Don't pay so you can read it. Pay so everyone can!

Don't pay so you can read it.
Pay so everyone can!

Qantas off the hook for data breach they could have seen coming

by | Sep 26, 2026 | Business, Latest Posts

The Medicare data breach raises questions over why Qantas got away with a data breach affecting millions of customers. Cybersecurity researcher Benjamin Mossé reports.

In October last year, hackers leaked over 5 million Qantas customer records into the dark web after the company refused to pay the ransom demanded.

The data had been stolen from their customer-management system (a Salesforce database) and included contact details, birth dates and frequent flyer numbers, but not credit card or passport details.

The Office of the Australian Information Commissioner (OAIC), spent almost a year making preliminary inquiries into the breach, until Privacy Commissioner Carly Kind announced in July that the regulator would not open a formal investigation.

The OAIC said the material it had examined did not indicate Qantas had failed to take reasonable steps to protect customer information. It also praised the airline’s response once the breach was detected, including shutting down access, bringing in forensic specialists and notifying affected customers.

The OAIC also said it did not appear Qantas could reasonably have anticipated and prevented the attack in the form it took. However, that sits uneasily with what was already publicly known before the breach.

More than three months before the Qantas incident, Salesforce published a security warning about criminals impersonating IT support staff over the phone.

Hack probed with warnings it’s ‘too late’ to contain AI

It began with a phone call.

An attacker rang an employee at an overseas call centre used by Qantas and pretended to be from IT support. The employee was persuaded to follow instructions that ultimately gave the attacker access to a system containing customer information.

As Salesforce had warned, attackers were persuading employees to approve malicious applications which could then be used to steal company data. It specifically warned about modified versions of a tool called Data Loader, and recommended restricting access to connected applications, limiting who could use bulk data tools, imposing network restrictions and monitoring large downloads.

Then, just 24 days before the Qantas breach, Google’s Threat Intelligence Group published details of a campaign using essentially the same broad method.

Google described financially motivated attackers phoning employees, pretending to be IT support and persuading them to connect attacker-controlled applications to Salesforce systems. Once connected, those applications could be used to extract large volumes of data.

Google also recommended tighter controls over applications, user permissions and large data exports.

Did Qantas ignore the warnings?

None of this proves Qantas broke the law. Nor does it prove that any one of the recommended safeguards would definitely have stopped the attack. That distinction matters.

The legal question is not whether a company can guarantee that hackers will never get in. It is

whether it took reasonable steps

to protect the personal information it held, considering the risks it faced.

And that is where the OAIC’s reasoning becomes difficult to assess from the outside.

After the regulator released its report, I asked whether the publicly available Salesforce and Google warnings had been specifically considered during its inquiries.

I later lodged a Freedom of Information request seeking documents showing whether those warnings, or comparable intelligence about such attacks, had been put to Qantas.

The OAIC said no documents matching the request could be found or did not exist.

It also said its investigators had discussed Qantas’s awareness of security risks more generally when assessing its obligations under Australian Privacy Principle 11.

That does not establish that the regulator ignored the warnings, but it poses the question of how the existence of closely similar attacks — documented before millions of Qantas records were stolen — was weighed against the conclusion that the breach could not reasonably have been foreseen and prevented.

The distinction is important because this case reaches well beyond one airline.

A foreseeable risk

Australian companies and Government agencies such as Medicare hold enormous quantities of personal information, often in platforms operated by third parties. Criminal groups are constantly changing how they get at that information. They do not always defeat complicated security systems. In some cases,

they simply persuade a person with legitimate access to open the door.

Regulators therefore need to look not only at whether a company followed standard procedures, delivered staff training or responded quickly after an intrusion.

They also need to ask whether organisations were paying attention to warnings about the attacks occurring around them at the time and against the software they use.

The OAIC stresses that its Qantas process was only a preliminary inquiry, not a full investigation, and that its report should not be read as a general endorsement of the airline’s privacy practices. Complaints relating to the breach also remain separate from that decision.

The question remains: if an attack method has already been publicly documented, and the impacted software provider has itself warned about it and published practical countermeasures, then at what point does an “unforeseeable” cyber-attack become one that should have been foreseen?

Palantir. All seeing, all knowing. Inspired by Sauron

Benjamin Mosse

Benjamin Mossé is a cybersecurity expert, entrepreneur and independent researcher with more than 20 years’ experience. He investigates cybersecurity policy, regulation, public spending and industry claims.

Don't pay so you can read it. Pay so everyone can!

Don't pay so you can read it.
Pay so everyone can!

Pin It on Pinterest

Share This