{"id":1223,"date":"2025-07-10T08:53:20","date_gmt":"2025-07-10T08:53:20","guid":{"rendered":"https:\/\/ft365.org\/index.php\/2025\/07\/10\/qantas-confirms-5-7-million-customers-hit-by-data-breach\/"},"modified":"2025-07-10T08:53:20","modified_gmt":"2025-07-10T08:53:20","slug":"qantas-confirms-5-7-million-customers-hit-by-data-breach","status":"publish","type":"post","link":"http:\/\/ft365.org\/index.php\/2025\/07\/10\/qantas-confirms-5-7-million-customers-hit-by-data-breach\/","title":{"rendered":"Qantas Confirms 5.7 Million Customers Hit by Data Breach"},"content":{"rendered":"<div>\n<p><img decoding=\"async\" src=\"https:\/\/ft365.org\/wp-content\/uploads\/2025\/06\/localimages\/ea721ff9-8ba4-4d88-b386-57e9e1606077.jpg?width=64&#038;height=64&#038;mode=crop&#038;scale=both&#038;format=webp\" alt=\"Photo of Phil Muncaster\" loading=\"lazy\"><\/p>\n<\/div>\n<div id=\"cphContent_pnlArticleBody\">\n<div id=\"layout-c6f0780a-3259-4fc5-9566-017e1af09d99\" data-layout-id=\"2\" data-edit-folder-name=\"text\" data-index=\"0\">\n<p>Qantas has confirmed that nearly six million customers have had their personal data compromised in\u00a0a recent breach.<\/p>\n<p>The Australian airline said that most (four million) of those affected had their name, email address and Qantas Frequent Flyer details exposed in the incident. Of these individuals, 1.2 million had only their name and email compromised.<\/p>\n<p>Of the remaining 1.7 million:<\/p>\n<ul>\n<li>1.3 million customers had their residential and\/or business address compromised<\/li>\n<li>1.1 million had their date of birth compromised<\/li>\n<li>900,000 had records including their mobile, landline or business phone number revealed<\/li>\n<li>400,000 had their gender exposed<\/li>\n<li>10,000 had details on meal preferences stolen\u00a0<\/li>\n<\/ul>\n<p>Those affected are currently being emailed by the airline to notify them of the specific data types taken in the raid.\u00a0<\/p>\n<p>Qantas claimed that there\u2019s no evidence the stolen data has been released. It also confirmed that no card, financial or passport data was compromised \u2013 nor were passwords, PINs or logins.<\/p>\n<p>However, even limited personal information like names, email addresses and frequent flyer numbers could be used by fraudsters to make phishing campaigns more convincing. These could be designed to elicit more sensitive financial information if, for example, scammers sent emails\/texts impersonating Qantas.\u00a0<\/p>\n<p>Just days before Qantas revealed news of the data breach,\u00a0the FBI warned that threat actors\u00a0from the infamous Scattered Spider collective were targeting the airline industry, although it\u2019s still unclear whether they are responsible for this incident.<\/p>\n<p><em>Read more about the Qantas cyber-attack: Qantas Reveals \u201cSignificant\u201d Contact Center Data Breach<\/em><\/p>\n<p>The Australian firm did confirm on Monday that\u00a0an unnamed threat actor\u00a0had contacted it, perhaps in a bid to extort the company.<\/p>\n<p>The original attack bore some of the hallmarks of a Scattered Spider campaign, given that it involved the targeting of a call center.<\/p>\n<p>Actors linked to the group, many of whom are native English speakers, are known to be adept at socially engineering IT helpdesk and call center staff into handing over or resetting passwords.<\/p>\n<p>In this case, they were able to gain access to a third-party customer servicing platform, and from there, data on 5.7 million Qantas customers.<\/p>\n<h2>Qantas Responds<\/h2>\n<p>Qantas group CEO, Vanessa Hudson, said the firm had taken additional security measures to help prevent a similar event occurring in the future.<\/p>\n<p>\u201cWe remain in constant contact with the National Cyber Security Coordinator, Australian Cyber Security Centre and the Australian Federal Police. I would like to thank the various agencies and the Federal Government for their continued support,\u201d she added.<\/p>\n<p>The airline urged customers affected by the breach to:<\/p>\n<ul>\n<li>Stay on the lookout for phishing emails, texts and phone calls, especially when the sender\/caller purports to be from Qantas<\/li>\n<li>Use multi-factor authentication (MFA) on all email and other accounts<\/li>\n<li>Stay up to date on the latest threats by visiting the Australian Cyber Security Centre and the National Anti-Scam Centre\u2019s Scamwatch site<\/li>\n<li>Never provide any online account passwords, or personal or financial information, to \u2018officials\u2019 who get in touch over the phone\/via email or text<\/li>\n<li>Visit IDCARE\u2019s Learning Centre and the Office of the Australian Information Commissioner website for more information on how to protect personal data<\/li>\n<\/ul><\/div>\n<p>Image\u00a0credit: Art of Ngu \/ Shutterstock.com<\/p>\n<\/p><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Qantas has confirmed that nearly six million customers have had their personal data compromised in\u00a0a recent breach. The Australian airline said that most (four million) of those affected had their name, email address and Qantas Frequent Flyer details exposed in the incident. Of these individuals, 1.2 million had only their name and email compromised. Of<\/p>\n","protected":false},"author":2,"featured_media":1224,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-1223","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"featured_image_urls":{"full":["http:\/\/ft365.org\/wp-content\/uploads\/2025\/07\/1223-178801d5-82cc-464b-9b66-0b40958c39f7.jpg",300,300,false],"thumbnail":["http:\/\/ft365.org\/wp-content\/uploads\/2025\/07\/1223-178801d5-82cc-464b-9b66-0b40958c39f7-150x150.jpg",150,150,true],"medium":["http:\/\/ft365.org\/wp-content\/uploads\/2025\/07\/1223-178801d5-82cc-464b-9b66-0b40958c39f7.jpg",300,300,false],"medium_large":["http:\/\/ft365.org\/wp-content\/uploads\/2025\/07\/1223-178801d5-82cc-464b-9b66-0b40958c39f7.jpg",300,300,false],"large":["http:\/\/ft365.org\/wp-content\/uploads\/2025\/07\/1223-178801d5-82cc-464b-9b66-0b40958c39f7.jpg",300,300,false],"1536x1536":["http:\/\/ft365.org\/wp-content\/uploads\/2025\/07\/1223-178801d5-82cc-464b-9b66-0b40958c39f7.jpg",300,300,false],"2048x2048":["http:\/\/ft365.org\/wp-content\/uploads\/2025\/07\/1223-178801d5-82cc-464b-9b66-0b40958c39f7.jpg",300,300,false],"morenews-featured":["http:\/\/ft365.org\/wp-content\/uploads\/2025\/07\/1223-178801d5-82cc-464b-9b66-0b40958c39f7.jpg",300,300,false],"morenews-large":["http:\/\/ft365.org\/wp-content\/uploads\/2025\/07\/1223-178801d5-82cc-464b-9b66-0b40958c39f7.jpg",300,300,false],"morenews-medium":["http:\/\/ft365.org\/wp-content\/uploads\/2025\/07\/1223-178801d5-82cc-464b-9b66-0b40958c39f7.jpg",300,300,false],"crawlomatic_preview_image":["http:\/\/ft365.org\/wp-content\/uploads\/2025\/07\/1223-178801d5-82cc-464b-9b66-0b40958c39f7-146x146.jpg",146,146,true]},"author_info":{"display_name":"henry","author_link":"http:\/\/ft365.org\/index.php\/author\/henry\/"},"category_info":"<a href=\"http:\/\/ft365.org\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","_links":{"self":[{"href":"http:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/posts\/1223","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"http:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/comments?post=1223"}],"version-history":[{"count":0,"href":"http:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/posts\/1223\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/media\/1224"}],"wp:attachment":[{"href":"http:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/media?parent=1223"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/categories?post=1223"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/ft365.org\/index.php\/wp-json\/wp\/v2\/tags?post=1223"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}