Menu
Browse

Cyber Incident Victim: Qantas

Date:

Jun 2025

Location:

Australia

Summary

Qantas experienced a vishing attack in which an attacker posing as IT support convinced a contact‑centre agent to link a malicious data‑extraction tool to the airline’s customer‑relationship platform, allowing the exfiltration of millions of customer records. The compromised data included names, email addresses, phone numbers, dates of birth, addresses, gender, meal preferences and frequent‑flyer details, while credit‑card information, passport data, passwords and login credentials were not accessed. After detecting anomalous activity, the airline contained the incident, notified the Australian Federal Police, the Australian Cyber Security Centre and the Office of the Australian Information Commissioner, and established a dedicated support line for affected customers. The OAIC concluded its preliminary inquiries without opening a formal investigation, noting that the airline had taken remedial steps and that a default CRM setting enabling the connection has since been changed by the software provider.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 2 techniques
Threat Actors Type Location
0 actors Available to members Available to members

Description

Qantas experienced a security incident and immediately took steps to contain the affected system, confirming that its systems remain secure after containment. The airline began contacting customers to inform them of the incident, to apologise, and to provide details about the support available to them. As part of this response Qantas established a dedicated customer support line that can be reached at 1800 971 541 or +61 2 8028 0534, through which customers receive specialist identity‑protection advice and resources. Customers were also advised that they can check their flight details at any time via the Qantas App or the Qantas website and that Qantas will never request passwords or other sensitive information via email, text or phone calls.

Cyber Incident Image

In addition to direct customer outreach, Qantas created a dedicated information page where it pledges to continue sharing updates about the incident as they become available. The airline notified the Australian Cyber Security Centre and the Office of the Australian Information Commissioner about the breach. Because the incident is of a criminal nature, Qantas also notified the Australian Federal Police. Qantas stated that it is working closely with the Federal Government’s National Cyber Security Coordinator, the Australian Cyber Security Centre and independent specialised cyber‑security experts, and that it will continue to support these agencies throughout the investigation.

Qantas is presently contacting customers to raise awareness of the incident, to apologise and to outline the support options available. Individuals whose information may have been compromised will receive further communication from the airline. Those seeking assistance can call the dedicated support line at 1800 971 541 or +61 2 8028 0534 for specialist identity‑protection advice and resources, and they can verify their flight details through the Qantas App or website. The airline confirmed that its systems remain secure after the containment measures were applied.

Qantas has taken immediate steps to contain the incident, maintains the security of its systems, and will keep the dedicated information page updated with the latest developments. It has formally notified the Australian Cyber Security Centre, the Office of the Australian Information Commissioner and the Australian Federal Police, and will continue to cooperate with these agencies as the investigation proceeds.

Sources
Sources available to members
3 sources