Skip to content

Report Into Preliminary Inquiries Of Qantas

www.oaic.gov.au July 29, 2026

Every year, the Office of the Australian Information Commissioner ( OAIC ) is notified of more than a thousand data breaches that are likely to result in serious harm to individuals. For the past 8 years of OAIC Notifiable Data Breach ( NDB ) reporting, malicious or criminal attacks have consistently been the primary cause of such breaches, with social engineering or impersonation being a highly prevalent cause. Social engineering refers to situations where a malicious actor impersonates another individual to gain access to an account, system, network or physical location, bypassing technical security measures in the process.

The data breach experienced by Qantas Airways Limited ( Qantas ) in 2025, which affected approximately 5.12 million Australians, came as a result of a social engineering attack on an overseas third-party provider contracted by Qantas. The breach left many Australians concerned for their privacy, and frustrated that their personal information had been subjected to unauthorised access by hackers. As is standard procedure in major data breaches, the OAIC made preliminary inquiries to ascertain the causes of the data breach and identify any acts or practices on the part of Qantas that warrant investigation by the OAIC. These extensive preliminary inquiries took place over nearly a year and involved access to information and documents held by Qantas.

As detailed in the report, the information obtained through our preliminary inquiries did not indicate a likelihood that Qantas had failed to take reasonable steps to protect the personal information it held at the time of the incident. Nor did it indicate a likelihood that Qantas failed to take reasonable steps to ensure its overseas third-party provider complied with the Australian Privacy Principles ( APPs ). These observations are based on preliminary inquiries only. The OAIC has not conducted a Commissioner-initiated investigation ( CII ) and this report does not make concluded findings on these matters. It is still open to the Commissioner to commence an investigation of Qantas with respect to these or other practices.

The impact of the data breach was reduced by Qantas’ timely implementation of its incident management and reporting framework which sought to contain and remediate the data breach. Furthermore, Qantas’ post-incident remediation steps, which included engaging specialist teams to assist in forensic analysis of the incident and the provision of additional training, are examples of additional risk reduction measures. While they may not prevent all future intrusions, they are indicative of Qantas taking steps to reduce these risks.

For the reasons outlined in this report, I have concluded my preliminary inquiries into the data breach without commencing a CII or taking other regulatory action in response to the incident. I do not consider the evidence supports the likelihood of a breach and do not consider it an appropriate use of resources to commence a CII.

Section 33B of the Privacy Act empowers me to release information where doing so is in the public interest. I have decided to publish this report of the OAIC’s preliminary inquiries into the breach because of the high level of public interest in the incident, and the educative value of disseminating both the findings and information the OAIC’s decision-making process.

Qantas is Australia’s largest domestic and international airline. Qantas has centres located overseas that are operated by a third-party provider.

Qantas advised that on Saturday 28 June 2025, an agent employed at a centre ( Agent ) received a call from a threat actor impersonating ‘Qantas IT help’. The Agent was deceived into believing that the threat actor was a legitimate Qantas employee that was contacting to check an IT issue that the Agent may have been experiencing.

The threat actor directed the Agent to visit a website related to a customer relationship management platform used by Qantas centre agents ( CRM Platform ). The threat actor directed the Agent through a series of actions that the threat actor claimed were required to close an IT support ticket. At the time, the Agent was authorised to access the profiles of customers on the CRM Platform as part of performing their daily role.

The actions resulted in the Agent’s instance of the CRM Platform being connected to a data extraction tool operated by the threat actor, which was used to extract data from the profiles that the Agent had access to.

This constituted a cyber incident arising from a successful case of phone-based social engineering, also known as ‘vishing’.

In the morning of Monday 30 June 2025, a Qantas staff member with responsibilities in relation to the CRM Platform identified an unusual number of system-generated login attempt alerts from 28 June 2025. Upon seeing them, the staff member alerted the Qantas cybersecurity team. Subsequent internal investigations confirmed that the 2 alerts were generated due to an unusual number of failed login attempts.

Upon validating the alerts, Qantas took immediate steps to contain and remediate the cyber incident. On the same day of 30 June 2025, Qantas:

Qantas disclosed the incident to the public a few days later, on 2 July 2025.

Qantas also engaged specialist legal and forensics experts to conduct a forensic analysis of the customer data in the system that was compromised. On or around 9 July 2025, Qantas notified all impacted customers of the specific types of personal information that had been impacted by the incident.

Throughout our enquiries Qantas continued to actively monitor the CRM Platform and notified us that there is no evidence of any further or ongoing threat actor activity.

Between 11 July 2025 and 1 June 2026, the OAIC conducted preliminary inquiries with Qantas under s 42(2) of the Privacy Act to assess Qantas’ compliance with the Notifiable Data Breaches Scheme and determine whether to commence a CII under s 40(2) of the Privacy Act. The preliminary inquiries examined the circumstances of the cyber incident and the likelihood that Qantas had contravened APPs 1, 8 and 11.

In undertaking these preliminary inquiries, the OAIC had regard to the APP Guidelines, our regulatory position on the application of APPs 1, 8 and 11 as described in the APP Guidelines, recent privacy determinations, and established international and domestic cyber security frameworks – including ISO/IEC 27001, the Australian Government Information Security Manual (ISM), and the ASD Essential Eight Maturity Model.

Our preliminary inquiries established that:

This report details the information obtained during the OAIC’s preliminary inquiries, and reasons why the OAIC determined not to conduct a CII following those preliminary inquiries. This information may have relevance to other processes underway at the OAIC related to the data breach, such as individual and representative complaints. However, any decision on those processes will be taken on a case-by-case basis in accordance with the relevant provisions of the Privacy Act.

APP 1.2 requires an APP entity to take reasonable steps to implement practices, procedures and systems relating to the entity’s functions or activities that will ensure the entity complies with the APPs and any binding registered APP code, and enable the entity to deal with inquiries or complaints from individuals the entity’s compliance with the APPs and any binding registered APP code.

In assessing Qantas’ compliance with APP 1.2, we had regard to the following:

In relation to the assessment of whether Qantas had taken reasonable steps to ensure it could deal with inquiries or complaints from individuals APP compliance, we observed:

The information obtained via preliminary inquiries did not suggest that Qantas failed to take reasonable steps to ensure compliance with the APPs and to enable Qantas to deal with inquiries or complaints from individuals Qantas’ compliance with the APPs.

We consider that the information available suggests that the steps taken by Qantas were adequate in the circumstances to comply with the APPs, including having adequate measures in place with respect to the management and ongoing compliance of their third-party service providers, and with respect to dealing with inquiries or complaints from individuals APP compliance.

APP 8.1 provides that before an APP entity discloses personal information an individual to an overseas recipient, the entity must take such steps as are reasonable in the circumstances to ensure that the recipient does not breach the APPs (other than APP1) in relation to the information. Where an APP entity discloses personal information to an overseas recipient, it is accountable for an act or practice of the overseas recipient that would breach the APPs per s16C of the Privacy Act.

In assessing Qantas’ compliance with APP 8, we had regard to the relevant service level and contractual agreements between Qantas and the centre provider. Our inquiries identified that Qantas had a service level agreement with the centre provider which required it to maintain compliance with ISO 27001:2013 (or equivalent), provide Qantas with audit rights, and comply with the Privacy Act and the General Data Protection Regulation (GDPR).

ISO 27001 compliance is particularly relevant in assessing whether Qantas took reasonable steps to prevent a breach of the APPs in this context. Compliance with the standard requires adherence to several controls directly connected to the circumstances of this incident, including:

On balance, our inquiries did not identify any omissions in the steps Qantas took that, if addressed, would have prevented the breach that occurred in this incident. Additionally, the information available suggests that the centre provider’s compliance with the relevant standards, particularly in the areas of access control, agent training, and monitoring were reasonable in the circumstances, and it is our view that Qantas took steps to ensure that this was the case.

APP 11.1 requires organisations to take such steps as are reasonable in the circumstances to protect personal information from unauthorised access. Reasonable steps include technical and organisational measures. Technical measures include protecting personal information by implementing technological controls and physical measures relating to software and hardware. Organisational measures involve implementing policies, processes and procedures to protect the security of information.

The fact that a breach occurred does not, on its own, mean that an organisation failed to take steps as are reasonable in the circumstances.

As per the APP Guidelines, [1] the steps that an APP entity must take to ensure the security of personal information will depend on the circumstances. This includes:

Based on the information provided by Qantas in response to our preliminary inquiries, it appears that at the time of the incident:

On balance, the evidence obtained did not point towards significant omissions or failures in the steps taken by Qantas to address the security risks. This is on the basis that:

In addition to the steps in place at the time of the incident, Qantas advised that it:

APP 11.2 requires an APP entity to take such steps as are reasonable in the circumstances to destroy or de-identify the personal information it holds once the personal information is no longer needed for any purpose for which the personal information may be used or disclosed under the APPs.

Based on the information provided by Qantas in response to our preliminary inquiries, it appears that:

On balance, the evidence obtained did not point towards significant omissions or failures in the steps Qantas took to de-identify or destroy personal information that was no longer needed was reasonable in the circumstances. This was on the basis that:

I have a broad discretion to commence an investigation of an act or practice where it may be a contravention of the APPs and where it is desirable to do so (s 40(2)). Decisions to exercise that discretion are guided by the OAIC’s Statement of Regulatory Approach, Privacy Regulatory Action Policy and alignment with our Regulatory Priorities .

The information obtained during the preliminary inquiries into the data breach did not point towards a contravention of the APPs that would justify the exercise of the discretion to investigate this matter further. The preliminary inquiries did not reveal any omissions or failings in the steps taken by Qantas to protect the personal information it held or to ensure the centre provider complied with the APPs. Based on the information provided, it does not appear that Qantas could have reasonably foreseen and prevented the breach in the manner that it occurred. The way in which the threat actor gained access was through a vishing attack which could not have been prevented by a strengthening of Qantas’ current role-based access controls. Additionally, the preliminary inquiries indicated that the incident was not indicative of a systemic deficiency in staff training. Qantas was quick to activate its crisis management response post incident and undertake a forensic analysis of the incident.

I am therefore closing the preliminary inquiries into the data breach without commencing a CII or taking other regulatory action in response to the incident at this time. It is still open to me to commence an investigation with respect to these or other practices at a later time, and this report should not be taken as an endorsement of Qantas’ acts or practices or an assurance of their broader compliance with the APPs.

As the OAIC has received a Representative Complaint, and individual complaints, this data breach, I confirm that those parties are being engaged with directly in relation to their individual complaints and the contents of this report.

Having regard to the matters listed in s 33B(2) of the Privacy Act, I am of the view that publishing this report would be in the public interest. I confirm that this report reflects the outcomes of preliminary inquiries. Accordingly individual complaints and any future commissioner-initiated investigation would be considered on the basis of information relevant to those processes. In my view publication of this report reflecting the outcome of preliminary inquiries would not prejudice the rights of individuals or the processes available under the Privacy Act.

I have also considered whether the publication of this report would likely disclose any confidential information. The report details steps taken by Qantas in relation to this significant event. However, in my view, that content reflects established standards and procedures generally known or in place to prevent and/or manage cyber risks. Accordingly, when balanced against the public interest to be served I am satisfied that publication of this report will serve the public interest for reasons including that greater awareness of the need for cyber security and associated vigilance offers an additional layer of community protection.

I am satisfied, on balance, that it is in the public interest to disclose this report publicly. This is because of the high level of public interest in the incident and the benefits in promoting public awareness and understanding of this significant event, the causative factors and the extant privacy protections implemented by Qantas. Given the increasing sophistication of cyber attacks, I consider that publishing details of this preliminary inquiry can highlight to APP entities of the need to take reasonable steps to protect personal information from unauthorised access. It is also important to note that while no security control is completely effective, appropriate risk reductions measures such as the measures taken by Qantas can reduce the impact of privacy interference of individuals. Individuals and the community will also benefit from a heightened awareness of the risks of cyber-attack particularly those that deploy social engineering.

[1] , 11.8.

[2] See, for instance: Overview of record-keeping rules for business | Australian Taxation Office .

Extracted Entities

Attack Types (1)

Countries (1)