Fake “Qantas IT Help” Vishing Led to Data Theft

IT News Australia · Medium sophistication
Last updated July 30, 2026

Qantas avoided a formal Australian privacy regulator investigation after a June 2025 breach that impacted about 5.12 million people. The breach started with a phone-based social engineering call where an attacker posed as “Qantas IT help” and convinced a call-centre agent to connect a customized data extraction tool to Qantas’ CRM, enabling mass data export.

How the Attack Worked

This incident began with a vishing call, a phone-based social engineering technique. An unnamed threat actor impersonating "Qantas IT help" contacted the airline's call centre and reached a customer service agent. Posing as internal IT support, the caller convinced the agent to connect a customized version of Salesforce's Data Loader tool to the CRM platform Qantas uses to manage customer records. That connection enabled mass extraction of data, ultimately affecting approximately 5.12 million people. The stolen data included personal information and frequent flyer information.

Why It Succeeded

The attack did not rely on malware or exploiting a software vulnerability. It relied entirely on the agent trusting an unsolicited call from someone claiming to represent internal IT. Call centre and customer service staff are trained to be responsive and helpful, which can make them a soft target when a caller sounds authoritative and uses internal-sounding language like "IT help." Once the agent agreed to connect the tool, the attacker had a direct path into the CRM with no further social engineering required.

What to Watch For

Customer-facing and CRM-adjacent teams should treat the following as red flags:

  • An unsolicited call claiming to be internal IT support
  • Any request to connect, install, or run a tool that can access customer data
  • Pressure to perform unusual technical steps that fall outside an agent's normal duties

These patterns apply broadly across call centres, customer service desks, IT helpdesks, and CRM administration roles, all of which were identified as target audiences for this type of attack.

Building Resistance

Organizations with customer-facing teams and CRM access can reduce exposure to this type of attack by:

  • Training staff to verify internal IT requests through a known callback process before taking any action, rather than trusting the caller's claimed identity
  • Treating any request to connect external tools or change system access as high-risk, requiring supervisor or security approval
  • Reinforcing that social engineering can lead directly to large-scale data loss, not just isolated account compromise

This case shows that a single successful vishing call, targeting one agent, can result in extraction of data at a very large scale. Preparing frontline staff with clear verification steps and escalation paths for unusual technical requests is a practical way to reduce this risk.

Key findings

  • The incident began with vishing: an attacker called Qantas’ call centre while impersonating “Qantas IT help.”
  • A call-centre agent was convinced to connect a customized version of Salesforce Data Loader to Qantas’ CRM, enabling mass extraction.
  • Approximately 5.12 million Australians were affected.
  • Stolen data included personal information and frequent flyer information.
  • OAIC/Privacy Commissioner conducted preliminary inquiries and concluded Qantas acted quickly to contain the breach and alert the public, but a future formal investigation remains possible.

Who’s being targeted

  • Commonly targeted roles: Call Centre, Customer Service, IT Helpdesk / IT Support, Security / Privacy, CRM Administrators.
  • Affected industries: Airlines, Transportation, Call centers / Customer support operations.
  • Attack channels: vishing.
  • Impersonated: Qantas IT help.

Red flags to watch for

  • Unsolicited call claiming to be internal IT support
  • Request to connect/install or run a tool that can access customer data
  • Pressure to perform unusual technical steps outside the agent’s normal duties
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How did the Qantas vishing attack work?

An attacker called Qantas' call centre claiming to be internal IT support and convinced an agent to connect a customized version of Salesforce's Data Loader tool to the CRM, which enabled mass data extraction.

What data was stolen in the Qantas breach?

Stolen data included personal information and frequent flyer information affecting approximately 5.12 million Australians.

Why did the vishing call succeed?

The agent was convinced by an unsolicited call impersonating internal IT support and was pressured into performing an unusual technical step outside normal duties, without a verification process to catch the deception.

What can organizations do to prevent similar attacks?

Train customer-facing staff to verify internal IT requests through a known callback process and require supervisor or security approval before connecting any tool to a CRM system.

Read the video transcript

Imagine this: one call to a help desk, and suddenly 5 million customers’ data is up for grabs. In the Qantas breach, someone phoned the call centre, said they were “Qantas IT help,” and talked an agent into connecting a customised Salesforce Data Loader straight into the CRM. That single yes let them mass‑export personal and frequent flyer data for about 5.12 million people. The only real clues? Unsolicited “IT help” call and a push to run a tool that touches customer data. Your move: if anyone calls claiming to be IT and asks you to install, connect, or run a tool on customer systems, stop and use the official internal callback process before doing anything.

Similar attacks

Brinks Home Hit via Microsoft Entra Vishing

Brinks Home Hit via Microsoft Entra Vishing

Brinks Home says it is investigating a cybersecurity incident after the ShinyHunters group claimed it broke in by calling employees and tricking them into approving Microsoft Entra authentication actions. The attacker is threatening to publish data it claims to have stolen, including alleged…

July 31, 2026
“Work Panel” Streamlines Vishing Into One Console

“Work Panel” Streamlines Vishing Into One Console

Okta says it gained an inside look at “Work Panel,” a polished SaaS-style dashboard that helps voice-phishing (vishing) crews rapidly set up fake login sites and guide victims through password and MFA capture. The tool clones brand look-and-feel for services like Okta and Microsoft 365, then lets a…

July 29, 2026
Fake “Qantas IT Help” Call Led to 5.7M Leak

Fake “Qantas IT Help” Call Led to 5.7M Leak

Australia’s Privacy Commissioner said Qantas’ 2025 breach was triggered by a tech-support phone scam targeting a contact center agent. The caller posed as “Qantas IT help” and coached the agent to take steps in the CRM that actually connected it to a data-extraction tool, enabling theft of customer…

July 16, 2026
Phishing Hits M365; Deepfake Vishing Targets Funds

Phishing Hits M365; Deepfake Vishing Targets Funds

The roundup describes real social-engineering incidents: a phishing email that led an employee to enter credentials on a fake Microsoft 365 login page, and a wave of voice-phishing attempts against major hedge funds using voice-mimicking technology. Both incidents show practical lures that can be…

August 7, 2026
Fake $149.99 Apple/Amazon Charge Popup Scam

Fake $149.99 Apple/Amazon Charge Popup Scam

A scam campaign uses full-screen browser popups impersonating Apple Support or Amazon to claim an “unauthorized” $149.99 charge and pressure victims to call a phone number. Callers reach a live scammer posing as support who tries to gain remote access or steal payment/account details, sometimes…

August 6, 2026
ChatGPT Billing Phish and Fake Snap Support Scams

ChatGPT Billing Phish and Fake Snap Support Scams

This roundup describes real-world social engineering, including phishing emails that impersonate ChatGPT billing to steal payment card data and a convicted attacker who posed as Snapchat support to trick people into handing over login codes. The common theme is impersonation of trusted brands to…

July 31, 2026