Overview
- Qantas detected unusual activity on June 30 in a third-party contact centre platform and swiftly quarantined the affected system.
- An initial review found stolen data included customer names, email addresses, phone numbers, birth dates and frequent flyer numbers, while payment, passport and login credentials were not compromised.
- The carrier has notified the Australian Cyber Security Centre, the Office of the Australian Information Commissioner and the Australian Federal Police and is supporting their ongoing investigation.
- Affected customers are being contacted directly and offered access to dedicated support lines and identity-protection resources.
- Qantas shares dipped about 2%, and cybersecurity firm CyberCX says the breach bears the hallmarks of the Scattered Spider hacker group.