Australia's privacy regulator has closed its inquiry into the 2025 Qantas data breach without opening a formal investigation. In a report published on 16 July 2026, the Office of the Australian Information Commissioner (OAIC) said the evidence did not support the likelihood that Qantas had breached its obligations under the country's privacy law, and that a Commissioner-Initiated Investigation would not be a warranted use of resources. For a breach that exposed the personal information of roughly 5.7 million customers, that is a striking outcome — and a deliberate signal about how the regulator now weighs fault.
What the regulator actually examined
Between 11 July 2025 and 1 June 2026, the OAIC conducted preliminary inquiries under section 42(2) of the Privacy Act, assessing Qantas' compliance with the Notifiable Data Breaches scheme and whether the airline had likely contravened Australian Privacy Principles 1, 8 and 11 — the obligations covering open information handling, cross-border disclosure and the requirement to take reasonable steps to protect personal information. The Commissioner concluded the evidence did not support the likelihood of a contravention, and published the report under a public-interest provision precisely because of the case's profile and its educative value.
The reasoning is the important part. The OAIC found that Qantas had reasonable measures in place before the incident: supplier and security audits, mandatory and recurring cyber-awareness training, role-based access controls, contractual privacy requirements imposed on third-party service providers, defined data-retention and deletion practices overseen by a dedicated privacy office, and a prompt breach-response program once the incident was detected. The OAIC concluded that, based on the evidence before it, none of the additional measures it considered would likely have prevented this particular incident. The controls existed; the attack succeeded anyway.
How the breach happened
The incident did not begin with a broken firewall. It began with a phone call. Attackers used voice phishing — a vishing (voice-phishing) social-engineering attack — against an employee at an overseas third-party contact centre, based in Manila, that handled Qantas customer service. Through manipulation rather than a technical exploit, they obtained access to a customer database supporting that contact centre. Qantas' core flight and operational systems were not affected.
One detail from the report is worth drawing out for anyone running similar setups: a default configuration setting in the customer-relationship-management platform allowed an end user to authorise the third-party connection that was abused. According to the OAIC report, the software provider has since changed that default configuration for all customers. It is a familiar and uncomfortable pattern — a setting that ships permissive, is never locked down because nobody registers it as a risk, and becomes the point the whole incident turns on.
Why the regional angle is real
For Southeast Asian readers this is not an abstract Australian story. The compromised system supported an offshore contact centre in Manila, which places the attack squarely on the region's large business-process-outsourcing footprint. The Philippines, and the broader ASEAN BPO sector, host the customer-service and back-office operations of a great many foreign enterprises, and this incident is a concrete reminder that the security of those operations is now part of the client's risk surface. When an attacker targets people and third-party systems rather than aircraft or core banking, the offshore contact centre becomes a primary target, and the governance standard the OAIC applied — reasonable oversight of third parties — is exactly the control that determines exposure.
Key Takeaways
The OAIC closed its inquiry into the 2025 Qantas breach on 16 July 2026 without opening a formal investigation, finding the evidence did not support a likely breach of Australian privacy law.
The breach exposed roughly 5.7 million customers and stemmed from a vishing attack on an employee at a Manila-based third-party contact centre, not a technical exploit of Qantas' systems.
The OAIC credited Qantas' pre-incident controls: supplier audits, recurring training, role-based access, third-party contractual terms and prompt breach response.
A permissive default setting in the CRM platform enabled the abused third-party connection; the vendor has since changed that default for all customers.
The decision is not an endorsement, further action remains possible, and it does not affect the affected individuals or any separate civil claims or potential class-action proceedings.