INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Qantas suffers massive data breach from tech support scam attack

| 2026-07-16 06:27 CRITICAL MEDIUM DATA BREACH PHISHING & SOCIAL ENGINEERING CRITICAL INFRASTRUCTURE & OT
Executive Summary
AI-generated
A massive data breach at Australian airline Qantas occurred in 2025, resulting in the leak of personally identifiable information for approximately 5.7 million customers. The attack was attributed to a tech support scam, where an individual claiming to represent "Qantas IT help" tricked a contact center agent into accessing a CRM system and performing actions that connected it to a data extraction tool, allowing the attackers to siphon off customer records. The Australian Privacy Commissioner found that Qantas did not breach its privacy obligations despite leaking PII, as the airline had taken adequate steps to protect personal information from unauthorized access through role-based access controls and other techniques. However, the Commissioner noted that the threat actor gained access through a vishing attack, which could not have been prevented by strengthening existing security measures.
Technical Mitigations AI-generated
• User Training (ATT&CK mitigation for Social Engineering): Reduces success of phishing/vishing/impersonation and modern “human interface” lures. • Audit (ATT&CK mitigation for Social Engineering): Enables correlation of email/identity/SaaS/endpoint activity that appears legitimate. • Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Scattered SpiderScattered Spider
Target & Sectors
FIVE_EYES FIVE_EYES aviationaviation
Incident Timeline
‎2026/07/16
Threat actors, identified as the Scattered Spider gang, used a tech support scam to target Qantas' contact center and breach customer data.
victims 5.7 customers
threat_actor Scattered Spider
Tactical Metrics
Metrics
victims
5,700,000
Customers
Intelligence Sources
The Register - Cybercrime 2026-07-16