Qantas Avoids Investigation Over Data Breach Affecting More Than 5M Australians
Synopsis
The OAIC has decided not to investigate Qantas over its 2025 data breach, saying the airline had reasonable security measures in place despite more than 5.12 million customers being affected.
Key Highlights
- Qantas will not be investigated by the Office of the Australian Information Commissioner (OAIC) over a data breach impacting 5.12 million Australians.
- Qantas likely broke no Australian privacy laws, watchdog says.
- The breach was perpetrated by using social engineering on an offshore call centre employee.
Australia’s privacy watchdog will not formally investigate the data breach that revealed personal information of over 5.12 million Australians, as there was no probable violation of the data protection laws & hence ruled out any chance of Qantas facing a formal investigation for it.
The Office of the Australian Information Commissioner (OAIC) said its initial investigations into whether the airline had complied with Australia’s Privacy Act and Notifiable Data Breaches Scheme did not warrant further regulatory action.
Breach of Private Info Not Likely
Privacy Commissioner Carly Kind admitted the incident was concerning but said there was not enough evidence to show that breaches of Qantas’s privacy obligations were likely.
Although the regulator can still reopen an investigation into Australian airlines later, she said it would be inappropriate for the OAIC to undertake a comprehensive inquiry at this stage. More serious or repeated violations of the Privacy Act may incur penalties greater than A$50 million.
Hack Caused by Social Engineering
The cyberattack occurred in June 2025 when a hacker employed phone-based social engineering to convince an employee at an international call centre to link a Qantas platform with the hacker’s data extraction tool. Customer data was subsequently put on the dark web.
Pre-attack, Qantas had a number of security measures in place, including routine audits of its overseas service provider, cyber and data protection training for contact centre staff and processes to delete or de-identify personal information once it is no longer needed, the OAIC said.
The attack was detected within two days, revoked access from the compromised account, took action by investigating unauthorised activity and activating its incident response procedures. The regulator noted at the same time that there is no indication that the threat actor was still active.
Qantas Strengthens Security
Qantas said it had enhanced system monitoring, increased staff training and implemented further security checks since the event.
Legal experts said the OAIC’s ruling aligned with Australian privacy law which only requires organisations to take reasonable steps to protect personal information, not provide flawless protection. However, the OAIC was not aware of any information that would suggest that Qantas could have reasonably anticipated or prevented the attack.
Source: Information Age
At Inspirepreneurs Magazine, covering entrepreneurship, business failures, and the human stories behind the world's most ambitious founders. She writes at the intersection of strategy and storytelling.
You Might Also Like
Intel Hires Qualcomm Veteran to Lead PC and Physical AI
Australia Central Bank Flags High Inflation as Confidence Drops Sharply