---
title: "Qantas contact-centre data incident"
description: "Evidence-backed account of Qantas contact-centre data incident, covering what happened, impact, timeline, attack vector, technical details, and primary sources."
incident_type: "Data incident"
status: "active"
last_modified: "2026-08-09"
canonical_url: "https://www.ally.security/incidents/qantas-contact-centre-data-incident-2025"
markdown_url: "https://www.ally.security/incidents/qantas-contact-centre-data-incident-2025.md"
stix_url: "https://www.ally.security/incidents/qantas-contact-centre-data-incident-2025/stix.json"
---

# Qantas contact-centre data incident

Phone-based social engineering against an overseas third-party contact centre that connected a Qantas CRM instance to a threat-actor data-extraction tool. Compromise of Qantas customer contact and loyalty-program records stored in the affected CRM platform.

Last modified Aug 9, 2026 · 2 sources

## Summary

- **Environment:** Company report recorded by the regulator; not a universal claim beyond the monitored platform and inquiry period.
- **Operational impact:** No outage or recovery duration quantified
- **Financial impact:** No public cost estimate

## What happened

Phone-based social engineering against an overseas third-party contact centre that connected a [Qantas](https://www.qantas.com/) CRM instance to a threat-actor data-extraction tool. [2](#source-2)

## Impact

Compromise of Qantas customer contact and loyalty-program records stored in the affected CRM platform. [1](#source-1) [2](#source-2)

Documented data types include:

- Names — Customer names; fields varied by record. [1](#source-1) [2](#source-2)
- Contact information — Email addresses, phone numbers, and some residential, business, or hotel addresses; fields varied by record. [1](#source-1) [2](#source-2)
- Dates of birth — Dates of birth in a subset of customer records. [1](#source-1) [2](#source-2)
- Gender information — Gender information in a subset of customer records. [1](#source-1) [2](#source-2)
- Loyalty program information — Qantas Frequent Flyer numbers and, for some records, tier, points balance, and status credits. [1](#source-1) [2](#source-2)
- Demographic information — Meal preferences in a subset of customer records. [1](#source-1) [2](#source-2)

A cited record reports 5,120,000 individuals (Approximate number of Australians affected, as reported by the OAIC; as of 2026-07-16). [1](#source-1) [2](#source-2)

A cited record reports 5,670,000 records (Approximate customer records compromised globally, including overseas customers; records are not necessarily unique people; as of 2026-07-16). [1](#source-1) [2](#source-2)

The agent's authorized CRM instance was connected through legitimate interactions to a data-extraction tool operated by the threat actor. [2](#source-2)

## Timeline

### June 28, 2025 — Activity began

Date the contact-centre agent received the social-engineering call and unauthorized extraction path was established. [2](#source-2)

### June 30, 2025 — Discovery

Date unusual login-attempt alerts were escalated to the Qantas cybersecurity team. [2](#source-2)

### July 2, 2025 — Public disclosure

Date Qantas publicly disclosed the incident. [2](#source-2)

### July 11, 2025 — Activity began

Beginning of the OAIC preliminary-inquiry period. [2](#source-2)

### June 1, 2026 — Documented activity ended

End of the OAIC preliminary-inquiry period. [2](#source-2)

### July 16, 2026 — Documented event

Publication date of the OAIC report. [2](#source-2)

### August 9, 2026 — Briefing updated

This briefing was last reviewed and updated on August 9, 2026.

## Threat Group & Attack Vector

The OAIC reported that the CRM platform did not store credit-card, personal financial, or passport information, and Qantas said passwords, PINs, and login details were not compromised. [2](#source-2)

A caller impersonating Qantas IT deceived an overseas contact-centre agent in a phone-based social-engineering attack, also described as vishing. [2](#source-2)

The compromised CRM platform was used by an overseas contact centre operated by an unnamed third-party provider contracted by Qantas. [2](#source-2)

### Actors

- No threat actor group has been identified in the reviewed public evidence.

### TTPs

- [T1566.004 — Phishing: Spearphishing Voice](https://attack.mitre.org/techniques/T1566/004/) [2](#source-2)

## Response

During the OAIC inquiries, Qantas reported no evidence of further or ongoing threat-actor activity on the CRM platform. The OAIC emphasized that it had not conducted a full Commissioner-initiated investigation, made no concluded findings, and did not present the report as a broader endorsement of Qantas's compliance. The OAIC closed its preliminary inquiries without commencing a Commissioner-initiated investigation or taking other regulatory action at that time because the available evidence did not point toward a likely APP contravention warranting further investigation. Qantas activated crisis management, engaged legal and forensic specialists, and provided additional social-engineering training after the incident. On or around 9 July 2025, Qantas notified impacted customers of the specific categories of personal information involved. On 30 June 2025, Qantas froze and revoked access to the associated account, securing the CRM platform and triggering incident-response processes. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [2](#source-2)

## Assets

[Download the case-scoped STIX 2.1 bundle](<https://www.ally.security/incidents/qantas-contact-centre-data-incident-2025/stix.json>)

## Sources

Primary source records used to research this incident.

<a id="source-1"></a>

### Qantas cyber incident

official · Qantas Airways Limited

<https://agencyconnect.qantas.com/en/news/jul-2025/qantas-cyber-incident>

<a id="source-2"></a>

### Report into preliminary inquiries of Qantas

regulatory · Office of the Australian Information Commissioner · Jul 16, 2026

<https://www.oaic.gov.au/privacy/privacy-assessments-and-decisions/privacy-decisions/Investigation-inquiry-reports/report-into-preliminary-inquiries-of-qantas>

<details>
<summary>Evidence ledger</summary>

Review the supporting structured claims.

1. **Resulted In · 100% confidence · current**  
   June 2025 Qantas contact-centre compromise: The agent's authorized CRM instance was connected through legitimate interactions to a data-extraction tool operated by the threat actor.
2. **Exposed Data Category · 100% confidence · current**  
   Qantas customer CRM data exposure: Names
3. **Resulted In · 100% confidence · current**  
   June 2025 Qantas contact-centre compromise: During the OAIC inquiries, Qantas reported no evidence of further or ongoing threat-actor activity on the CRM platform.
4. **Resulted In · 100% confidence · current**  
   Qantas customer CRM data exposure: The OAIC reported that the CRM platform did not store credit-card, personal financial, or passport information, and Qantas said passwords, PINs, and login details were not compromised.
5. **Affected Organization · 100% confidence · current**  
   June 2025 Qantas contact-centre compromise: Qantas Airways Limited
6. **Exposed Data Category · 100% confidence · current**  
   Qantas customer CRM data exposure: Contact information
7. **Resulted In · 100% confidence · current**  
   OAIC preliminary inquiries into Qantas: The OAIC emphasized that it had not conducted a full Commissioner-initiated investigation, made no concluded findings, and did not present the report as a broader endorsement of Qantas's compliance.
8. **Affected Individual Count · 100% confidence · current**  
   Qantas customer CRM data exposure: 5,120,000 individual
9. **Used Attack Technique · 95% confidence · current**  
   June 2025 Qantas contact-centre compromise: https://attack.mitre.org/techniques/T1566/004/
10. **Began At · 100% confidence · current**  
   June 2025 Qantas contact-centre compromise: 2025-06-28
11. **Exposed Data Category · 100% confidence · current**  
   Qantas customer CRM data exposure: Dates of birth
12. **Exposed Data Category · 100% confidence · current**  
   Qantas customer CRM data exposure: Gender information
13. **Resulted In · 100% confidence · current**  
   June 2025 Qantas contact-centre compromise: A caller impersonating Qantas IT deceived an overseas contact-centre agent in a phone-based social-engineering attack, also described as vishing.
14. **Disclosed At · 100% confidence · current**  
   June 2025 Qantas contact-centre compromise: 2025-07-02
15. **Began At · 100% confidence · current**  
   OAIC preliminary inquiries into Qantas: 2025-07-11
16. **Exposed Data Category · 100% confidence · current**  
   Qantas customer CRM data exposure: Loyalty program information
17. **Resulted In · 100% confidence · current**  
   June 2025 Qantas contact-centre compromise: Qantas customer CRM data exposure
18. **Resulted In · 100% confidence · current**  
   OAIC preliminary inquiries into Qantas: The OAIC closed its preliminary inquiries without commencing a Commissioner-initiated investigation or taking other regulatory action at that time because the available evidence did not point toward a likely APP contravention warranting further investigation.
19. **Exposed Record Count · 100% confidence · current**  
   Qantas customer CRM data exposure: 5,670,000 record
20. **Discovered At · 100% confidence · current**  
   June 2025 Qantas contact-centre compromise: 2025-06-30
21. **Resulted In · 100% confidence · current**  
   June 2025 Qantas contact-centre compromise: Qantas activated crisis management, engaged legal and forensic specialists, and provided additional social-engineering training after the incident.
22. **Ended At · 100% confidence · current**  
   OAIC preliminary inquiries into Qantas: 2026-06-01
23. **Affected Organization · 100% confidence · current**  
   OAIC preliminary inquiries into Qantas: Qantas Airways Limited
24. **Exposed Data Category · 100% confidence · current**  
   Qantas customer CRM data exposure: Demographic information
25. **Resulted In · 100% confidence · current**  
   June 2025 Qantas contact-centre compromise: The compromised CRM platform was used by an overseas contact centre operated by an unnamed third-party provider contracted by Qantas.
26. **Resulted In · 100% confidence · current**  
   Qantas impacted-customer notifications: On or around 9 July 2025, Qantas notified impacted customers of the specific categories of personal information involved.
27. **Occurred At · 100% confidence · current**  
   OAIC preliminary inquiries into Qantas: 2026-07-16
28. **Resulted In · 100% confidence · current**  
   June 2025 Qantas contact-centre compromise: On 30 June 2025, Qantas froze and revoked access to the associated account, securing the CRM platform and triggering incident-response processes.
29. **Resulted In · 100% confidence · current**  
   June 2025 Qantas contact-centre compromise: Qantas impacted-customer notifications

</details>
