October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run ScanOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

Qantas customer data exposed in contact-centre breach: what happened and what to do

A vishing attack on an overseas Qantas contact-centre employee exposed approximately 5.67 million records. Here is what data was involved, what was not stored, and what customers should do after the OAIC’s July 2026 decision.
From TheFinanceBase Team6 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Yes—the Qantas breach was real. In 2025, a criminal used phone-based social engineering to manipulate an employee at an overseas third-party contact centre, then extracted customer records from the CRM session the employee was authorised to use. The OAIC’s July 2026 report puts the compromised total at approximately 5.67 million records, including about 5.12 million Australians. The information varied by record. Qantas and the OAIC say the platform did not store passwords, PINs, login credentials, credit-card details, personal financial information or passport details.

The OAIC closed preliminary inquiries on July 16, 2026 without opening a Commissioner-initiated investigation or taking regulatory action at that stage. That was not a blanket finding that Qantas had never breached privacy obligations; individual and representative complaints remained relevant.

What happened in the Qantas breach?

According to the OAIC report, the incident began on Saturday, June 28, 2025. Someone impersonating Qantas IT called an employee at an overseas contact centre and directed the employee to a website associated with the customer-relationship-management (CRM) platform. The employee was told to perform steps supposedly needed to close an IT ticket.

Those steps connected the employee’s legitimate CRM session to an attacker-controlled data-extraction tool. The attacker then accessed customer profiles available to that employee. This was an authorised-user abuse scenario caused by “vishing” (voice phishing), rather than a disclosed intrusion directly through Qantas’ airline-operating systems.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Sale
Password Safe
  • Requires 3 "AAA" batteries (included)
  • Unit auto-locks for 30 minutes after 5 consecutive incorrect PINs

Qantas detected unusual login activity on June 30, revoked the relevant access and secured the platform. It publicly disclosed the incident on July 2 and began notifying affected customers about their specific data categories from around July 9.

Timeline

Date Event
June 28, 2025 An attacker allegedly deceived a contact-centre employee by phone and connected the employee’s CRM session to a malicious extraction tool.
June 30, 2025 Qantas detected unusual login activity, revoked access and began forensic analysis.
July 2, 2025 Qantas publicly announced the incident and notified relevant Australian agencies.
Around July 9, 2025 Customer notifications began, identifying the categories involved for each person.
July 11, 2025–June 1, 2026 The OAIC conducted preliminary inquiries under section 42(2) of the Privacy Act.
July 16, 2026 The OAIC published its report and closed those preliminary inquiries without commencing a Commissioner-initiated investigation.

How many records were compromised?

Qantas initially said the third-party platform held service records for about 6 million customers in its July 2, 2025 ASX announcement. The later OAIC assessment refined the number to approximately 5.67 million compromised customer records, including overseas records, of which about 5.12 million related to Australians.

These are records, not necessarily a one-to-one count of unique people. A customer can have more than one record or email address, so the figures should not be read as an exact headcount.

What information was exposed?

The records were not uniform. The OAIC identified two broad groups:

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
Atlancube PasswordPocket Offline Hardware Password Keeper with Bluetooth Auto-Fill for iPhone and Android, Stores 1,000 Logins, Military-Grade AES-256 Encryption (Black)
  • Auto-Fill Feature: Say goodbye to the hassle of manually entering passwords! PasswordPocket automatically fills in your credentials with just a single click.
  • Internet-Free Data Protection: Use Bluetooth as the communication medium with your device. Eliminating the need to access the internet and reducing the risk of unauthorized access.
  • Military-Grade Encryption: Utilizes advanced encryption techniques to safeguard your sensitive information, providing you with enhanced privacy and security.
  • Offline Account Management: Store up to 1,000 sets of account credentials in PasswordPocket.
  • Support for Multiple Platforms: PasswordPocket works seamlessly across multiple platforms, including iOS and Android mobile phones and tablets.
Approximate records Information that could be present
4 million Name, email address, phone number and Qantas Frequent Flyer information, including number, tier, points balance and status credits.
1.7 million other records Some or all of the above, plus one or more of residential or business addresses, a hotel address used for misplaced-baggage delivery, date of birth, gender and meal preferences.

Your own Qantas notification is the authoritative description of what was associated with your record. A headline listing every category would incorrectly suggest that all affected customers had the same information exposed.

What was not stored on the compromised platform?

The OAIC report says the CRM platform did not store:

  • Credit-card details
  • Personal financial information
  • Passport details

Qantas also advised the OAIC that customer passwords, PINs and login details were not accessed or compromised. That reduces the risk of direct credential theft, but it does not eliminate phishing, impersonation or loyalty-account fraud. Contact details, dates of birth, addresses and Frequent Flyer data can make a scammer’s story more convincing.

Was Qantas’ main airline system hacked?

The documented compromise involved a third-party CRM system used by one Qantas contact centre. Qantas’ initial announcement reported no impact to airline operations or safety, and the OAIC described the affected environment as the contact-centre platform. That does not prove that every Qantas system was immune to risk; it means the identified incident was confined to the described customer-servicing environment, with the sensitive categories above reportedly absent from it.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Sale
Elegant Password Book with Alphabetical Tabs - Hardcover Password Book for Internet Website Address Login - 5.2" x 7.6" Password Keeper and Organizer w/Notes Section & Back Pocket (Turquoise)
  • NEVER FORGET A PASSWORD AGAIN: Almost every App. has a password, it is almost impossible to remember all the password log in details. This password book is specifically designed to help you create secure passwords and store all your passwords safely in one place. You will never forget your password log-in details again with this password keeper.
  • ALPHABETICAL A-Z TABS FOR QUICK ACCESS: Alphabetical tabs design allows you to store your passwords alphabetically so you can find what you want faster, no more annoying searches!
  • ANONYMOUS WITHOUT ANY TITLE: On the outside, this password notebook organizer looks just like those writing journals, there is no title listed on the cover, so no one would know it's a password book. But we still recommend keeping the internet password logbook in a safe place such as a locked drawer or a shelf full of books.
  • THICK NO-BLEED PAPER: This 5.2" x 7.6" password book contains 74 sheets of thick 120gsm paper that resists ink smearing, say goodbye to those cheap password books that bleed ink!
  • PREMIUM QUALITY & PERFECT MEDIUM SIZE: This password journal comes with a high-quality leatherette hardcover, an elastic band, pen holder, ribbon bookmarker, and inner accordion pocket. It measures 5.2 inches wide and 7.6 inches long, which is the perfect size for your needs.

What did Qantas do?

  • Froze the account associated with the unusual access and secured the CRM platform.
  • Reviewed logs and the extraction activity with legal, forensic and cybersecurity specialists.
  • Notified the OAIC, Australian Cyber Security Centre, National Cyber Security Coordinator and Australian Federal Police.
  • Contacted affected customers about the data categories involved.
  • Provided a dedicated 24/7 support line and referred impacted people to specialist identity-protection services.
  • Added social-engineering training for contact-centre staff.

The OAIC said Qantas identified and escalated the incident promptly. During its inquiries, Qantas reported no evidence of continuing threat-actor activity. That does not mean exposed information can be recovered or that future scams are impossible.

What did the OAIC decide in July 2026?

The OAIC conducted preliminary inquiries, not a full Commissioner-initiated investigation. It said the evidence did not indicate a likelihood that Qantas had failed to take reasonable steps to protect personal information or to ensure its overseas provider complied with the Australian Privacy Principles. The preliminary inquiries therefore closed without further regulatory action at that stage.

The OAIC considered Qantas’ provider audits, cyber-awareness and privacy training, role-based access controls, incident-management processes, and retention, destruction and de-identification practices. It also noted a CRM default that allowed an end user to authorise a third-party application connection; the software provider subsequently changed that configuration for all customers.

This was not a blanket exoneration. The OAIC said the report did not endorse all Qantas practices or assure broader compliance, and that complaints could still be considered. The result could also differ if later information justified further action.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #4
Clever Fox Password Book with Alphabetical Tabs, 4"x5.5" Keeper Black
  • NEVER FORGET A PASSWORD AGAIN - Clever Fox password journal will help you create secure passwords and keep them safe and organized. This password book allows you to store all your passwords and other computer information in one place to find it easily.
  • ALPHABETICAL A-Z TABS - Alphabetic tab system makes it easy to find any password you need. The book also has sections for most important passwords, wireless & email settings, software license information & additional notes.
  • ELEGANT, SMART, PRACTICAL & SECURE PASSWORD ORGANIZATION - This password keeper book has been designed to be anonymous without an obvious title on the cover. For added security there is space to write hints instead of the password itself.
  • POCKET SIZE & PREMIUM QUALITY - This internet address and password logbook with tabs comes in pocket size (4.0x5.5 inches). The password notebook has an eco-leahter hardcover, elastic band, pen loop, bookmark, pocket for notes, and thick 120gsm paper.
  • 60-DAY MONEY-BACK GUARANTEE - We will exchange or refund your password organizer if you aren’t satisfied with your password organization for any reason. Reach out to us via message to refund your internet password logbook.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What affected customers should do now

1. Check your individual notification

Do not assume that another customer’s list of exposed fields applies to you. Use the notification sent by Qantas or contact its official incident support page through a channel you find independently.

2. Secure your Frequent Flyer account

  1. Sign in only through the official Qantas website or app.
  2. Change any password reused on another service, replacing it with a unique, long password.
  3. Enable available multi-factor authentication or a passkey.
  4. Review profile details, contact information, recent activity, points and redemptions.
  5. Contact Qantas through an official channel if anything changed without your permission.

Qantas’ member-account security guidance warns that criminals may target loyalty accounts and attempt to bypass two-factor authentication through phone-number takeover or social engineering.

3. Expect convincing impersonation attempts

Be cautious with calls, emails and texts referring to a booking, points balance, refund or account problem. Qantas says it will not ask for your password, booking-reference details or sensitive login information; independently verify any contact and never disclose a one-time code to a caller.

4. Respond proportionately to identity risk

If your notification included a date of birth, address or other identity attributes, watch for identity-verification requests involving travel, banking, telecommunications or government services. Contact banks or mobile providers using independently sourced numbers if suspicious activity appears. The OAIC’s cyber-incident guidance identifies IDCARE as a source of identity and cyber-support advice.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
RecZone LLC Password Safe Electronic Storage Organizer Keeper Device and Stylus Bundle
  • Securely Remember All Your Passwords, Log-in's, User Names, ATM PIN Numbers and More
  • Large Back-lit LCD Screen, QWERTY Keyboard - So Easy to Use
  • Enter one PIN number and have access to 400 accounts. Search function included.
  • Unit auto locks for 30 minutes after 5 consecutive incorrect PIN attempts
  • Includes mini stylus for easier keypad entry

Because the compromised platform reportedly did not contain payment-card or passport details, do not automatically cancel every card or replace identity documents solely because of this incident. Take those steps when your notification, a separate event or your institution indicates a specific risk.

5. Complain through the proper channel

If you want a formal privacy response, complain to Qantas first and give it an opportunity to respond. If the matter remains unresolved, the OAIC’s guidance on the incident explains the next complaint route.

What businesses can learn from the incident

  • Third-party access requires continuous oversight, not just contract reviews.
  • Training should cover vishing and malicious integration approvals, not only password theft.
  • CRM and OAuth-style connection defaults should require strong approval controls and monitoring.
  • Least-privilege permissions, extraction alerts and rapid log review can limit authorised-user abuse.
  • Retention, destruction and de-identification reduce the amount available when an account is misused.

What remains unresolved?

The OAIC’s preliminary process did not decide every possible privacy question. Later individual or representative complaints could produce further findings. The publicly available material also does not establish whether the extracted data was publicly released, nor whether a particular customer’s later fraud was caused by this incident. Those questions should not be treated as settled without authoritative evidence.

Quick Recap

SaleBestseller No. 1
Password Safe
Password Safe
Requires 3 "AAA" batteries (included); Unit auto-locks for 30 minutes after 5 consecutive incorrect PINs
$30.95
Bestseller No. 5
RecZone LLC Password Safe Electronic Storage Organizer Keeper Device and Stylus Bundle
RecZone LLC Password Safe Electronic Storage Organizer Keeper Device and Stylus Bundle
Securely Remember All Your Passwords, Log-in's, User Names, ATM PIN Numbers and More; Large Back-lit LCD Screen, QWERTY Keyboard - So Easy to Use
$37.84

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase07 MAR 2625 minWhat Is a 457 Plan?
  2. The Money DeskBlogTheFinanceBase07 MAR 2621 minTime Value of Money: What It Is and How It Works
  3. The Money DeskBlogTheFinanceBase07 MAR 2627 minAre You Living in One of These Top 10 Most Expensive Cities to Retire?
Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.