Qantas Avoids Formal OAIC Inquiry Regarding 2025 Vishing Event


We independently review everything we recommend. When you buy through our links, we may earn a commission which is paid directly to our Australia-based writers, editors, and support staff. Thank you for your support!

Brief Overview

  • Qantas will not undergo an official OAIC inquiry regarding the June 2025 data breach.
  • Initial investigations by the OAIC revealed that Qantas implemented sufficient measures to handle the breach.
  • The breach impacted the personal and frequent flyer details of 5.12 million Australians.
  • The data was compromised via a social engineering method identified as vishing.
  • The OAIC may still choose to initiate a formal investigation later on.

Qantas Tackles Data Breach Issues

Summary of the June 2025 Breach

In June 2025, Qantas faced a major data breach that unveiled the personal and frequent flyer data of roughly 5.12 million Australians. This incident was linked to cyber attacks from groups referred to as Scattered Spider, Lapsus$, and ShinyHunters. The event raised alarms regarding the airline’s data protection protocols.

OAIC’s Initial Findings

The Office of the Australian Information Commissioner (OAIC), under the leadership of Privacy Commissioner Carly Kind, carried out initial inquiries into the breach. They assessed whether Qantas contravened Australian Privacy Principles 1, 8, and 11, which relate to the handling, overseas disclosure, and security of personal data. The findings suggested that Qantas had implemented proper measures to manage the breach, including containing the issue and swiftly notifying the public.

Understanding the Vishing Technique

The breach was carried out utilizing a technique known as vishing, a variety of social engineering where perpetrators mimic trusted organizations to gather information. In this scenario, the attacker impersonated “Qantas IT help” and deceived a call center representative into employing a customized version of Salesforce’s Data Loader tool, enabling the mass extraction of customer data.

Future Considerations for Qantas

Although the OAIC has opted not to initiate a formal investigation at this time, this determination is not definitive. The regulatory body holds the authority to pursue a formal inquiry should new information emerge or if Qantas does not maintain adequate data protection standards going forward. This situation underscores the persistent cyber threats encountered by organizations and the critical need for strong security protocols.

Conclusion

Qantas has evaded an immediate formal investigation from the OAIC concerning the data breach in June 2025, which affected millions of Australians. The preliminary investigations by the OAIC established that Qantas handled the breach properly, though the possibility of future inquiries persists. This episode emphasizes the threats posed by vishing attacks and the importance of rigorous data protection measures within the aviation sector.

Reader questions

Frequently asked questions

Fast answers to the questions readers ask most about Qantas Avoids Formal OAIC Inquiry Regarding 2025 Vishing Event.

What triggered the data breach at Qantas?

The breach was instigated by a vishing attack, where an adversary impersonated “Qantas IT help” and manipulated a call center agent into utilizing a tailored Salesforce tool for data extraction.

How many Australians were impacted by the Qantas data breach?

Approximately 5.12 million Australians had their personal and frequent flyer information compromised during the breach.

Did the OAIC find Qantas guilty of violating any privacy principles?

The OAIC’s initial inquiries did not find Qantas in violation of Australian Privacy Principles 1, 8, and 11, as the airline took measures to manage and contain the breach.

Is the OAIC able to conduct a formal investigation in the future?

Yes, the OAIC maintains the authority to initiate a formal investigation if deemed necessary, based on new information or future compliance concerns.

How did Qantas respond to the data breach?

Qantas acted swiftly to contain the breach and communicated the incident to the public, thereby reducing potential risks to their customers.

What is vishing and why is it a threat?

Vishing is a social engineering tactic where assailants leverage voice communication to impersonate trusted figures and acquire sensitive information. It is a threat because it manipulates human trust, potentially resulting in major data breaches.

Posted by Matthew Miller

Matthew Miller is a Brisbane-based Consumer Technology Editor at Techbest covering breaking Australia tech news.

Leave a Reply

Your email address will not be published. Required fields are marked *