Qantas Data Breach Started With A Fake IT Support Call
Bitdefender, Thursday, July 16th, 2026
A vishing attack impersonating Qantas IT support exposed 5.67 million customer records, Australia's privacy regulator found.
Bitdefender detailed how an attacker posing as Qantas IT support manipulated an overseas contact center employee into authorizing a malicious data connection during a June 2025 vishing attack.
Roughly 5.67 million customer records were exposed, including names, contact information, and frequent-flyer details, though credit card data and passwords were not compromised.
Australia's privacy regulator found that unusual login-attempt alerts surfaced two days later, prompting Qantas to revoke access and publicly disclose the incident.
The Office of the Australian Information Commissioner closed its preliminary inquiries without opening a formal investigation or taking regulatory action.