Fake “Qantas IT Help” Call Led to 5.7M Leak

The Register Security · Medium sophistication
Last updated July 30, 2026

Australia’s Privacy Commissioner said Qantas’ 2025 breach was triggered by a tech-support phone scam targeting a contact center agent. The caller posed as “Qantas IT help” and coached the agent to take steps in the CRM that actually connected it to a data-extraction tool, enabling theft of customer records affecting about 5.7 million people.

How the attack worked

The breach began with a phone call, not malware or a phishing email. An attacker called a contact center agent and claimed to represent internal IT support, using the phrase “Qantas IT help” to establish credibility. The caller then instructed the agent to log into a CRM system and perform specific steps that were framed as necessary to close a routine support ticket.

Instead of resolving a ticket, those steps connected the CRM to a data extraction tool controlled by the attacker. That tool was then used to siphon off customer records, ultimately affecting around 5.7 million people. No malware needed to be installed and no credentials needed to be stolen through a fake login page. The agent's own legitimate access was used against the organization.

Why it succeeded

This attack worked because it exploited trust in internal processes rather than technical weaknesses. A few factors stand out:

  • The caller impersonated a familiar, authoritative internal function (IT support), which lowers an agent's guard compared to an external or unknown caller.
  • The request was framed as a routine task, closing a support ticket, rather than something obviously suspicious like sharing a password.
  • The actions requested blended in with normal CRM administration, making it hard for the agent to recognize that a system integration was being changed.
  • Australia's Privacy Commissioner noted that role-based access controls alone might not have reasonably prevented this outcome, since the agent was acting within their normal scope of access.

What to watch for

Contact center and CRM-adjacent staff should be alert to these signals:

  • Unsolicited calls claiming to be internal IT support, especially ones that arrive without a prior ticket or request from the agent.
  • Pressure to complete unfamiliar CRM steps framed as necessary to “close a ticket.”
  • Instructions that involve connecting tools, granting access, or changing system settings rather than standard customer-service tasks.

These red flags apply broadly to service desk, CRM administrator, and privacy/compliance teams, not just frontline agents.

How to build resistance

Organizations can reduce exposure to this kind of pretext by combining process and awareness:

  • Require call-back verification through an official internal directory or ticketing portal before acting on any unsolicited “IT support” request.
  • Train staff to pause and escalate whenever a request involves changing integrations, enabling access, or connecting external tools, even if it's framed as routine.
  • Run realistic vishing exercises built around common workflows like “closing a support ticket,” since attackers weaponize normal business processes rather than obviously malicious requests.
  • Reinforce that verifying identity is not a sign of distrust toward colleagues, but a standard safeguard against impersonation.

This incident illustrates how a single well-crafted phone call, aimed at a routine workflow, can lead to a large-scale data exposure without any conventional hacking.

Key findings

  • The breach originated from a social-engineering attack against a contact center agent (vishing/phone-based pretext).
  • The attacker impersonated internal IT support (“Qantas IT help”) and used a support-ticket pretext to get the agent to perform actions in the CRM.
  • Those actions connected the CRM to a data extraction tool, which was then used to siphon customer records.
  • The Privacy Commissioner did not open a formal privacy probe and stated Qantas could not have reasonably foreseen and prevented the breach through stronger role-based access controls alone.
  • The identity of the attackers was not confirmed; commentary suggested possible links to “Scattered Spider,” but this was not established in the report.

Who’s being targeted

  • Commonly targeted roles: Contact center / Customer service, Service desk / IT support teams, CRM administrators, Privacy and compliance teams.
  • Affected industries: Airlines / Aviation, Travel and transportation contact centers.
  • Attack channels: vishing.
  • Impersonated: “Qantas IT help” (internal IT support).

Red flags to watch for

  • Unsolicited call claiming to be internal IT support
  • Pressure to perform unfamiliar CRM steps to ‘close a ticket’
  • Instructions that change system integrations/settings rather than normal customer-service tasks
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How did the attacker gain access to customer data?

An attacker called a contact center agent claiming to be internal IT support, then coached the agent through CRM steps that instead connected the system to a data extraction tool used to steal customer records.

Was this a technical hack or a social engineering attack?

It was a social engineering attack, specifically a vishing (voice phishing) call that impersonated internal IT support rather than a technical exploit.

Could stronger access controls have prevented this breach?

According to the Privacy Commissioner's findings, the breach could not necessarily have been foreseen and prevented through role-based access controls alone, since the agent was manipulated into performing actions within their normal permissions.

What roles are most at risk from this type of attack?

Contact center and customer service agents, service desk and IT support teams, CRM administrators, and privacy or compliance teams are the primary targets for this kind of pretext.

Read the video transcript

Imagine this: one phone call, fake 'Qantas IT help', and 5.7 million customer records gone. In the Qantas breach, a crook called a contact center agent, claimed to be 'Qantas IT help', and walked them through CRM steps to 'close a support ticket'. Those clicks secretly hooked the CRM to a data extraction tool. Here’s the trap: it sounded routine, close a ticket, but the caller was unsolicited, the CRM steps were unusual, and they changed integrations, not customer details. That’s vishing: social engineering over the phone. Your move: if 'IT support' calls you and asks for unusual CRM steps, stop and call them back using the official internal directory or ticketing portal, don’t just follow phone instructions.

Similar attacks

Fake “Qantas IT Help” Vishing Led to Data Theft

Fake “Qantas IT Help” Vishing Led to Data Theft

Qantas avoided a formal Australian privacy regulator investigation after a June 2025 breach that impacted about 5.12 million people. The breach started with a phone-based social engineering call where an attacker posed as “Qantas IT help” and convinced a call-centre agent to connect a customized…

July 16, 2026
Phishing Hits M365; Deepfake Vishing Targets Funds

Phishing Hits M365; Deepfake Vishing Targets Funds

The roundup describes real social-engineering incidents: a phishing email that led an employee to enter credentials on a fake Microsoft 365 login page, and a wave of voice-phishing attempts against major hedge funds using voice-mimicking technology. Both incidents show practical lures that can be…

August 7, 2026
Fake $149.99 Apple/Amazon Charge Popup Scam

Fake $149.99 Apple/Amazon Charge Popup Scam

A scam campaign uses full-screen browser popups impersonating Apple Support or Amazon to claim an “unauthorized” $149.99 charge and pressure victims to call a phone number. Callers reach a live scammer posing as support who tries to gain remote access or steal payment/account details, sometimes…

August 6, 2026
ChatGPT Billing Phish and Fake Snap Support Scams

ChatGPT Billing Phish and Fake Snap Support Scams

This roundup describes real-world social engineering, including phishing emails that impersonate ChatGPT billing to steal payment card data and a convicted attacker who posed as Snapchat support to trick people into handing over login codes. The common theme is impersonation of trusted brands to…

July 31, 2026
“Work Panel” Streamlines Vishing Into One Console

“Work Panel” Streamlines Vishing Into One Console

Okta says it gained an inside look at “Work Panel,” a polished SaaS-style dashboard that helps voice-phishing (vishing) crews rapidly set up fake login sites and guide victims through password and MFA capture. The tool clones brand look-and-feel for services like Okta and Microsoft 365, then lets a…

July 29, 2026
Fake Cloudflare Prompt Tricks Claude Agents

Fake Cloudflare Prompt Tricks Claude Agents

A researcher demonstrated that a Claude web-browsing agent could be manipulated by a fake “Cloudflare authentication” warning on a malicious website. Once the agent followed the prompt loop and clicked links, it could be coaxed into revealing personal/owner details such as employer and hometown.…

July 24, 2026