On 28 June 2025, a caller rang a contact centre agent working for a third-party provider to Qantas. He said he was calling from Qantas IT. He talked the agent through a series of steps that connected the airline's CRM system to a data extraction tool. Nobody wrote malicious code. Nobody cracked a password. Nobody bypassed multi-factor authentication. The agent did exactly what their access allowed them to do, at the request of someone who sounded like they had the authority to ask.
By the time anyone noticed, 5.7 million customer records had left the building.
The regulator's finding
In July 2026, Australia's Privacy Commissioner published the findings of a year-long inquiry into the breach. Qantas had implemented security awareness training. Access controls were in place. The Commissioner found no likelihood that Qantas had failed to take reasonable steps to protect the data it held, and declined to open a formal investigation.
Read that finding again. The controls worked. Qantas ran the kind of security programme regulators expect, and 5.7 million records still left through a door someone was persuaded to open.
Where the real gap sits
This is not a story about weak technology. Role-based access controls cannot stop a person with legitimate access from being convinced to use it. Multi-factor authentication cannot stop a person from doing, on request, exactly what their job already allows them to do. The attacker did not need a vulnerability in the CRM. He needed one convincing phone call and one agent who believed the person on the other end had the authority to ask.
This is the pattern behind the majority of serious intrusions today. Attackers increasingly skip the technical perimeter, because the legitimate access path is faster and leaves nothing for a scanner to catch. A convincing instruction arrives. The right person is deceived, or the right system is compromised. Valid credentials are used. The action executes. By the time anyone notices, the damage is done.
Why faster detection would not have helped
Qantas was not a company that under-invested in security. The gap sat at one moment: the instant the CRM connection was authorised. No amount of faster monitoring changes what happens in that moment, because the action itself looked entirely legitimate. It was carried out by an authorised person, using authorised access, following what looked like a routine support request. Detection only helps after the fact. This was a failure that needed stopping before it completed, not one that needed noticing sooner.
What a hard stop at the execution boundary would have looked like
If a second, independent authority had needed to confirm that CRM-to-extraction-tool connection before it executed, out of band, on a device that authority controls, the vishing call would have hit a wall regardless of how convincing it was. The contact centre agent's belief that the caller was legitimate would no longer be the only thing standing between an attacker and 5.7 million records. A named authority would simply be in a position to stop the action if they had not requested it. If the action was genuinely theirs, it proceeds, because it was always legitimate.
Nobody needs to catch the deception for this to work. The action stops being exploitable regardless of whether the human in the chain was fooled.
The board question
Every board asks whether its controls are strong. Qantas's controls were strong, and the regulator said so. The sharper question is narrower: which actions, if a single person were convinced to authorise them by someone impersonating a colleague, would cause damage on this scale. Once that list exists, the fix is not more training or a faster response plan. It is a rule that no single deceived person can complete that action alone.
GoFirm is The Authority Platform. Stop unauthorised action. Every time.
In association with Osinto.ai, the collective intelligence platform for Security, Resilience & Defence. Osinto's AI-enabled open-source network and governed collaborative operational environment help mitigate the growing security, resilience and governance obligation in seconds, not days.
References
Office of the Australian Information Commissioner, Report into preliminary inquiries of Qantas, published 16 July 2026. oaic.gov.au
Office of the Australian Information Commissioner, Privacy Commissioner completes preliminary inquiries into Qantas 2025 data incident, media statement, 16 July 2026. oaic.gov.au
The Register, Tech support scam caused massive data breach at Australian airline Qantas, 16 July 2026. theregister.com
Security Affairs, Qantas data breach impacted 5.7 million individuals, July 2025. securityaffairs.com
The Cyber Express, Qantas Did Everything Right, And Got Breached Anyway, 16 July 2026. thecyberexpress.com
