Qantas Gets Off Scot-Free in Data Breach Despite Public Warnings
Qantas escaped scrutiny for a data breach affecting millions of customers after the Office of the Australian Information Commissioner (OAIC) decided not to open a formal investigation. The breach occurred in October last year when hackers leaked over 5 million Qantas customer records into the dark web.
The OAIC said it did not appear that Qantas could reasonably have anticipated and prevented the attack, but this assessment has been questioned given publicly available warnings from Salesforce and Google about similar attacks. More than three months before the breach, Salesforce published a security warning about criminals impersonating IT support staff over the phone.
Just 24 days before the Qantas breach, Google's Threat Intelligence Group published details of a campaign using essentially the same broad method. The attack involved an attacker ringing an employee at an overseas call centre used by Qantas and persuading them to follow instructions that ultimately gave the attacker access to a system containing customer information.
The OAIC said no documents matching a Freedom of Information request could be found, which sought evidence that the regulator had specifically considered the publicly available warnings during its inquiries. The distinction is important because this case reaches well beyond one airline, and regulators need to assess whether organisations were paying attention to warnings about attacks occurring around them at the time.