Qantas Avoids Investigation Over Data Breach Affecting More Than 5M Australians

Qantas Avoids Investigation Over Data Breach Affecting More Than 5M Australians

Shivangi
Jul 22, 2026 12:13 PM IST
Category Transport

Synopsis

The OAIC has decided not to investigate Qantas over its 2025 data breach, saying the airline had reasonable security measures in place despite more than 5.12 million customers being affected.

01
Chapter one

Key Highlights

  • Qantas will not be investigated by the Office of the Australian Information Commissioner (OAIC) over a data breach impacting 5.12 million Australians.
  • Qantas likely broke no Australian privacy laws, watchdog says.
  • The breach was perpetrated by using social engineering on an offshore call centre employee.

Australia’s privacy watchdog will not formally investigate the data breach that revealed personal information of over 5.12 million Australians, as there was no probable violation of the data protection laws & hence ruled out any chance of Qantas facing a formal investigation for it.

The Office of the Australian Information Commissioner (OAIC) said its initial investigations into whether the airline had complied with Australia’s Privacy Act and Notifiable Data Breaches Scheme did not warrant further regulatory action.

02
Chapter two

Breach of Private Info Not Likely

Privacy Commissioner Carly Kind admitted the incident was concerning but said there was not enough evidence to show that breaches of Qantas’s privacy obligations were likely.

Although the regulator can still reopen an investigation into Australian airlines later, she said it would be inappropriate for the OAIC to undertake a comprehensive inquiry at this stage. More serious or repeated violations of the Privacy Act may incur penalties greater than A$50 million.

03
Chapter three

Hack Caused by Social Engineering

The cyberattack occurred in June 2025 when a hacker employed phone-based social engineering to convince an employee at an international call centre to link a Qantas platform with the hacker’s data extraction tool. Customer data was subsequently put on the dark web.

Pre-attack, Qantas had a number of security measures in place, including routine audits of its overseas service provider, cyber and data protection training for contact centre staff and processes to delete or de-identify personal information once it is no longer needed, the OAIC said.

The attack was detected within two days, revoked access from the compromised account, took action by investigating unauthorised activity and activating its incident response procedures. The regulator noted at the same time that there is no indication that the threat actor was still active.

04
Chapter four

Qantas Strengthens Security

Qantas said it had enhanced system monitoring, increased staff training and implemented further security checks since the event.

Legal experts said the OAIC’s ruling aligned with Australian privacy law which only requires organisations to take reasonable steps to protect personal information, not provide flawless protection. However, the OAIC was not aware of any information that would suggest that Qantas could have reasonably anticipated or prevented the attack.

Source: Information Age


Written by Shivangi

At Inspirepreneurs Magazine, covering entrepreneurship, business failures, and the human stories behind the world's most ambitious founders. She writes at the intersection of strategy and storytelling.