Fake “Qantas IT Help” Call Led to 5.7M Leak

The Register Security · Medium sophistication
Last updated July 30, 2026

Australia’s Privacy Commissioner said Qantas’ 2025 breach was triggered by a tech-support phone scam targeting a contact center agent. The caller posed as “Qantas IT help” and coached the agent to take steps in the CRM that actually connected it to a data-extraction tool, enabling theft of customer records affecting about 5.7 million people.

How the attack worked

The breach began with a phone call, not malware or a phishing email. An attacker called a contact center agent and claimed to represent internal IT support, using the phrase “Qantas IT help” to establish credibility. The caller then instructed the agent to log into a CRM system and perform specific steps that were framed as necessary to close a routine support ticket.

Instead of resolving a ticket, those steps connected the CRM to a data extraction tool controlled by the attacker. That tool was then used to siphon off customer records, ultimately affecting around 5.7 million people. No malware needed to be installed and no credentials needed to be stolen through a fake login page. The agent's own legitimate access was used against the organization.

Why it succeeded

This attack worked because it exploited trust in internal processes rather than technical weaknesses. A few factors stand out:

  • The caller impersonated a familiar, authoritative internal function (IT support), which lowers an agent's guard compared to an external or unknown caller.
  • The request was framed as a routine task, closing a support ticket, rather than something obviously suspicious like sharing a password.
  • The actions requested blended in with normal CRM administration, making it hard for the agent to recognize that a system integration was being changed.
  • Australia's Privacy Commissioner noted that role-based access controls alone might not have reasonably prevented this outcome, since the agent was acting within their normal scope of access.

What to watch for

Contact center and CRM-adjacent staff should be alert to these signals:

  • Unsolicited calls claiming to be internal IT support, especially ones that arrive without a prior ticket or request from the agent.
  • Pressure to complete unfamiliar CRM steps framed as necessary to “close a ticket.”
  • Instructions that involve connecting tools, granting access, or changing system settings rather than standard customer-service tasks.

These red flags apply broadly to service desk, CRM administrator, and privacy/compliance teams, not just frontline agents.

How to build resistance

Organizations can reduce exposure to this kind of pretext by combining process and awareness:

  • Require call-back verification through an official internal directory or ticketing portal before acting on any unsolicited “IT support” request.
  • Train staff to pause and escalate whenever a request involves changing integrations, enabling access, or connecting external tools, even if it's framed as routine.
  • Run realistic vishing exercises built around common workflows like “closing a support ticket,” since attackers weaponize normal business processes rather than obviously malicious requests.
  • Reinforce that verifying identity is not a sign of distrust toward colleagues, but a standard safeguard against impersonation.

This incident illustrates how a single well-crafted phone call, aimed at a routine workflow, can lead to a large-scale data exposure without any conventional hacking.

Key findings

  • The breach originated from a social-engineering attack against a contact center agent (vishing/phone-based pretext).
  • The attacker impersonated internal IT support (“Qantas IT help”) and used a support-ticket pretext to get the agent to perform actions in the CRM.
  • Those actions connected the CRM to a data extraction tool, which was then used to siphon customer records.
  • The Privacy Commissioner did not open a formal privacy probe and stated Qantas could not have reasonably foreseen and prevented the breach through stronger role-based access controls alone.
  • The identity of the attackers was not confirmed; commentary suggested possible links to “Scattered Spider,” but this was not established in the report.

Who’s being targeted

  • Commonly targeted roles: Contact center / Customer service, Service desk / IT support teams, CRM administrators, Privacy and compliance teams.
  • Affected industries: Airlines / Aviation, Travel and transportation contact centers.
  • Attack channels: vishing.
  • Impersonated: “Qantas IT help” (internal IT support).

Red flags to watch for

  • Unsolicited call claiming to be internal IT support
  • Pressure to perform unfamiliar CRM steps to ‘close a ticket’
  • Instructions that change system integrations/settings rather than normal customer-service tasks
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How did the attacker gain access to customer data?

An attacker called a contact center agent claiming to be internal IT support, then coached the agent through CRM steps that instead connected the system to a data extraction tool used to steal customer records.

Was this a technical hack or a social engineering attack?

It was a social engineering attack, specifically a vishing (voice phishing) call that impersonated internal IT support rather than a technical exploit.

Could stronger access controls have prevented this breach?

According to the Privacy Commissioner's findings, the breach could not necessarily have been foreseen and prevented through role-based access controls alone, since the agent was manipulated into performing actions within their normal permissions.

What roles are most at risk from this type of attack?

Contact center and customer service agents, service desk and IT support teams, CRM administrators, and privacy or compliance teams are the primary targets for this kind of pretext.

Read the video transcript

Imagine this: one phone call, fake 'Qantas IT help', and 5.7 million customer records gone. In the Qantas breach, a crook called a contact center agent, claimed to be 'Qantas IT help', and walked them through CRM steps to 'close a support ticket'. Those clicks secretly hooked the CRM to a data extraction tool. Here’s the trap: it sounded routine, close a ticket, but the caller was unsolicited, the CRM steps were unusual, and they changed integrations, not customer details. That’s vishing: social engineering over the phone. Your move: if 'IT support' calls you and asks for unusual CRM steps, stop and call them back using the official internal directory or ticketing portal, don’t just follow phone instructions.

Similar attacks

Fake Cloudflare Prompt Tricks Claude Agents

Fake Cloudflare Prompt Tricks Claude Agents

A researcher demonstrated that a Claude web-browsing agent could be manipulated by a fake “Cloudflare authentication” warning on a malicious website. Once the…

July 24, 2026
FaceTime Spoof Calls Steal Codes and Money

FaceTime Spoof Calls Steal Codes and Money

Apple warns that scammers are using FaceTime calls, often with spoofed caller ID, to impersonate Apple or banks and pressure people into sharing passwords,…

July 17, 2026
“Russian Coms” Vishing Platform Busted

“Russian Coms” Vishing Platform Busted

UK authorities charged five people linked to “Russian Coms,” a vishing (phone-scam) platform used to make large volumes of spoofed calls that appeared to come…

July 14, 2026