Fake “Qantas IT Help” Vishing Led to Data Theft

IT News Australia · Medium sophistication
Last updated July 30, 2026

Qantas avoided a formal Australian privacy regulator investigation after a June 2025 breach that impacted about 5.12 million people. The breach started with a phone-based social engineering call where an attacker posed as “Qantas IT help” and convinced a call-centre agent to connect a customized data extraction tool to Qantas’ CRM, enabling mass data export.

How the Attack Worked

This incident began with a vishing call, a phone-based social engineering technique. An unnamed threat actor impersonating "Qantas IT help" contacted the airline's call centre and reached a customer service agent. Posing as internal IT support, the caller convinced the agent to connect a customized version of Salesforce's Data Loader tool to the CRM platform Qantas uses to manage customer records. That connection enabled mass extraction of data, ultimately affecting approximately 5.12 million people. The stolen data included personal information and frequent flyer information.

Why It Succeeded

The attack did not rely on malware or exploiting a software vulnerability. It relied entirely on the agent trusting an unsolicited call from someone claiming to represent internal IT. Call centre and customer service staff are trained to be responsive and helpful, which can make them a soft target when a caller sounds authoritative and uses internal-sounding language like "IT help." Once the agent agreed to connect the tool, the attacker had a direct path into the CRM with no further social engineering required.

What to Watch For

Customer-facing and CRM-adjacent teams should treat the following as red flags:

  • An unsolicited call claiming to be internal IT support
  • Any request to connect, install, or run a tool that can access customer data
  • Pressure to perform unusual technical steps that fall outside an agent's normal duties

These patterns apply broadly across call centres, customer service desks, IT helpdesks, and CRM administration roles, all of which were identified as target audiences for this type of attack.

Building Resistance

Organizations with customer-facing teams and CRM access can reduce exposure to this type of attack by:

  • Training staff to verify internal IT requests through a known callback process before taking any action, rather than trusting the caller's claimed identity
  • Treating any request to connect external tools or change system access as high-risk, requiring supervisor or security approval
  • Reinforcing that social engineering can lead directly to large-scale data loss, not just isolated account compromise

This case shows that a single successful vishing call, targeting one agent, can result in extraction of data at a very large scale. Preparing frontline staff with clear verification steps and escalation paths for unusual technical requests is a practical way to reduce this risk.

Key findings

  • The incident began with vishing: an attacker called Qantas’ call centre while impersonating “Qantas IT help.”
  • A call-centre agent was convinced to connect a customized version of Salesforce Data Loader to Qantas’ CRM, enabling mass extraction.
  • Approximately 5.12 million Australians were affected.
  • Stolen data included personal information and frequent flyer information.
  • OAIC/Privacy Commissioner conducted preliminary inquiries and concluded Qantas acted quickly to contain the breach and alert the public, but a future formal investigation remains possible.

Who’s being targeted

  • Commonly targeted roles: Call Centre, Customer Service, IT Helpdesk / IT Support, Security / Privacy, CRM Administrators.
  • Affected industries: Airlines, Transportation, Call centers / Customer support operations.
  • Attack channels: vishing.
  • Impersonated: Qantas IT help.

Red flags to watch for

  • Unsolicited call claiming to be internal IT support
  • Request to connect/install or run a tool that can access customer data
  • Pressure to perform unusual technical steps outside the agent’s normal duties
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How did the Qantas vishing attack work?

An attacker called Qantas' call centre claiming to be internal IT support and convinced an agent to connect a customized version of Salesforce's Data Loader tool to the CRM, which enabled mass data extraction.

What data was stolen in the Qantas breach?

Stolen data included personal information and frequent flyer information affecting approximately 5.12 million Australians.

Why did the vishing call succeed?

The agent was convinced by an unsolicited call impersonating internal IT support and was pressured into performing an unusual technical step outside normal duties, without a verification process to catch the deception.

What can organizations do to prevent similar attacks?

Train customer-facing staff to verify internal IT requests through a known callback process and require supervisor or security approval before connecting any tool to a CRM system.

Read the video transcript

Imagine this: one call to a help desk, and suddenly 5 million customers’ data is up for grabs. In the Qantas breach, someone phoned the call centre, said they were “Qantas IT help,” and talked an agent into connecting a customised Salesforce Data Loader straight into the CRM. That single yes let them mass‑export personal and frequent flyer data for about 5.12 million people. The only real clues? Unsolicited “IT help” call and a push to run a tool that touches customer data. Your move: if anyone calls claiming to be IT and asks you to install, connect, or run a tool on customer systems, stop and use the official internal callback process before doing anything.

Similar attacks

FaceTime Spoof Calls Steal Codes and Money

FaceTime Spoof Calls Steal Codes and Money

Apple warns that scammers are using FaceTime calls, often with spoofed caller ID, to impersonate Apple or banks and pressure people into sharing passwords,…

July 17, 2026
“Russian Coms” Vishing Platform Busted

“Russian Coms” Vishing Platform Busted

UK authorities charged five people linked to “Russian Coms,” a vishing (phone-scam) platform used to make large volumes of spoofed calls that appeared to come…

July 14, 2026