What happened
Qantas detected and contained an intrusion into a third-party customer servicing platform used by one of its contact centres in early July 2025. Roughly 5.7 million unique customers had data exposed, including names, email addresses, frequent flyer numbers, tier and points data, plus addresses for 1.3 million, dates of birth for 1.1 million and phone numbers for 900,000. No financial data, passports or credentials were taken. A criminal made contact and Qantas engaged the Australian Federal Police over extortion.
How the deception worked
The crew targeted the airline's outsourced contact centre platform rather than Qantas's core systems. Their reported technique was to impersonate employees or contractors when calling IT help desks, and specifically to persuade support staff to enrol an additional MFA device onto a targeted account. That is a more durable outcome than stealing a one-time code: the attacker's own phone becomes a permanent second factor, surviving password changes and generating valid approvals indefinitely until someone audits the enrolled devices.
AI involvement · No AI reported
No AI involvement reported.
The control that would have caught it· our reading, not a claim from the sources
Alert on and require strong verification for MFA device enrolment changes, and hold outsourced contact-centre providers to the same identity-proofing standard as internal IT.
Sources (4)
- Qantas data breach impacted 5.7 million individualsSecurity Affairs·securityaffairs.comOpen ↗
- Qantas confirms customer data breach amid Scattered Spider attacksSecurity Affairs·securityaffairs.comOpen ↗
- Update on Qantas cyber incident: Wednesday 9 July 2025Qantas Newsroom·qantasnewsroom.com.auOpen ↗
- Tech support scam caused massive data breach at Australian airline QantasThe Register·theregister.comOpen ↗
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.