
Qantas Did Everything “Right” — And Got Breached Anyway. Regulators Say That’s the Point.
A vishing call to an overseas contact center agent. A fake IT ticket. A default setting nobody thought to lock down. That's all it took to expose the personal data of roughly 5 million Australians — and now the country's privacy regulator has decided Qantas isn't to blame for it.
The Office of the Australian Information Commissioner (OAIC) closed the book this week on its year-long preliminary inquiry into the June 2025 Qantas data breach, and the conclusion cuts against the instinct to punish the victim of a cyberattack.
Also read: Australia’s Qantas Confirms Cyberattack: 6 Million Service Records Compromised
According to the OAIC's report, the evidence gathered did not indicate a l...