惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

爱范儿
爱范儿
大猫的无限游戏
大猫的无限游戏
WordPress大学
WordPress大学
C
Cyber Attacks, Cyber Crime and Cyber Security
D
DataBreaches.Net
G
Google Developers Blog
博客园 - Franky
V
V2EX
博客园 - 叶小钗
D
Docker
The GitHub Blog
The GitHub Blog
Microsoft Security Blog
Microsoft Security Blog
博客园 - 【当耐特】
H
Hackread – Cybersecurity News, Data Breaches, AI and More
B
Blog RSS Feed
月光博客
月光博客
M
MIT News - Artificial intelligence
F
Fortinet All Blogs
Microsoft Azure Blog
Microsoft Azure Blog
人人都是产品经理
人人都是产品经理
IT之家
IT之家
Google DeepMind News
Google DeepMind News
Apple Machine Learning Research
Apple Machine Learning Research
V
Visual Studio Blog
博客园 - 司徒正美
Stack Overflow Blog
Stack Overflow Blog
罗磊的独立博客
J
Java Code Geeks
U
Unit 42
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
博客园 - 聂微东
T
Tailwind CSS Blog
T
The Blog of Author Tim Ferriss
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Blog — PlanetScale
Blog — PlanetScale
Jina AI
Jina AI
C
Check Point Blog
Y
Y Combinator Blog
MyScale Blog
MyScale Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
阮一峰的网络日志
阮一峰的网络日志
宝玉的分享
宝玉的分享
B
Blog
小众软件
小众软件
云风的 BLOG
云风的 BLOG
I
InfoQ
Recorded Future
Recorded Future
酷 壳 – CoolShell
酷 壳 – CoolShell
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
美团技术团队

Consumer Insights

South Korea diplomatic academy hack exposes diplomat data Credential stuffing attack at Chick-fil-A comes with data breach notice for customers Coca-Cola halts Fairlife production across US after ransomware attack Lidl warns customers after data breach How to find out if your identity has been exposed by infostealers Texas breach exposes PII of 3 million hunting and fishing license customers Maine forced to take down data breach portal after fake notices filed with authorities Carnival breach exposes data of nearly 6 million people 7-Eleven data breach exposes data of 185,000 people UK Water Supplier Fined Nearly £1 Million After Hackers Roamed Networks for Almost 2 Years DAEMON Tools Lite breach prompts urgent update after malware-laced installer Instructure confirms breach; millions of Canvas users potentially impacted Stalkerware data leak exposes private screenshots linked to celebrities and influencers Hackers claim to have breached Udemy, stealing 1.4 million user records Rituals data breach exposes customer details Booking.com says breach exposed travelers’ data Basic-Fit data breach exposes member information across Europe Rockstar Games confirms breach after ShinyHunters leaks stolen analytics data Lapsus$ claims AstraZeneca breach exposes code and credentials Aura data breach exposes 900,000 records after phishing attack Telus Digital data breach confirmed after ShinyHunters claims 1PB theft Was Your Data Exposed in the Latest Under Armour Breach? Here’s What You Should Do Breach at Tinder, Hinge and OkCupid exposes user data Europe Fines Big Tech €1.2 Billion under GDPR in 2025 European Space Agency's cybersecurity in freefall as yet another breach exposes spacecraft and mission data European Space Agency Confirms New Data Breach; Classified Info May Have Been Stolen Rainbow Six Siege Servers Offline After Massive Breach Floods Accounts with Billions of R6 Credits 21,000 Nissan Customers Exposed After Third-Party Server Breach Spotify Catalog Scraped, 300TB Music and Metadata Dumped via Torrent University of Sydney Confirms Data Breach Affecting Thousands Leroy Merlin Breach Alert: French Customers Notified After Cyberattack Exposes Personal Data CodeRED Emergency Alerts Disrupted Across US After Ransomware Breach
Qantas data breach started with a fake IT support call
Vlad CONSTANTINESCU · 2026-07-16 · via Consumer Insights

A vishing attack on an overseas contact center exposed 5.67 million Qantas customer records in 2025, Australia’s privacy regulator says.

Key takeaways

  • An attacker posing as “Qantas IT help” manipulated a contact center agent into authorizing a malicious data connection.
  • Approximately 5.67 million customer records were compromised, including contact and frequent-flyer information.
  • Credit card details, passport data, passwords, PINs and account login credentials were not exposed.
  • The OAIC closed its preliminary inquiries without opening a formal investigation or taking regulatory action.

A fake support call opened access to customer data

On June 28, 2025, an attacker called an employee at an overseas contact center operated by a Qantas contractor. Posing as part of the airline’s IT support team, the caller directed the agent to a customer relationship management platform and described several actions as necessary to close a support ticket.

Those legitimate-looking steps connected the agent’s CRM session to a data extraction tool controlled by the attacker. Qantas identified unusual login-attempt alerts two days later. It then revoked access to the affected account, began assessing the data theft and it publicly disclosed the incident on July 2.

OAIC finds no basis for a formal investigation

The Office of the Australian Information Commissioner said roughly 5.67 million records were compromised. Around 4 million contained names, phone numbers, email addresses and Qantas Frequent Flyer details. Another 1.7 million also included information such as addresses, birth dates, gender or meal preferences.

The OAIC’s preliminary inquiries did not indicate that Qantas was likely to have breached its obligations under Australia’s privacy rules. The regulator cited supplier audits, recurring security training, role-based access controls and Qantas’ incident response. It also noted that a default CRM setting allowed an end user to authorize the third-party connection; the software provider has since changed that setting for all customers.

What affected Qantas customers should do

The regulator’s decision is not a definitive finding that all Qantas practices complied with privacy law, and further action remains possible. Qantas confirmed in October 2025 that criminals had released stolen customer data, although a New South Wales Supreme Court injunction prohibits others from accessing, using or distributing it.

Customers should independently verify unexpected Qantas communications, enable two-factor authentication and never disclose passwords, booking references or financial information to an unsolicited caller. Bitdefender Scamio can analyze suspicious messages, links or screenshots, while Bitdefender Digital Identity Protection can monitor exposed personal information and provide guidance when breach-related risks appear.