Qantas Did Everything Right and Still Got Breached — By a Phone Call
Here’s a result that should worry every business owner: Australia’s Privacy Commissioner looked at the 2025 Qantas breach — which leaked details on 5.7 million people — and decided the airline didn’t break any privacy rules. As The Register reported, a crook simply rang a contact-centre agent, claimed to be “Qantas IT help”, and talked them through steps that quietly connected the CRM to a data-extraction tool. No malware. No unpatched server. Just a convincing phone call — a technique known as voice phishing, or vishing.
The uncomfortable part is the Commissioner’s reasoning. Qantas had audited its provider, run staff security-awareness testing and used role-based access controls, and the regulator found the breach “could not have been prevented” by tightening those controls further. In other words, you can pass the audit, tick every technical box, and still lose the lot to someone who’s polite on the phone. It’s the same playbook the Scattered Spider crew has run against airlines, retailers and insurers worldwide — and Australian help desks field these calls too.
So what actually stops it? A written identity-verification step for anyone requesting a password or MFA reset, and the discipline to use it every single time. That means no reset on a phone request alone: verify through a separate channel, call back to a number already on file, or use a shared code word. Limit who can reset accounts, log every reset, and make sure whoever answers your phones — in-house or an outsourced help desk — knows they’re allowed to say “I’ll call you back.” Most Australian SMBs we see have hardened their firewalls but never written this procedure down. The ACSC has flagged help-desk social engineering repeatedly for exactly this reason.
If you’re not sure how your team would handle that call today, that’s the gap to close. We help Northern Beaches and Central West NSW businesses tighten their cyber security processes and run team cyber safety training, so a friendly voice can’t simply talk its way past your controls.
Related Guide
Cybersecurity for Sydney SMBs
Explore our complete guide to protecting your business from cyber threats.
