Qantas escapes formal OAIC probe over 2025 vishing breach – iTnews

July 16, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: itnews.com.au

Threat Risk: High
Victim: Aviation Industry
Incident: A large-scale data breach triggered by a vishing attack targeting call center employees.
Impact: Exposure of personal and frequent flyer data for approximately 5.12 million customers.
Attacker: Scattered Spider, Lapsus$, or ShinyHunters
Analysis: Attackers used vishing to impersonate IT support and deceive call center staff into deploying a modified Salesforce Data Loader tool. This allowed the threat actors to bypass standard security controls and perform mass data extraction from the company’s CRM. The incident underscores the persistent risk of human-centric vulnerabilities in high-pressure customer service environments.
Recommendations: Implement strict multi-factor authentication and approval workflows for any CRM data export tools.; Conduct targeted vishing simulation training for call center and help desk employees.; Establish a mandatory identity verification or ‘call-back’ protocol for all internal IT support requests.
Source: iTnews

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *