The Office of the Australian Information Commissioner concluded that Qantas did not fail to take reasonable steps to protect personal information. The OAIC's reasoning, as reported by iTnews and The Register, appears to centre on the fact that the attack was a sophisticated social engineering exercise — a vishing call — rather than a technical breach the airline should have foreseen or prevented through better system controls.
That conclusion will raise eyebrows. Vishing — voice phishing, where an attacker impersonates IT support or a vendor over the phone — is not a novel attack vector. It has been well-documented for years and sits squarely within the threat models that large organisations are expected to plan for. The technique is so common that Scattered Spider, the group behind the Transport for London hack sentenced yesterday, used a near-identical playbook.
Why this matters beyond Qantas. The OAIC decision sets a quiet precedent: if an attacker successfully impersonates tech support and an employee is deceived, that may not constitute a failure to protect data under Australia's Privacy Act. For every other large organisation holding millions of Australians' personal records — banks, health funds, telcos — the message is ambiguous at best.
Australia's Privacy Act reform has been grinding through parliament, with proposals to strengthen the "reasonable steps" test and introduce a direct right of action for individuals. This outcome will almost certainly be cited in that debate, both by advocates arguing the current framework lacks teeth and by industry arguing it already works.
What Qantas exposed. The breach involved names, contact details, frequent flyer membership numbers, and booking information. For 5.7 million people, that's a meaningful trove — enough to fuel targeted phishing and loyalty fraud campaigns. There's no public evidence the data has been weaponised at scale, but that's a cold comfort given the breach is now well over a year old and the data is presumably still in circulation somewhere.
What to watch. Parliament resumes in August and the Privacy Act reform bill is expected back before the Senate. Watch for the OAIC's Qantas decision to be raised in committee hearings. Also watch whether other carriers and large consumer-facing companies quietly update their "we take your privacy seriously" posture — or conclude they don't need to.
The regulator had an opportunity to draw a clear line on social engineering as a foreseeable risk. It didn't. That line will now need to be drawn somewhere else.
