The Authorization Was Legitimate. Nobody Watched What Happened Next.
A session control gap — not a broken identity control — is why approximately 5.67 million Qantas customer records were compromised. No password was stolen. No multi-factor prompt was defeated, because the attacker never logged in at all. The Office of the Australian Information Commissioner concluded its preliminary inquiries in July 2026 without commencing a…
