
“Work Panel” Streamlines Vishing Into One Console
Okta says it gained an inside look at “Work Panel,” a polished SaaS-style dashboard that helps voice-phishing (vishing) crews rapidly set up fake login sites…
Qantas avoided a formal Australian privacy regulator investigation after a June 2025 breach that impacted about 5.12 million people. The breach started with a phone-based social engineering call where an attacker posed as “Qantas IT help” and convinced a call-centre agent to connect a customized data extraction tool to Qantas’ CRM, enabling mass data export.
This incident began with a vishing call, a phone-based social engineering technique. An unnamed threat actor impersonating "Qantas IT help" contacted the airline's call centre and reached a customer service agent. Posing as internal IT support, the caller convinced the agent to connect a customized version of Salesforce's Data Loader tool to the CRM platform Qantas uses to manage customer records. That connection enabled mass extraction of data, ultimately affecting approximately 5.12 million people. The stolen data included personal information and frequent flyer information.
The attack did not rely on malware or exploiting a software vulnerability. It relied entirely on the agent trusting an unsolicited call from someone claiming to represent internal IT. Call centre and customer service staff are trained to be responsive and helpful, which can make them a soft target when a caller sounds authoritative and uses internal-sounding language like "IT help." Once the agent agreed to connect the tool, the attacker had a direct path into the CRM with no further social engineering required.
Customer-facing and CRM-adjacent teams should treat the following as red flags:
These patterns apply broadly across call centres, customer service desks, IT helpdesks, and CRM administration roles, all of which were identified as target audiences for this type of attack.
Organizations with customer-facing teams and CRM access can reduce exposure to this type of attack by:
This case shows that a single successful vishing call, targeting one agent, can result in extraction of data at a very large scale. Preparing frontline staff with clear verification steps and escalation paths for unusual technical requests is a practical way to reduce this risk.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
An attacker called Qantas' call centre claiming to be internal IT support and convinced an agent to connect a customized version of Salesforce's Data Loader tool to the CRM, which enabled mass data extraction.
Stolen data included personal information and frequent flyer information affecting approximately 5.12 million Australians.
The agent was convinced by an unsolicited call impersonating internal IT support and was pressured into performing an unusual technical step outside normal duties, without a verification process to catch the deception.
Train customer-facing staff to verify internal IT requests through a known callback process and require supervisor or security approval before connecting any tool to a CRM system.
Imagine this: one call to a help desk, and suddenly 5 million customers’ data is up for grabs. In the Qantas breach, someone phoned the call centre, said they were “Qantas IT help,” and talked an agent into connecting a customised Salesforce Data Loader straight into the CRM. That single yes let them mass‑export personal and frequent flyer data for about 5.12 million people. The only real clues? Unsolicited “IT help” call and a push to run a tool that touches customer data. Your move: if anyone calls claiming to be IT and asks you to install, connect, or run a tool on customer systems, stop and use the official internal callback process before doing anything.

Okta says it gained an inside look at “Work Panel,” a polished SaaS-style dashboard that helps voice-phishing (vishing) crews rapidly set up fake login sites…

Australia’s Privacy Commissioner said Qantas’ 2025 breach was triggered by a tech-support phone scam targeting a contact center agent. The caller posed as…

Microsoft reports attackers linked to ShinyHunters spent a year getting into corporate Salesforce data without exploiting Salesforce bugs. One key method was…

Apple warns that scammers are using FaceTime calls, often with spoofed caller ID, to impersonate Apple or banks and pressure people into sharing passwords,…

The article highlights how attackers can quickly build convincing executive “profiles” from public information and use them to manipulate employees. It cites…

UK authorities charged five people linked to “Russian Coms,” a vishing (phone-scam) platform used to make large volumes of spoofed calls that appeared to come…