{"meta":{"database":"Global Social Engineering Impact Database","url":"https://global-social-engineering-impact-da.vercel.app","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","generated":"2026-08-29T09:19:33.013Z","total":1,"returned":1,"limit":50,"offset":0,"next":null,"note":"Read loss_kind before summing loss_usd: only direct_loss and ransom_paid are comparable. Entries with entry_type \"benchmark\" are aggregate agency statistics and overlap with everything else by construction."},"results":[{"title":"Qantas contact centre platform breached after help desk tricked into adding MFA","date":"2025-07-01","date_precision":"day","victim_org":"Qantas Airways","sector":"Transportation & Logistics","country":"Australia","primary_vector":"Help Desk Impersonation","secondary_vectors":["Vishing (Voice Phishing)","Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement reported.","outcomes":["Data Breach","Extortion"],"loss_usd":null,"loss_note":"Qantas cut executive bonuses by 15% following the breach; no direct loss figure was published.","records_affected":5700000,"threat_actor":"Scattered Spider / Muddled Libra (reported)","summary":"Qantas detected and contained an intrusion into a third-party customer servicing platform used by one of its contact centres in early July 2025. Roughly 5.7 million unique customers had data exposed, including names, email addresses, frequent flyer numbers, tier and points data, plus addresses for 1.3 million, dates of birth for 1.1 million and phone numbers for 900,000. No financial data, passports or credentials were taken. A criminal made contact and Qantas engaged the Australian Federal Police over extortion.","how_it_worked":"The crew targeted the airline's outsourced contact centre platform rather than Qantas's core systems. Their reported technique was to impersonate employees or contractors when calling IT help desks, and specifically to persuade support staff to enrol an additional MFA device onto a targeted account. That is a more durable outcome than stealing a one-time code: the attacker's own phone becomes a permanent second factor, surviving password changes and generating valid approvals indefinitely until someone audits the enrolled devices.","lessons":"Alert on and require strong verification for MFA device enrolment changes, and hold outsourced contact-centre providers to the same identity-proofing standard as internal IT.","confidence":"Confirmed","sources":[{"title":"Qantas data breach impacted 5.7 million individuals","url":"https://securityaffairs.com/179782/data-breach/qantas-data-breach-impacted-5-7-million-individuals.html","publisher":"Security Affairs"},{"title":"Qantas confirms customer data breach amid Scattered Spider attacks","url":"https://securityaffairs.com/179557/cyber-crime/qantas-confirms-customer-data-breach-amid-scattered-spider-attacks.html","publisher":"Security Affairs"},{"title":"Update on Qantas cyber incident: Wednesday 9 July 2025","url":"https://www.qantasnewsroom.com.au/media-releases/update-on-qantas-cyber-incident-wednesday-9-july-2025","publisher":"Qantas Newsroom"},{"title":"Tech support scam caused massive data breach at Australian airline Qantas","url":"https://www.theregister.com/cyber-crime/2026/07/16/tech-support-scam-caused-massive-data-breach-at-australian-airline-qantas/5272267","publisher":"The Register"}],"entry_type":"incident","slug":"2025-qantas-contact-centre-platform-breached-after-help-desk-tricked-into-add","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-qantas-contact-centre-platform-breached-after-help-desk-tricked-into-add"}]}