
Fake “Qantas IT Help” Vishing Led to Data Theft
Qantas avoided a formal Australian privacy regulator investigation after a June 2025 breach that impacted about 5.12 million people. The breach started with a…
Australia’s Privacy Commissioner said Qantas’ 2025 breach was triggered by a tech-support phone scam targeting a contact center agent. The caller posed as “Qantas IT help” and coached the agent to take steps in the CRM that actually connected it to a data-extraction tool, enabling theft of customer records affecting about 5.7 million people.
The breach began with a phone call, not malware or a phishing email. An attacker called a contact center agent and claimed to represent internal IT support, using the phrase “Qantas IT help” to establish credibility. The caller then instructed the agent to log into a CRM system and perform specific steps that were framed as necessary to close a routine support ticket.
Instead of resolving a ticket, those steps connected the CRM to a data extraction tool controlled by the attacker. That tool was then used to siphon off customer records, ultimately affecting around 5.7 million people. No malware needed to be installed and no credentials needed to be stolen through a fake login page. The agent's own legitimate access was used against the organization.
This attack worked because it exploited trust in internal processes rather than technical weaknesses. A few factors stand out:
Contact center and CRM-adjacent staff should be alert to these signals:
These red flags apply broadly to service desk, CRM administrator, and privacy/compliance teams, not just frontline agents.
Organizations can reduce exposure to this kind of pretext by combining process and awareness:
This incident illustrates how a single well-crafted phone call, aimed at a routine workflow, can lead to a large-scale data exposure without any conventional hacking.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
An attacker called a contact center agent claiming to be internal IT support, then coached the agent through CRM steps that instead connected the system to a data extraction tool used to steal customer records.
It was a social engineering attack, specifically a vishing (voice phishing) call that impersonated internal IT support rather than a technical exploit.
According to the Privacy Commissioner's findings, the breach could not necessarily have been foreseen and prevented through role-based access controls alone, since the agent was manipulated into performing actions within their normal permissions.
Contact center and customer service agents, service desk and IT support teams, CRM administrators, and privacy or compliance teams are the primary targets for this kind of pretext.
Imagine this: one phone call, fake 'Qantas IT help', and 5.7 million customer records gone. In the Qantas breach, a crook called a contact center agent, claimed to be 'Qantas IT help', and walked them through CRM steps to 'close a support ticket'. Those clicks secretly hooked the CRM to a data extraction tool. Here’s the trap: it sounded routine, close a ticket, but the caller was unsolicited, the CRM steps were unusual, and they changed integrations, not customer details. That’s vishing: social engineering over the phone. Your move: if 'IT support' calls you and asks for unusual CRM steps, stop and call them back using the official internal directory or ticketing portal, don’t just follow phone instructions.

Qantas avoided a formal Australian privacy regulator investigation after a June 2025 breach that impacted about 5.12 million people. The breach started with a…

Okta says it gained an inside look at “Work Panel,” a polished SaaS-style dashboard that helps voice-phishing (vishing) crews rapidly set up fake login sites…

A researcher demonstrated that a Claude web-browsing agent could be manipulated by a fake “Cloudflare authentication” warning on a malicious website. Once the…

Apple warns that scammers are using FaceTime calls, often with spoofed caller ID, to impersonate Apple or banks and pressure people into sharing passwords,…

The article highlights how attackers can quickly build convincing executive “profiles” from public information and use them to manipulate employees. It cites…

UK authorities charged five people linked to “Russian Coms,” a vishing (phone-scam) platform used to make large volumes of spoofed calls that appeared to come…