
The Office of the Australian Information Commissioner (OAIC) released its preliminary findings on 16 July 2026, concluding that Qantas took “reasonable steps” to protect customer data before and after last year’s cyber-attack on a third-party call-centre platform. The breach exposed contact details and frequent-flyer numbers of around six million passengers. While class actions against other corporates have resulted in heavy penalties, the OAIC said evidence did not support commencing a commissioner-initiated investigation, effectively clearing Qantas of negligence claims for now. For global-mobility managers, the decision is reassuring: Qantas will avoid the operational distractions and potential compensation costs that a protracted legal battle might have created, preserving focus on restoring network reliability ahead of the busy northern-winter season. The carrier told corporate clients it would nonetheless continue to invest in cyber defences and incident-response training. Cyber-security experts note that the report underscores regulator expectations around vendor management and rapid breach containment—an important signal for visa-processing agencies and travel-tech suppliers that also handle sensitive passenger data. They advise corporates to treat the episode as a reminder to audit information-sharing arrangements embedded in online booking tools and expense platforms. While the OAIC finding eliminates immediate legal risk, it emphasised that data breaches are “a persistent feature of today’s digital world”. Industry analysts warn that any future incident could still trigger hefty fines under the new Privacy Penalty regime—up to A$50 million or 30 % of domestic turnover.
Source: Australian Aviation