Tech Support Scam Caused Massive Data Breach at Qantas

Find out how a tech support scam led to the leak of 5.7M data at Qantas and why the airline wasn't sanctioned.

viernes, 17 de julio de 2026 • 5 min read • Q2BSTUDIO Team

Qantas did not breach privacy despite data breach

The recent massive data breach incident at Australian airline Qantas, which occurred in 2025, has once again put on the table the fragility of business defenses against social engineering attacks. According to the Australian Privacy Commissioner's report, the origin was a tech support scam — a vishing attack — in which a cybercriminal posed as IT staff from the airline itself to trick a contact center agent. The breach exposed the personal information of 5.7 million customers, however, the regulator determined that Qantas did not breach its privacy obligations because it had implemented audits, role-based access controls, and regular training. This case, far from being an anomaly, represents a wake-up call for all organizations that handle sensitive data: technology alone is not enough if the human factor continues to be the weakest link.

The attackers' strategy was meticulous. They called the contact center claiming to belong to the Qantas support team and asked the agent to access the CRM system to close a ticket. In reality, that action connected the CRM to a data extraction tool that the criminals used to steal customer records. This type of attack demonstrates that even the most robust technical measures—such as role-based access controls—can be circumvented if an employee, relying on the identity of the interlocutor, executes actions that compromise security. The lesson is clear: cybersecurity is not only a problem of firewalls and encryption, but also of processes, organizational culture, and continuous training.

For companies looking to protect against similar threats, it's critical to take a comprehensive approach that combines technology, processes, and people. In this context, tools such as AI agents for companies are revolutionizing the detection of anomalous behavior in real time. An AI system can analyze call patterns, identify suspicious voice tones, or alert on unusual requests for access to critical systems. In addition, the implementation of properly configured AWS and Azure cloud services offers additional layers of security through identity policies, continuous monitoring, and incident response automation.

The Commissioner's report also highlighted that Qantas had conducted regular contact center operator audits and security awareness tests months before the incident. However, the question that arises is: were those tests sufficiently specific against vishing tactics? Many organizations still focus on email phishing simulations, neglecting phone attacks. Here, the role of a specialized cybersecurity consultancy is invaluable. A pentesting service, such as the one offered by Q2BSTUDIO, makes it possible to identify vulnerabilities in human and technical processes, as well as recommend specific improvements in the infrastructure.

Beyond regulatory compliance, the Qantas leak underscores the importance of designing bespoke applications that integrate security controls from the ground up. Tailored software can include approval workflows for critical actions, contextual multi-factor authentication, and detailed audit trails. This way, even if an employee is misled, the system may require a second authorization or block the action if it detects unusual behavior. Software customization allows security to be tailored to the specific risks of each business, something that generic solutions rarely achieve.

Another relevant aspect is data management. Qantas stated that it carried out annual deletions of outdated records in its CRM, and that at the time of the attack there was no data pending deletion. However, the massive volume of personal information stored — even if it's necessary — represents an attractive target for attackers. Companies should implement stricter data minimization policies, supported by business intelligence tools such as Power BI, which allow visualizing the life cycle of information and detecting unnecessary accumulations. Business intelligence services not only optimize decision-making, but also contribute to data governance by identifying what information can be deleted or anonymized.

The role of artificial intelligence in preventing this type of fraud cannot be underestimated. AI systems for businesses can analyze call metadata, agent behavior patterns, and correlate events to detect vishing campaigns before they cause harm. In addition, AI agents can act as virtual assistants that verify the identity of callers using dynamic security questions or voice biometrics. Q2BSTUDIO, with its expertise in application development and process automation, offers customized solutions that integrate these capabilities into cloud environments, whether AWS or Azure, ensuring scalability and regulatory compliance.

The Qantas case also leaves a reflection on shared responsibility in the technological supply chain. The contact center operated under the airline's supervision, but the attack showed that access controls and training, while present, were not enough to prevent human error. Companies that outsource critical services must ensure that their suppliers implement security standards equivalent to their own. Here, carrying out technical and process audits, accompanied by a continuous improvement plan, is essential. Services such as cybersecurity and pentesting provided by Q2BSTUDIO help organizations evaluate not only their own infrastructure, but also that of their business partners.

Finally, it is important to note that although the Australian regulator decided not to open a formal investigation, the reputational impact and potential class action lawsuits are already underway. Customer trust is difficult to regain when their personal data has been exposed. Therefore, beyond complying with privacy principles, companies must make security a strategic pillar. Investing in custom applications, artificial intelligence for early threat detection, and well-configured cloud services is not an expense, but an investment that protects the most valuable asset: information.

In conclusion, the Qantas leak proves that no system is foolproof when the human factor is involved. However, by combining continuous training, advanced technology and expert advice, it is possible to significantly reduce the risk. Q2BSTUDIO, as a software and technology development company, helps companies build strong defenses through custom software solutions, AI integration, AWS and Azure cloud services, and business intelligence tools such as Power BI. It's not just about reacting to incidents, it's about anticipating them with a proactive cybersecurity strategy.

OUR SERVICES

How we can help you

Do you have a project in mind?

Tell us your vision and we'll turn it into a software solution. Whatever the scope, we make your idea real.