Skip to main content

Qantas confirms access to data of millions of customers via a provider

Qantas reported that an attacker had accessed a third-party customer service platform used by a call centre.

CybersecuritySeintec Team2-3 min read
Qantas confirms access to data of millions of customers via a provider

News summary

Qantas reported that an attacker had accessed a third-party customer service platform used by a call centre. The database contained data on millions of customers.

SaaS and providers form part of the company's actual perimeter. MFA, permissions, integrations, support accounts, and auditing in external services must fall under the same security governance.

Source: Reuters — 1 July 2025

What happened

Qantas reported on 1 July 2025 that an attacker had accessed a third-party customer service platform used by a call centre, according to Reuters. The affected database contained information belonging to millions of the airline's customers.

Access occurred through the external provider managing the customer service platform, not directly within Qantas's internal systems, placing the origin of the incident with a third party holding access to the company's data.

What it means for a mid-sized business

The case confirms that SaaS and external service providers form part of a company's real security perimeter, even when not under its direct technical control. An incident at the provider has the same effect on customer data as an internal incident would.

Multi-factor authentication, permission control, integration management, oversight of support accounts and periodic audits of external services should be part of the same security governance model applied to internal systems.

What to review

Controls to apply to external providers with access to customer data:

  • Which external providers, including call centres or support teams, have access to customer data.
  • What security controls the contract requires from those providers and whether they are periodically verified.
  • Whether an agreed notification procedure exists in case of an incident at the provider.
  • Whether data shared with the provider is limited to what is strictly necessary for the service.

Frequently Asked Questions

Was the attack directly on Qantas?
No; it occurred through a customer service platform managed by a third party used by a call centre.
Is a company responsible for data managed by an external provider?
In terms of security and reputation, yes; the impact on customers is the same even if the incident occurs at a third party.
What can be required from an external provider handling customer data?
Multi-factor authentication, strict access control, permission audits and a clear incident notification procedure.

Concepts mentioned in this article: SaaS

Technology only adds value when it is well-designed, protected, and maintained. Seintec can help you implement these best practices in your company; speak with our team to assess your environment.

Contact Seintec

Related service

Cybersecurity

We shield your business so it never stops.

Next step

Would you like to implement these improvements in your company?

Speak with a Seintec expert and we will review how this applies to your infrastructure together.