Qantas confirms access to data of millions of customers via a provider
Qantas reported that an attacker had accessed a third-party customer service platform used by a call centre.

News summary
Qantas reported that an attacker had accessed a third-party customer service platform used by a call centre. The database contained data on millions of customers.
SaaS and providers form part of the company's actual perimeter. MFA, permissions, integrations, support accounts, and auditing in external services must fall under the same security governance.
Source: Reuters — 1 July 2025
What happened
Qantas reported on 1 July 2025 that an attacker had accessed a third-party customer service platform used by a call centre, according to Reuters. The affected database contained information belonging to millions of the airline's customers.
Access occurred through the external provider managing the customer service platform, not directly within Qantas's internal systems, placing the origin of the incident with a third party holding access to the company's data.
What it means for a mid-sized business
The case confirms that SaaS and external service providers form part of a company's real security perimeter, even when not under its direct technical control. An incident at the provider has the same effect on customer data as an internal incident would.
Multi-factor authentication, permission control, integration management, oversight of support accounts and periodic audits of external services should be part of the same security governance model applied to internal systems.
What to review
Controls to apply to external providers with access to customer data:
- Which external providers, including call centres or support teams, have access to customer data.
- What security controls the contract requires from those providers and whether they are periodically verified.
- Whether an agreed notification procedure exists in case of an incident at the provider.
- Whether data shared with the provider is limited to what is strictly necessary for the service.
Frequently Asked Questions
- Was the attack directly on Qantas?
- No; it occurred through a customer service platform managed by a third party used by a call centre.
- Is a company responsible for data managed by an external provider?
- In terms of security and reputation, yes; the impact on customers is the same even if the incident occurs at a third party.
- What can be required from an external provider handling customer data?
- Multi-factor authentication, strict access control, permission audits and a clear incident notification procedure.
Concepts mentioned in this article: SaaS
Technology only adds value when it is well-designed, protected, and maintained. Seintec can help you implement these best practices in your company; speak with our team to assess your environment.
Contact SeintecRelated service
Cybersecurity
We shield your business so it never stops.