Qantas contact-centre data incident

Phone-based social engineering against an overseas third-party contact centre that connected a Qantas CRM instance to a threat-actor data-extraction tool. Compromise of Qantas customer contact and loyalty-program records stored in the affected CRM platform.

Last modified

Summary

  • Environment: Company report recorded by the regulator; not a universal claim beyond the monitored platform and inquiry period.
  • Operational impact: No outage or recovery duration quantified
  • Financial impact: No public cost estimate
  • Record status: Developing record. Reviewed August 9, 2026; updated as evidence emerges.

What happened

Phone-based social engineering against an overseas third-party contact centre that connected a Qantas CRM instance to a threat-actor data-extraction tool. [2]

Impact

Compromise of Qantas customer contact and loyalty-program records stored in the affected CRM platform. [1][2]

Documented data types include:

  • Names — Customer names; fields varied by record. [1][2]
  • Contact information — Email addresses, phone numbers, and some residential, business, or hotel addresses; fields varied by record. [1][2]
  • Dates of birth — Dates of birth in a subset of customer records. [1][2]
  • Gender information — Gender information in a subset of customer records. [1][2]
  • Loyalty program information — Qantas Frequent Flyer numbers and, for some records, tier, points balance, and status credits. [1][2]
  • Demographic information — Meal preferences in a subset of customer records. [1][2]

A cited record reports 5,120,000 individuals (Approximate number of Australians affected, as reported by the OAIC; as of 2026-07-16). [1][2]

A cited record reports 5,670,000 records (Approximate customer records compromised globally, including overseas customers; records are not necessarily unique people; as of 2026-07-16). [1][2]

The agent’s authorized CRM instance was connected through legitimate interactions to a data-extraction tool operated by the threat actor. [2]

Timeline

  1. Activity began

    Date the contact-centre agent received the social-engineering call and unauthorized extraction path was established.

    [2]
  2. Discovery

    Date unusual login-attempt alerts were escalated to the Qantas cybersecurity team.

    [2]
  3. Public disclosure

    Date Qantas publicly disclosed the incident.

    [2]
  4. Activity began

    Beginning of the OAIC preliminary-inquiry period.

    [2]
  5. Documented activity ended

    End of the OAIC preliminary-inquiry period.

    [2]
  6. Documented event

    Publication date of the OAIC report.

    [2]
  7. Briefing updated

    This briefing was last reviewed and updated on August 9, 2026.

Threat Group & Attack Vector

The OAIC reported that the CRM platform did not store credit-card, personal financial, or passport information, and Qantas said passwords, PINs, and login details were not compromised. [2]

A caller impersonating Qantas IT deceived an overseas contact-centre agent in a phone-based social-engineering attack, also described as vishing. [2]

The compromised CRM platform was used by an overseas contact centre operated by an unnamed third-party provider contracted by Qantas. [2]

Actors

  • No threat actor group has been identified in the reviewed public evidence.

TTPs

Response

During the OAIC inquiries, Qantas reported no evidence of further or ongoing threat-actor activity on the CRM platform. The OAIC emphasized that it had not conducted a full Commissioner-initiated investigation, made no concluded findings, and did not present the report as a broader endorsement of Qantas’s compliance. The OAIC closed its preliminary inquiries without commencing a Commissioner-initiated investigation or taking other regulatory action at that time because the available evidence did not point toward a likely APP contravention warranting further investigation. Qantas activated crisis management, engaged legal and forensic specialists, and provided additional social-engineering training after the incident. On or around 9 July 2025, Qantas notified impacted customers of the specific categories of personal information involved. On 30 June 2025, Qantas froze and revoked access to the associated account, securing the CRM platform and triggering incident-response processes. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [2]