Qantas Data Leak & Australia’s $5.8M Privacy Penalty

Show Links

Episode Transcript

Qantas has been named among nearly 40 companies facing ransom demands from a global hacker group that claims to have stolen up to a billion records from Salesforce. Meanwhile, Australian Clinical Labs has become the first company in Australia fined under the Privacy Act — a record $5.8 million penalty — for a data breach that exposed over 220,000 patient records.

These two incidents highlight how data breaches are escalating in both scale and consequence. From social engineering to regulatory fines, the message is clear: cyber resilience isn’t optional.

Key Takeaways

  • Qantas Ransom Demands: Hackers targeted major companies via Salesforce integrations, exploiting social engineering and data export permissions.
  • $5.8M Privacy Penalty: Australian Clinical Labs was fined for failing to secure personal health information after a ransomware attack.
  • Trend Alert: Regulators are moving from warnings to penalties — “reasonable steps” for security are no longer enough.
  • Human Factor: Both incidents underline that human error and third-party access are still the biggest weak points in cybersecurity.
  • Business Impact: Breaches now have dual consequences—loss of trust and legal accountability.

Sources & Further Reading

What To Do Next

  • Book your free Empower Systems Assessmentnationalpc.com.au/empower

  • Listen to my audiobook: Sitting Duck – The Phone Call You Don’t Want to Receive → Available now on Spotify and leading audiobook platforms

  • Subscribe to the Don’t Be A Sitting Duck Podcast for daily insights

It was a quiet wintry evening when executives at Qantas and nearly 40 of the world’s big names got something nasty in their inboxes: ransom demands tied to a massive trove of customer data. Then, down in Australia, a health-services firm has become the first to face a civil penalty for a cyber-driven privacy breach—$5.8 million. These two stories show just how high the stakes have become for business cybersecurity. We’ll unpack how the hackers pulled this off, why regulators are getting tougher, and most importantly—what your business can do today to shield itself.

Welcome to the Don’t Be A Sitting Duck Podcast, I’m Leigh Kefford—let’s dive in.

Qantas is among nearly 40 global companies targeted by a hacker collective calling itself Scattered Lapsus$ Hunters, which claims to have stolen up to 1 billion customer records from Salesforce databases and is threatening to leak them unless ransom demands are met.

How It Happened & Why It Matters
The attack appears to rely heavily on voice phishing (vishing) and social engineering rather than purely technical system exploits. The hackers impersonated IT support staff to trick employees into installing rogue versions of data export tools (like modified Salesforce Data Loader) that allowed them to extract records.

Even though Salesforce claims its underlying platform wasn’t compromised, the attackers leveraged gaps in human defences and third-party integrations.

Why it matters: the personal data exposed—names, contact details, birthdates, frequent flyer numbers—can fuel phishing campaigns, identity fraud, and reputational damage. Once data is public, legal and regulatory consequences loom.

Take Action

Conduct Red Team / Social Engineering simulations focussing on vishing and impersonation. Train staff to verify unusual requests.

Enforce least privilege and segmented access to sensitive systems like CRM and cloud data exports.

Monitor and log data export activity, especially bulk or automated jobs. Use anomaly detection on unusual export volumes.

Have contracts and oversight for third-party partners who access core systems (e.g., call centres).

Plan your incident response for extortion: establish policy around whether to engage with ransoms, coordination with law enforcement, and legal injunctions.

Australian Clinical Labs (ACL) has agreed to pay a $5.8 million civil penalty under the Privacy Act in relation to a data breach at its Medlab subsidiary, which exposed the health and personal data of about 223,000 people. This marks a landmark enforcement action under Australia’s evolving privacy enforcement regime.

How It Happened & Why It Matters
The breach dates back to 2022, shortly after ACL acquired Medlab, when a ransomware attack (by the Quantum group) exposed data including personal health records, identity information, and financial data.

ACL admitted to contraventions of the Privacy Act 1988 for failing to take “reasonable steps” to secure personal information.

Why it matters: this is possibly the first civil penalty of its kind in Australia for cyber-driven privacy harm. It sends a signal that businesses may be held financially accountable, not just by class actions but via regulatory penalties.

Take Action

Review your privacy governance frameworks, ensuring accountability for data protection across corporate acquisitions or mergers.

Conduct privacy impact assessments (PIAs) whenever handling sensitive health or personal data.

Implement and document reasonable security measures (e.g. encryption, multi-factor access, regular patching) for particularly sensitive data.

Establish data breach response plans including regulatory reporting obligations, stakeholder communication, and forensic investigations.

Stay informed of changes to the Privacy Act (such as new civil penalty regimes) and ensure compliance frameworks evolve.

That’s a wrap for today’s episode! Want more cybersecurity insights? Head over to sittingduck.com.au for show notes, resources, and the latest updates. Thinking about your business security? Here’s what to do next: Book your free Empower Systems Assessment at nationalpc.com.au/empower to uncover vulnerabilities and learn how to strengthen your defences. Listen to my audiobook, Sitting Duck – The Phone Call You Don’t Want to Receive—a real-world look at Business Email Compromise. Available now on Spotify and leading audiobook platforms.

Until next time—stay safe, stay informed, and don’t be a sitting duck!

This podcast was produced by National PC, delivering expert cyber security services in Townsville and Cairns through our Empower Managed IT solutions—secure, reliable, and built for North Queensland businesses.