Desk live·
ForensicPost
Cloud/Aviation/File 25-0701

Through the Call Centre, Into the Platform, out With 5.7 Million Records

Qantas detected an incident on 30 June 2025 in which an attacker targeted a call centre and reached a third-party customer servicing platform. The airline later confirmed as many as 5.7 million customers affected.

Constructed geometry · not a chart of case data
TargetQantas
ActorUnattributed
D. Kennedy12 min readConfidence: high2 sources reviewed

Qantas detected an incident on 30 June 2025 in which an attacker targeted a call centre and obtained access to a third-party customer servicing platform. The airline subsequently confirmed that as many as 5.7 million customers were affected.

Two Structures This Database Files Separately, Combined

The call centre is the identity-led route — the human who can be persuaded, filed at 25-0512 and throughout the identity theme. The third-party servicing platform is the concentration route — the supplier holding everybody’s customers, filed at 25-0801 and 25-0814.

Here they compose. A single conversation produced access to an estate holding 5.7 million records, because the person being deceived was authorised on a platform whose scope was the entire customer base.

The lesson is not that call centres need better training. It is that the blast radius of a successful social-engineering call is set by an architectural decision made elsewhere — how much a servicing agent’s session can reach — and nobody makes that decision while thinking about social engineering.

An Airline’s Customer File Is A Travel History

Frequent-flyer records are not simply contact details. They describe where a person has been, how often, with whom they were booked, and what they paid — a longitudinal movement record accumulated over years.

That is the dataset described at 25-0725 as a component of pattern-of-life collection. This desk is not suggesting any such purpose here; the point is that the same records support entirely different uses depending on who holds them, and an airline’s risk assessment considers only fraud.

Same-Day Detection, Again

The incident was detected on the day it occurred. As at 25-1027, that deserves stating plainly against a corpus full of multi-month dwell times.

It also did not prevent the outcome. When the access route is a legitimate session on a platform designed for bulk customer servicing, extraction is fast, and detection speed stops being the control that matters.

How we reported this

Compiled from public reporting of company statements, listed below. The servicing platform is not named. The affected figure is the company’s upper bound as reported. Corrections: corrections@forensicpost.com.

Sources
  1. Top 10 cyber-attacks of 2025Infosecurity Magazine
  2. Top data breaches in 2025, month-wiseSecurity Boulevard
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary