Heading image for The breach that could not be foreseen - except that it was

What the image represents

V reads a Salesforce advisory to the 5.12 million Australians affected by the Qantas breach. Salesforce had publicly described a closely matching attack method 108 days before the Qantas incident. The OAIC’s preliminary report states that, based on the information provided, Qantas could not reasonably have foreseen and prevented the breach as it occurred.

On 16 July 2026, the Office of the Australian Information Commissioner (OAIC) published its Report into preliminary inquiries of Qantas, examining the cyber incident that began on 28 June 2025 and compromised approximately 5.67 million customer records. (1)

According to the OAIC, a threat actor contacted an agent employed by an overseas contact-centre provider and impersonated “Qantas IT help”. The caller then guided the agent through a series of steps that connected the agent’s instance of Qantas’s CRM platform to a data-extraction tool controlled by the attacker.

Qantas detected unusual login-attempt alerts on 30 June 2025, confirmed unauthorised access, and publicly disclosed the incident on 2 July. (1)

The OAIC’s preliminary view

The OAIC conducted preliminary inquiries between 11 July 2025 and 1 June 2026. It ultimately decided not to commence a Commissioner-initiated investigation. The report makes clear that this was not a concluded finding that Qantas had complied with its privacy obligations, and that the Commissioner may investigate at a later date if further information warrants it.

In explaining the decision, Australian Privacy Commissioner Carly Kind wrote:

“Based on the information provided, it does not appear that Qantas could have reasonably foreseen and prevented the breach in the manner that it occurred.”

The OAIC said the information before it did not reveal significant gaps in Qantas’s controls.

It noted that the CRM platform’s default configuration allowed an end user to approve the third-party connection used in the attack. The OAIC also concluded that stronger role-based access controls would not have prevented the incident, and that standard social-engineering training was unlikely to have stopped an attack of this kind. The CRM provider subsequently changed the relevant default setting.

Salesforce and Data Loader

The OAIC report does not identify the CRM provider or the data-extraction tool by name.

Public reporting later filled in some of those details. On 16 July 2026, iTnews reported that the contact-centre agent had been induced to connect a customised version of Salesforce Data Loader to the CRM environment used by Qantas. (4)

Salesforce warned of the technique 108 days earlier

On 12 March 2025 — 108 days before the initial Qantas call — Salesforce warned that attackers were impersonating IT support, persuading users to approve malicious connected applications, including modified versions of Data Loader, and extracting Salesforce data. (2)

Salesforce recommended restricting connected applications and Data Loader access, limiting connections by IP address, and monitoring or blocking unusually large downloads.

GTIG documented a similar campaign 24 days earlier

On 4 June 2025 — 24 days before the Qantas incident — Google Threat Intelligence Group (GTIG) reported that UNC6040 was using a similar technique against Salesforce customers. (3)

Diagram of the UNC6040 Salesforce Data Loader attack flow published by GTIG

GTIG described attackers posing as IT support, persuading employees to authorise malicious Salesforce applications and using modified versions of Data Loader to steal data. Its recommended mitigations included tighter controls over connected applications, API and Data Loader access, application allowlisting, IP restrictions and monitoring for large exports.

These similarities do not establish that Qantas should necessarily have prevented the breach, or that every recommended control would have stopped it. They do establish that Salesforce and GTIG had publicly documented closely similar attacks before 28 June 2025. The OAIC report does not mention either publication or state whether their recommendations were considered.

An FBI warning on the day of the breach

The OAIC dates the initial social-engineering call to Saturday, 28 June 2025, but does not state what time it occurred.

At 9:50:24 am AEST that day, the FBI published an alert saying Scattered Spider had expanded its targeting to the airline sector. The alert described the group using social engineering to deceive IT help desks into granting access. (7)

FBI alert concerning Scattered Spider and the airline sector

Publication time of the FBI alert

The FBI did not mention Qantas, and the OAIC has not attributed the breach to Scattered Spider. Contemporary reporting nevertheless noted similarities between the Qantas breach and Scattered Spider’s methods. (8, 9)

Because the OAIC gives no time for the initial call, the public record does not establish whether the FBI alert came before or after the Qantas attack began.

I raised the threat intelligence with the OAIC

I wrote to the Australian Privacy Commissioner raising the possible relevance of the Salesforce and GTIG publications to the Qantas incident. (5)

The OAIC subsequently acknowledged receipt of that correspondence and said:

“We have no formal comment or feedback to offer in this regard, but acknowledge receipt of the information you have provided.” (6)

What the FOI response revealed

I lodged a Freedom of Information request with the OAIC seeking documents concerning whether the agency had put the Salesforce and GTIG publications — or other similar threat intelligence — to Qantas or its representatives during the preliminary inquiries. (10)

The OAIC’s decision said that no documents falling within the scope of the request could be found:

“Documents cannot be found, do not exist or have not been received” (10)

The decision added that OAIC investigators had nevertheless canvassed Qantas’s awareness of security risks before the incident as part of their assessment under Australian Privacy Principle 11.

The OAIC therefore says it examined Qantas’s prior awareness of security risks, but identified no documents within the scope of the request recording that the Salesforce or GTIG publications — or comparable threat intelligence — were specifically put to Qantas.

Opinion

The issue is whether the OAIC’s preliminary inquiry adequately tested the question APP 11 actually asks: whether Qantas had taken the technical and organisational measures that were reasonable in the circumstances.

Before the breach, Salesforce and GTIG had publicly described closely similar attacks and identified controls intended to reduce the risk. Yet the OAIC concluded that Qantas could not reasonably have foreseen and prevented the breach “in the manner that it occurred”.

The OAIC says it canvassed Qantas’s awareness of security risks, but its report does not explain whether this threat intelligence was examined or whether the recommended controls formed part of the APP 11 assessment. My FOI request identified no documents within scope that resolve that question.

That does not prove the issue was ignored. But it leaves an important gap in the public record: we cannot see how the existence of closely similar, previously documented attacks factored into the OAIC’s assessment of what security measures were reasonable in the circumstances.

That matters beyond Qantas. If relevant threat intelligence is not properly accounted for when assessing what measures are reasonable under APP 11, the assessment risks falling behind not only the threats organisations actually face, but those they should reasonably be capable of anticipating and defending against.

References

  1. Report into preliminary inquiries of Qantas, Office of the Australian Information Commissioner, 16 July 2026.

  2. Protect Your Salesforce Environment from Social Engineering Threats, Salesforce, 12 March 2025; updated 14 March 2025.

  3. The Cost of a Call: From Voice Phishing to Data Extortion, Google Threat Intelligence Group, 4 June 2025.

  4. Qantas escapes formal OAIC probe over 2025 vishing breach, iTnews, 16 July 2026.

  5. Threat Intelligence and the Qantas Breach, letter from Benjamin Mosse to the Australian Privacy Commissioner, 10 August 2026.

  6. Email from the Office of the Australian Information Commissioner to Benjamin Mosse, acknowledging receipt of the letter. Copy on file.

  7. Alert concerning Scattered Spider targeting the airline sector, Federal Bureau of Investigation, 27 June 2025 UTC / 28 June 2025 AEST.

  8. What we know about Scattered Spider, the hacker group targeting airlines, ABC News, 2 July 2025.

  9. Qantas confirms cyber-attack exposed records of up to 6 million customers, The Guardian, 2 July 2025.

  10. FOIREQ26/00258, Office of the Australian Information Commissioner, 21 September 2026.