| In July 2026, the OAIC closed its year-long preliminary inquiries into the June 2025 Qantas data breach (which affected approximately 5.12 million Australians, of some 5.7 million customers in total), deciding not to commence a Commissioner-initiated investigation because the evidence did not indicate a likelihood that Qantas had failed to take reasonable steps. That outcome matters more than the breach itself: it shows regulators are prepared to distinguish between organisations that failed to take reasonable steps and organisations that were breached despite taking them. For boards, the lesson is that a documented, proportionate security process (not a perfect outcome) is what APP 11 actually demands. |
Every business asks the same question after a competitor’s breach makes headlines: could that happen to us, and would we be found at fault if it did? The OAIC’s handling of the Qantas matter gives a rare, concrete answer.
On 28 June 2025, an attacker impersonating Qantas IT support telephoned an agent at an overseas third-party contact centre contracted by Qantas and talked that agent into connecting a modified data extraction tool to the customer relationship management platform, a voice-based social engineering technique known as vishing. Roughly 5.12 million Australians were affected, out of approximately 5.7 million customers overall. Twelve months later, the regulator’s preliminary inquiries closed with the observation that the evidence did not indicate a likelihood that Qantas had failed to take reasonable steps under Australian Privacy Principle 11, or that it had failed to take reasonable steps to ensure its overseas provider complied with the APPs. The report is careful to add that these are observations only, that it makes no concluded findings, and that the Commissioner may still commence an investigation.
The Line the Regulator Drew
APP 11 has never required perfect security; it requires reasonable steps proportionate to the risk. Until now, that standard has mostly been tested in hindsight, after a breach, with regulators understandably inclined to find fault. The Qantas report is different: it is a regulator setting out, in a published document, why it considered training, access controls and technical safeguards to have been reasonable even though a sophisticated social engineering attack still succeeded, and doing so without waiting for a formal investigation to compel it.
There is a further nuance worth drawing out, and it is the most instructive part of the report. The OAIC observed that standard security awareness training focuses on credential theft and does not usually address the less common tactic of inducing an employee to authorise access through legitimate system interactions, so the attack would likely have succeeded even with that training in place: an outcome only made more likely with the speed and sophistication added via AI. It also observed that the vulnerability arose from a default configuration permitting an end user to authorise a third-party application connection, meaning Qantas’ role-based access controls would not have prevented it either. The setting has since been changed by the CRM provider for all its customers.
Read together, those two observations do real work. The regulator accepted that a control can be reasonable and still not prevent the attack: the standard is not whether the organisation anticipated every technique; it is whether it maintained a defensible process for identifying and responding to risk. But note where the risk actually sat: in a vendor’s default setting that no one at Qantas chose. That is where the next argument will be. A default you never selected is still a configuration you own, and the answer to “we didn’t know it was set that way” is increasingly going to be that you should have asked.
That does not mean the bar has dropped. It means the bar has been described more precisely: the test is whether an organisation can demonstrate a considered, current, and proportionate security posture, not whether it can guarantee an outcome no organisation can guarantee.
Why Documentation Is the Real Deliverable
The practical takeaway is evidentiary. An organisation that can show a risk assessment, a training program, access control reviews, and an incident response plan (all dated, current, and actually followed) is in a fundamentally better position than one relying on a general assertion that “we take security seriously.” Note too that the regulator credited what happened after the breach. The report records that Qantas identified and escalated the incident promptly and contained the threat, and that it did so consistently with the steps it had already taken to integrate recovery processes into its cyber security risk management system; the OAIC’s view being that the impact of the breach was reduced by the timely implementation of that incident management and reporting framework. The point is not that Qantas responded well; it is that responding well was the predictable output of a framework built beforehand. Reasonableness is assessed across the whole timeline, so a response plan that has actually been exercised is part of the evidentiary file, not an appendix to it.
In practice, this is where most organisations are exposed. When I ask a client to produce their risk assessment, the answer falls into one of three categories. Often it does not exist at all: security is being managed competently by people who have simply never written down what they considered. Sometimes it exists but is generic: a downloaded template populated with risks that could apply to any business, which tells a regulator nothing about how this organisation thought about its own information flows. Most commonly it exists, it was thoughtful when it was written, and it has not been touched since, because it was never structured in a way that forces the considerations to be revisited. Of course this insight is my own experience and differs across industries and even within industries.
The point remains that a risk assessment without a review trigger, a named owner and a date is a historical document, and the Qantas outcome turned on evidence that was none of those things. If you take one action from this article, make it the third category: build the assessment so that keeping it current is a scheduled obligation rather than a good intention.
The under-reported half of this outcome is third-party oversight. The compromise occurred at an overseas contact centre provider, not inside Qantas, so the regulator had to assess not only Qantas’ own controls but whether it had taken reasonable steps to ensure that provider complied with the APPs. Qantas cleared both limbs. For most organisations, the second limb is the weaker one: supplier security assessments are performed at onboarding, then never repeated, and the evidence of them lives in an inbox rather than a register. If your material personal-information flows pass through a provider, your APP 11 file is incomplete without a dated record of how that provider is assessed, what access it holds, and when that access was last reviewed.
The regulator’s comments also flagged agentic and advanced AI as a growing driver of cybersecurity risk, and framed continuous review as the standard going forward, not a one-off exercise.
What Boards Should Ask Now
These are the questions a board, or the general counsel advising it, should be able to answer today:
- Can we produce a current risk assessment on request, not reconstruct one after an incident?
- Is our staff training program documented, current, and does it reflect actual attack methods such as social engineering?
- Do we have a tested incident response plan, and can we show when it was last reviewed?
- Have we reviewed our security posture since AI-enabled threats became a mainstream vector?
- Which third parties hold or access our personal information, when was each last assessed, and can we produce that assessment?
- Do we know what the default security settings are in the platforms our providers use on our behalf, and who owns the decision to change them?
- If we were asked today for the evidence behind each answer above, how long would it take to assemble, and would it be dated before the incident or after it?
Disclaimer
This article is general information only and is not legal advice. It discusses the OAIC’s public findings regarding a 2025 data breach matter but does not reproduce those findings and does not constitute an assessment of any organisation’s compliance position. Obtain advice specific to your circumstances before acting.
Source: Office of the Australian Information Commissioner, Report into preliminary inquiries of Qantas (published July 2026), available at https://www.oaic.gov.au/privacy/privacy-assessments-and-decisions/privacy-decisions/Investigation-inquiry-reports/report-into-preliminary-inquiries-of-qantas.
