All About Cookies is an independent, advertising-supported website. Some of the offers that appear on this site are from third-party advertisers from which All About Cookies receives compensation. This compensation may impact how and where products appear on this site (including, for example, the order in which they appear).
All About Cookies does not include all financial or credit offers that might be available to consumers nor do we include all companies or all available products. Information is accurate as of the publishing date and has not been provided or endorsed by the advertiser.
The All About Cookies editorial team strives to provide accurate, in-depth information and reviews to help you, our reader, make online privacy decisions with confidence. Here's what you can expect from us:
- All About Cookies makes money when you click the links on our site to some of the products and offers that we mention. These partnerships do not influence our opinions or recommendations. Read more about how we make money.
- Partners are not able to review or request changes to our content except for compliance reasons.
- We aim to make sure everything on our site is up-to-date and accurate as of the publishing date, but we cannot guarantee we haven't missed something. It's your responsibility to double-check all information before making any decision. If you spot something that looks wrong, please let us know.
Despite personally identifiable information such as names, phone numbers, and email addresses of 5.67 million customers being exposed, Qantas will not face a Commissioner-Initiated Investigation (CII) over the matter.
This news comes after the Office of the Australian Information Commissioner (OAIC) published its preliminary investigation report[1] into the Qantas data breach.
Unfortunately for affected customers, that means they likely won't receive any monetary compensation. Moreover, they’ll need to take preventive measures to protect themselves against follow-up scams that could result from their exposed data.
Here’s how the data breach happened, why Qantas dodged billions of dollars in potential penalties, and the steps you can take now to protect yourself.
What customer data was exposed
Why will Qantas face no investigation
What can you do to protect yourself
Bottom line
How did the Qantas data breach happen
As outlined in the report, Qantas’s data breach was the result of a social engineering vishing (voice phishing) scam. Here’s how it unfolded:
- An agent employed at an overseas contact center run by a third-party provider received a call from a malicious third party impersonating Qantas IT Help.
- The caller guided the agent to the Salesforce CRM platform on the pretext of closing an IT support ticket.
- The agent was led to the Salesforce Connected App Setup page, where the attacker convinced them to link a modified version of Salesforce's own Data Loader utility, controlled by the attacker, as a trusted connected app.
- The attacker then used the tool to run bulk queries using the Salesforce API. This was possible because the agent had broad permissions to view the contact profiles of all Qantas customers.
As is often the case with social engineering attacks, there was no complex hacking involved. The attack involved no password theft or session hijacking, as the trusted app connection was correctly authorized by the agent themselves.
What customer data was exposed
The data breach resulted in the breach of approximately 5.67 million customer records, including those of overseas customers. Out of these, for approximately 4 million records, the following information was compromised:
- Names
- Phone numbers
- Email addresses
- Qantas Frequent Flyer details
For another 1.7 million customer records, additional information such as residential or business addresses, gender, meal preferences, and dates of birth was also compromised.
However, to Qantas flyers’ relief, no personal financial information, credit card details, or passport details were breached, as they were not stored on the CRM platform in the first place. Additionally, no customer passwords, login credentials, or PIN details were stolen.
Still, the information that was exposed can be enough for cybercriminals to launch targeted phishing attacks against you, like the one that led to the Qantas breach.
Attackers may impersonate trusted organizations to trick you into clicking malicious links or entering sensitive information on fake websites. They can then use the stolen information to facilitate identity theft or financial fraud, such as opening new lines of credit in your name.
Why will Qantas face no investigation
The preliminary investigation looked into Qantas’s compliance with the Australian Privacy Principles (APP) — a core set of rules under the Australian Privacy Act 1988 that govern how organizations should handle personal information, covering matters such as data collection, use, storage, security, and its destruction.
While there are a total of 13 APPs, only three were relevant to the Qantas situation:
- APP 1: Requires organizations to be able to handle privacy-related inquiries or complaints
- APP 8: Governs the cross-border disclosure of personal information
- APP 11: Covers the security of personal information, including preventing unauthorized access and de-identifying personal information when it is no longer needed.
The OAIC said that the information obtained during its preliminary inquiries did not suggest that Qantas had violated any of these APPs in a way that warranted a further investigation.
According to OAIC’s report, Qantas couldn’t be held responsible because:
- Mandatory training was already in place: Qantas already had mandatory training programs for its overseas contact center staff, which included regular cyber awareness online training courses. However, most social engineering training focuses on making employees aware of credential theft rather than suspicious interactions.
- Adequate overseas information disclosure compliance: Qantas’s agreement with the overseas contact center provider required compliance with ISO 27001:2013, along with audit rights for Qantas. The OAIC didn’t find any omission that, if fixed, would have prevented the breach, as adequate cross-border safeguards under APP 8 had been adhered to.
- Access control policies couldn’t have prevented the attack: The root cause of the attack can be pinned down to Salesforce’s default configuration, which allowed any end user to authorize a third-party application connection. In this case, even role-based access control wouldn’t have helped, as any employee could legitimately connect a third-party app to the Salesforce CRM application. Salesforce has since fixed this loophole, and now only admins can authorize such third-party app connections.
- Sufficient de-identification policies: Qantas’s information retention policy states that it must de-identify customers’ personal information that’s older than seven years if there’s no legal or business need for its retention. The OAIC found the airline to be in compliance and said that Qantas had removed the required customer data from its CRM platform both before and after the breach.
- Adequate post-incident response: Qantas acted swiftly once the breach was identified. It froze the compromised account and engaged legal and forensic experts to assess the extent of the data exfiltration. It also promptly triggered its incident response process and disclosed the breach publicly within days. Additionally, the airline rolled out new social engineering-specific training for its employees after the incident.
It's worth noting, however, that this isn't a final clean chit for the airline, as the OAIC can still commence an investigation at a later date.
What can you do to protect yourself
Even though Qantas carries over 1 million passengers every week — meaning your chances of being one of the 5.6 million customers impacted are slim — it's best not to be complacent about your digital privacy.
- Avoid clicking on unsolicited links or respond to urgent-looking requests. These could be phishing attacks designed to steal your banking logins or other personal information.
- Monitor your Qantas account for any unusual activity, such as unauthorized redemptions or points transfers. The airline also offers two-factor authentication for all Qantas and Frequent Flyer accounts. It adds an extra layer of protection by requiring a second temporary code in addition to your password when you log in.
- Consider contacting Qantas directly. Following the data breach, the airline established a dedicated 24/7 support line to provide specialist identity protection advice and resources. You can use it to confirm whether your details were compromised or report any attempted scams following the incident. Contact details: 1800 971 541 (within Australia) or +61 2 8028 0534 (outside Australia).
- Use an identity theft protection service. Even though the risk of account takeovers and financial fraud is low in this case, it's still worth considering an identity theft protection service for the next few months. It can help you monitor your digital privacy and immediately alert you if your sensitive information is leaked online.
- Report suspicious messages and scams. If you receive any suspicious messages or have become a victim of a cyber scam, report the incident to Scamwatch — a public phishing and scam reporting service run by the National Anti-Scam Centre — or ReportCyber, the official law enforcement cybercrime reporting portal run by the Australian Signals Directorate’s Australian Cyber Security Centre (ACSC).
Bottom line
The Qantas data breach paints a grim picture of today's data privacy landscape, showing that even if an organization has the required security systems and employee training in place, a single crack can still result in a massive data leak.
It also highlights the importance of staying on top of your digital privacy. In this case, affected customers won't be receiving any compensation, at least for now, as the OAIC found no evidence that Qantas had breached its privacy obligations in a way that warranted a formal investigation.
What affected customers can do, however, is take proactive steps to ensure their exposed information isn't used to facilitate further scams. This includes being cautious of phishing links, contacting Qantas's dedicated support line if they have any concerns, reporting scams to the appropriate authorities, and strengthening their digital privacy with third-party tools such as an identity theft protection service.