Australia’s privacy regulator has declined to investigate Qantas Airways over a data breach that exposed the personal information of approximately 5.12 million Australians, finding the airline satisfied the legal threshold of “reasonable steps” under the Privacy Act 1988. The outcome raises questions about how cyber liability policies are structured, priced, and defended in Australia – particularly as regulatory enforcement activity expands and breach volumes reach record levels.
The Office of the Australian Information Commissioner (OAIC) conducted preliminary inquiries into Qantas’ compliance with the Privacy Act and the Notifiable Data Breaches (NDB) Scheme following a security incident in June 2025, with stolen data published on the dark web in October of that year. According to the OAIC, a threat actor used phone-based social engineering to deceive an employee at an overseas contact centre in the Philippines into connecting a Qantas-affiliated customer relationship management (CRM) platform to a malicious data extraction tool. The breach was identified the same day. Qantas responded by analysing system logs to identify an unauthorised login, revoking access to the affected account, assessing the scope of data exfiltration, and activating incident response protocols.
Preliminary inquiries found that Qantas had pre-incident measures in place, including cyclical audits of its overseas service provider, cyber and data protection training for contact centre staff, and processes for destroying and de-identifying personal information no longer required. Privacy Commissioner Carly Kind said the evidence did not support a finding of breach. “While I recognise the serious implications of data breaches such as this one on the lives of the Australian community, in this instance I do not consider that the evidence supports the likelihood that a breach of privacy law occurred,” Kind said, while reserving the right to reopen the matter.
Blaine Hattie, principal at Sutton Laurence King Lawyers, said the outcome was consistent with Australian Privacy Principle 11 (APP 11). “[APP 11] does not impose liability automatically when a data breach occurs. It requires reasonable steps, not perfect security,” Hattie said, as reported by ACS. He added that the findings demonstrate an organisation can “theoretically comply with the Privacy Act while five million people lose their personal information.”
Melissa Tan, partner at Lander & Rogers, said the OAIC’s report provided one of the clearest indications to date of what “reasonable steps” looks like in practice. “For insurers assessing cyber and privacy risk, the key question may not simply be whether a breach occurred, but whether the insured can demonstrate that it was prepared for one. That preparedness will often be a critical factor in determining both regulatory exposure and claims defensibility,” Tan wrote.
The OAIC placed significant weight on Qantas’ management of its overseas service provider, including pre-engagement security assessments, periodic security audits, contractual requirements to comply with privacy obligations, audit rights, and requirements for compliance with recognised standards such as ISO 27001. For underwriters, those specific controls now constitute a documented benchmark for what vendor oversight needs to look like in order to satisfy the regulator – and, by extension, to support claims defensibility after a third-party compromise.
Data retention is a further exposure variable. Qantas’ policy permitted holding personal information for up to seven years from a customer’s most recent interaction, directly affecting the volume of data available to the attacker. Under APP 11.2, organisations are required to destroy or de-identify personal information once it is no longer needed, and holding excess data creates a larger attack surface for cybercriminals. Cyber insurers increasingly ask for evidence of data destruction processes, and poor retention practices can complicate claims and weaken a policyholder’s position after an incident.
Hattie also noted that “organisations now face sophisticated cyberattacks from organised criminal groups,” adding that “punishing an organisation that took reasonable precautions could discourage prompt disclosure and cooperation after an incident,” and that “it is important to remember that Qantas was also the victim of a crime.”
The attack vector is not exceptional in the Australian context. According to the Australian Signals Directorate’s (ASD) Australian Cyber Security Centre (ACSC) Annual Cyber Threat Report 2024-25, phishing – a type of social engineering – was recorded in 60% of incidents reported to the ACSC in FY2024-25, with social engineering described as a threat becoming easier for malicious actors to use at scale, in part due to artificial intelligence technologies. Australian cyber policy wordings increasingly apply sublimits specifically to social engineering and business email compromise claims – a structural response to the human-layer vulnerability the Qantas incident illustrates.
The offshore contact centre dimension also intersects directly with the Australian Prudential Regulation Authority’s (APRA) Prudential Standard CPS 230, which came into force on July 1, 2025. CPS 230 applies to all APRA-regulated entities – including general, life, and private health insurers – and requires a structured, accountable approach to managing risks from third-party service providers, including offshore arrangements.
Under CPS 230, APRA-regulated entities must undertake appropriate due diligence before entering into or materially modifying a material arrangement and must notify APRA prior to entering into any material offshoring arrangement. While Qantas is not an APRA-regulated entity, the standard directly governs the insurers writing cyber risk in Australia – and the vendor oversight benchmark it establishes will increasingly shape how those insurers assess offshore third-party arrangements in their policyholders’ operations at underwriting.
The OAIC has stated it will continue civil penalty proceedings against Optus and Medibank in 2026, following its $5.8 million civil penalty against Australian Clinical Labs and a $50 million settlement obtained from Meta Platforms. The Medibank proceedings illustrate the potential scale of costs. By 2024, Medibank had accumulated more than $125 million in breach-related expenses, excluding APRA’s $250 million increase in the insurer’s capital adequacy requirement, which reflected weaknesses identified in its information security environment. When the Optus and Medibank class actions reach trial, they could answer questions that go directly to insurers’ balance sheets: how courts will treat negligence in data breaches at scale, how much forensic evidence will be exposed to plaintiffs, and how easily future claimant firms can follow in their wake.
Australian cyber insurance policies typically include cover for legal costs defending OAIC regulatory investigations and, in some cases, cover for regulatory penalties – though this varies by policy and jurisdiction. Since December 10, 2024, the OAIC has also been empowered to seek mid-tier civil penalties for interferences with privacy that do not meet the threshold of a “serious” interference, widening the range of circumstances in which those policy provisions may be triggered.
The OAIC received 1,205 data breach notifications in 2025 – the highest annual total since the NDB scheme commenced in 2018, representing an 8% increase over 2024 – a volume that, set against cyber gross written premium of $32 million in the March 2026 quarter and premiums falling approximately 10% through 2025, indicates the structural adequacy of cyber policy limits and conditions warrants close examination at renewal.