Technology

Qantas Data Breach Exposes Millions of Records

In October 2025, Australia’s flag carrier Qantas disclosed that a major cyberattack had compromised the personal data of about 5 million customers. The breach stemmed from a hack in July 2025 of a third-party contact centre platform (reportedly a Salesforce-based system), where attackers used social engineering to trick call centre staff into handing over access credentials. 

The stolen data included names, email addresses, birth dates, phone numbers, home/business addresses, and frequent‑flyer numbers, but no payment information, credit card data, or passwords. No login credentials or Frequent Flyer account details were taken, and Qantas says its own systems and loyalty accounts remain secure. Once the airline detected unusual activity on June 30 and contained the attack, the hackers demanded a ransom. When Qantas (and others) did not pay, the cybercriminals, a group calling itself Scattered Lapsus$ Hunters (part of the “Trinity of Chaos” gang), publicly released the data on the dark web in mid-October.

Scope of the Breach and Data Lost

Qantas says roughly one million customers had sensitive data exposed (birthdates, phone numbers, and addresses), and another four million had only their name and email address compromised. Privacy regulators confirmed that some federal politicians’ home addresses were among the leaked information. Importantly, no passports, identity documents, credit card numbers, or other financial details were obtained by the hackers. Frequent Flyer account passwords, PINs, and logins were also not accessed. Qantas’s analysis shows the data mostly consisted of:

  • Customer name, email address, and (in many cases) the Frequent Flyer number and tier/status,
  • In some records, additional fields like residential and business addresses, date of birth, phone number, gender, and even meal preferences are included.

No user passwords or travel booking details were exposed. Qantas emphasises that the stolen information alone “is not enough to gain access to Frequent Flyer accounts,” especially because every account has two‑factor authentication (via one‑time passwords or authenticator apps) by default.

Cybersecurity experts urge that companies need to hire people with proper cyber security training, and must treat this event as a wake-up call to secure every link in the chain, because even an ostensibly secure global carrier can fall prey through a single service partner.

Impact on Customers and Frequent Flyers

Although the data was limited compared to other recent Australian breaches, customers face real risks of fraud and phishing. Armed with personal details, scammers can craft highly convincing impersonation attempts. For example, experts warn thieves may use people’s names, flight dates, and addresses to send fake rescheduling notices or bogus points redemption offers to trick travellers into revealing more information.

Indeed, Qantas and the government have already seen a surge in cold calls and spoof emails targeting passengers. Customers report callers posing as Qantas staff or travel agents asking for additional verification, a classic confidence trick. The government’s Cyber Security Minister, Tony Burke, urged people to “hang up on cold calls” and always verify by dialling official company numbers. Qantas also reminds customers that its emails always come from @qantas.com (never from domains like @qantas.net or @qantas.biz) and that the airline will never ask for passwords or payment details over the phone.

Frequent Flyers in particular should be cautious. CSIRO’s Dr Marthie Grobler notes that knowledge of a member’s tier level and travel history can make phishing pitches more believable. Attackers might impersonate Qantas to say, “Your flight has changed, please confirm your itinerary to receive bonus points,” or similar. Although actual accounts were untouched, passengers are advised to review any unusual communications. Qantas recommends updating passwords out of caution and ensuring multifactor authentication is enabled on email and other critical accounts.

How to Stay Safe After the Breach

Qantas and cybersecurity authorities stress the usual “stay alert” steps. Key recommendations include:

  • Verify unsolicited contacts. If someone calls or emails claiming to be from Qantas (or any business) about your account or points, hang up and call back using an official number from the company’s website. Never confirm personal information on the spot.
  • Use strong, unique passwords and 2FA. Turn on two-factor authentication (via an authenticator app or SMS) for email, Qantas, and other important accounts. Choose passwords you don’t reuse elsewhere so that even leaked data can’t open other accounts.
  • Beware of phishing. Treat any unexpected emails or texts with caution. Check sender addresses carefully (Qantas uses only official domains) and don’t click links or attachments in suspicious messages. You can contact Qantas through its support line if ever in doubt.
  • Monitor your accounts and credit. Keep an eye on bank and credit card statements for unusual charges. Australian customers may consider free ID protection or credit monitoring services to get alerts for any misuse of their information.
  • Report scams. If you receive a possible Qantas scam (e.g., a fake flight voucher email), report it immediately to Scamwatch.gov.au or your local authorities. Sharing your experience can help warn others.

Importantly, consider further education: enrolling in professional cybersecurity training can help individuals and businesses recognise and defend against social engineering attacks like these. Such courses teach the latest phishing tactics, how to spot deepfakes or spoof content, and best practices for securing devices and networks. Staying informed through official channels like the Australian Cyber Security Centre’s advice pages is also crucial.

Regulators and police are now involved. Qantas reported the breach to the Australian Cyber Security Centre (ACSC), the Office of the Australian Information Commissioner (OAIC), and the Australian Federal Police. The AFP cybercrime squad is investigating the hack, though arrests have not yet been announced. Meanwhile, legal firms have moved quickly: one major law firm lodged a privacy complaint on behalf of customers, alleging Qantas failed to adequately safeguard data. 

A class action suit has also been filed seeking damages and compensation for customers. If regulators find Qantas breached privacy laws, the airline could face fines up to A$50 million (or 30% of its turnover). By comparison, past incidents like the Medibank hack (2022) are still before the courts, showing how protracted such cases can be.

At present, Qantas has obtained a court injunction forbidding anyone (including the hackers) from accessing or publishing the stolen data. This means that possessing the leaked files, even if they contain your own records, is technically illegal in Australia. Officials like Minister Burke have warned the public not to go hunting for their info on the dark web. Still, security agencies expect fraudsters will illegally exploit the data regardless, so law enforcement and Qantas’s cyber teams are monitoring for any misuse.

Qantas’s Response and Next Steps

Qantas has vowed to support affected customers and shore up its systems. The airline says it detected the intrusion on June 30 via unusual activity on an outsourced contact‑centre platform and immediately contained it. Management reports that no Qantas-owned network was breached; it was entirely in the third-party system. Qantas promptly notified all impacted customers by email, explaining which of their personal fields were exposed. It has set up a dedicated 24/7 hotline and provided identity protection advice services for the most at-risk flyers.

In public statements, Qantas apologised for the incident and emphasised that it is taking “continued vigilance” measures. The airline secured an injunction (through the NSW Supreme Court) to block any use or sale of the stolen data. Internally, Qantas says it has “put in place additional security measures, increased training across our teams and strengthened system monitoring and detection” since the breach. It is working with independent cyber experts and government agencies (ACSC, AFP, OAIC) to investigate further and prevent follow-on attacks.

Moving forward, Qantas urges all customers to change their passwords if they haven’t recently, and to watch out for scams referencing this breach. The airline will continue updating its online support page with FAQs and advice. In the coming months, investigators will determine how the hackers got in (though social engineering is likely) and whether any new defences can block similar attacks. 

Sweta Bose

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

3 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

3 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

4 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

4 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

4 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

6 hours ago