Skip to main content
Breach Signal

Breach report

Travel & Hospitality

Qantas

Qantas hack results in theft of 6 million passengers' personal data

Hackers talked their way into a Qantas contact centre's customer platform in mid-2025, stealing records on about 5.7 million people; the airline's data later surfaced on a leak site as part of a wider extortion campaign against Salesforce customers.

Reported by TechCrunch

Records exposed

5.7M

About 5.7 million customers

Scale vs. largest on file

When
2025
How they got in
Voice-phishing of offshore call centre to access third-party customer platform (Salesforce)
Sector
Travel & Hospitality

On July 2, 2025, Qantas disclosed that a cybercriminal had targeted one of its customer contact centres two days earlier and gained access to a third-party platform holding customer service data. The Australian airline initially warned that the platform contained records on about 6 million customers and that a significant amount had likely been taken. After a forensic review, Qantas said on July 9 that 5.7 million unique customers were affected.

The data varied by customer. For about 4 million people, the stolen records were limited to names, email addresses and frequent flyer details, such as membership numbers and tier status. The remaining 1.7 million had additional information exposed, including home addresses, dates of birth, phone numbers, gender and meal preferences. Qantas said the system did not store credit card details, passport numbers or frequent flyer passwords and PINs, so accounts could not be accessed with the stolen information alone.

The attack came amid a wave of social engineering intrusions against airlines, including WestJet and Hawaiian Airlines, that security firms tentatively linked to the Scattered Spider collective, known for impersonating employees in phone calls to help desks. The platform involved was later confirmed to be a Salesforce environment used by a call centre in Manila. Qantas said it had been contacted by a potential threat actor and was verifying the claim, and it secured an injunction from the New South Wales Supreme Court barring anyone from accessing or publishing the stolen data.

In October 2025, a group calling itself Scattered Lapsus$ Hunters, which claimed to have stolen data from dozens of companies' Salesforce instances, published Qantas customer data on a leak site after an extortion deadline passed. Other companies named in the same campaign included Vietnam Airlines, Gap and Fujifilm. Qantas said it was working with the Australian Cyber Security Centre and federal police, offered customers a dedicated support line and identity protection advice, and faced a class action complaint. The airline also cut short-term bonuses for senior executives, including chief executive Vanessa Hudson, citing the breach.

The Qantas incident showed how attackers increasingly target the people and outsourced processes around cloud platforms rather than the software itself, using persuasive phone calls to obtain access. It became one of Australia's largest breaches since the Optus and Medibank incidents of 2022. For airlines and other consumer brands, it underlined the need to vet contact centre security and tightly restrict what data third-party connected apps can export. Customers were warned to expect phishing that uses their loyalty details.

More from the wire

More in Travel & Hospitality.

All 107 reports

Private AI for Life

Live your best life with Thinkspan: the all-in-one smart solution for organizing, securing, and accessing personal information. With Thinkspan, your life’s most important information stays protected and accessible.