The Australian Privacy Commissioner has warned of increased cyber risks in a preliminary report into last year’s massive Qantas data breach.
The carrier’s data breach affected more than five million customers following an attack on an overseas third-party provider contracted by QF.
The breach left many customers concerned for their privacy, and frustrated that their personal information had been subjected to unauthorised access by hackers, the commission’s preliminary report finds. However, it concludes that the information obtained during the preliminary inquiries did not reveal any omissions or failings
in the steps taken by QF to protect the personal information it held.
Australian Privacy Commissioner, Carly Kind, says before the incident QF undertook preventative measures such as auditing its overseas third-party contract centre provider, ensuring cyber and data protection training for contact centre agents and establishing processes for the destruction and de-identification of personal information once no longer required.
During and following the incident, QF took steps to reduce the impact of the breach. “Data breaches can occur despite organisations taking steps to protect personal information,” Kind says. “Agentic and advanced AI will only increase the cyber-security risks that businesses face, and it is critical that all organisations continuously review and enhance their security to protect against this growing threat.”



