OAIC Concludes Preliminary Inquiries into Qantas Data Breach
The 2025 cyber incident affected approximately 5.12 million Australians after a threat actor used a phone-based social engineering attack, commonly known as vishing, to deceive an employee at an overseas third-party contact centre into granting unauthorised access to customer information.
Following nearly a year of preliminary inquiries, the OAIC concluded that the available evidence did not indicate Qantas had failed to take reasonable steps to protect personal information or to ensure its overseas service provider complied with the Australian Privacy Principles. As a result, the Privacy Commissioner has decided not to commence a Commissioner-initiated investigation or take further regulatory action at this time.
The report also highlights the importance of effective incident response. Qantas' ability to quickly identify unusual system activity, contain the breach, notify affected customers and engage specialist forensic experts helped reduce the overall impact of the incident.
For records and information management professionals, the report reinforces several key lessons. Technical security measures alone are not enough to prevent cyber incidents. Organisations must also invest in staff awareness, robust governance, third-party risk management, incident response planning and ongoing monitoring to strengthen resilience against increasingly sophisticated social engineering attacks.
The OAIC has published the report in the public interest to provide transparency around its decision-making process and to help organisations better understand the importance of privacy governance and preparedness in responding to major cyber incidents.