Vanessa Hudson has been unusually prolific with her correspondence this past week.
Over six million Qantas customers received a personalised email from the CEO on Wednesday, alerting them that cybercriminals had breached the airline’s defences. For some, a second email followed just a day later with confirmation that their name, email, phone number, and frequent flyer number had been accessed in the attack.
Hudson’s message struck a serious tone: “I want to personally apologise that this has happened and explain what we know and how we’re supporting you.”
But despite the scale of the breach, Hudson was noticeably absent from public view. Federal Cybersecurity Minister Tony Burke told the ABC on Wednesday that Hudson was on leave and he had instead spoken with the acting CEO. It wasn’t until Friday—two days after the breach was made public—that Hudson appeared in a brief interview with Channel Seven, speaking from Athens.
Even in her absence, no other Qantas executive stepped forward publicly. Media requests were declined, and calls to the airline’s press line often went unanswered.
Given the reputational damage sustained during the Alan Joyce era, the airline’s quiet response to such a serious breach of trust seemed out of step.
Taking responsibility
The breach ranks among the most significant in Australia, though Qantas has sought to calm customer concerns by assuring them that financial and passport data were not affected.
In contrast, previous breaches at Optus, Medibank, and Latitude involved more sensitive and damaging information. Those incidents also saw top executives step forward—eventually—to take responsibility in public.
In the case of Medibank, CEO David Koczkar faced the choice of quietly paying a ransom or publicly acknowledging the attack. He chose the latter and kept his job. Meanwhile, Optus CEO Kelly Bayer Rosmarin resigned after facing months of backlash for downplaying the attack’s severity.
The risks of outsourcing
The Qantas hack occurred at a third-party call centre in Manila, reportedly when an employee granted a criminal access to a customer service platform. The timing coincided with an FBI alert warning airlines of cyber threats involving third-party vendors.
The trend toward offshoring and outsourcing over the past two decades has exposed organisations to increased cybersecurity risks. Many recent data breaches, including Medibank’s, were traced back to external contractors.
While bringing operations back in-house might limit exposure, many of these incidents are rooted in human error or poor judgement. The FBI’s warning noted that attackers often use social engineering tactics to impersonate staff, bypassing security measures like multi-factor authentication.
Understated response
Hudson’s emails were reassuring—emphasising that no financial or passport data had been leaked. However, even basic personal information like names, emails, and birth dates can be weaponised by cybercriminals.
Though Qantas said it hadn’t received a ransom demand, experts warn it’s unlikely such data would be stolen and then simply discarded. Cybersecurity specialists urge affected customers to remain alert for scams and identity theft.
So far, Qantas executives have maintained a low profile—and it appears to have worked. The share price has held steady, and public backlash has been muted. Whether that calm holds may depend on how the situation develops, but history has shown that avoiding public accountability often carries a price in the long run.
