01Summary
On June 30, 2025, Qantas detected unusual activity on a third-party customer service platform used by its Manila-based contact centre. Hackers gained access via social engineering (vishing) and exfiltrated customer records. The airline confirmed 5.7 million unique customers were impacted. In October 2025, the group Scattered LAPSUS$ Hunters leaked the data on the dark web after a ransom deadline passed.
02Background
Qantas is Australia's largest airline and national carrier. Like many large organisations, it relies on third-party vendors for contact centre operations, creating supply-chain security risks.
03Key revelations
- 01High risk of third-party / supply chain attacks in aviation.
- 02Effectiveness of vishing against offshore contact centres.
- 03Data eventually leaked after ransom deadline.
04Technical analysis
Attackers used vishing/social engineering to compromise a call centre worker, gaining access to a Salesforce-based third-party platform. The platform stored customer service records but did not contain payment card data or passports.
- Attack vector
- Vishing / Social Engineering on third-party vendor
- Attack method
- Credential compromise and data exfiltration
- Initial access
- Vishing (Voice Phishing)
- Exfiltration
- Bulk data extraction
Vulnerabilities exploited
- Human vulnerability to vishing
- Third-party platform access controls
05Threat actor
Scattered LAPSUS$ Hunters (linked to Scattered Spider tactics) – known for aggressive social engineering, vishing, and targeting large organisations via third-party vendors.
Aliases
- Scattered Spider
- SH
Attribution sources
- Qantas statements
- BleepingComputer
- The Guardian
- Cybersecurity researchers
06Victims and impact
Countries affected
- Australia
- Global
07Data exposed
Data types
- PII
- Names
- Email addresses
- Phone numbers
- Dates of birth
- Frequent Flyer numbers
- Addresses
- Meal preferences
08Financial damage
Reputational damage, increased scam activity targeting customers, regulatory scrutiny, and potential fines.
09Timeline
- 2025-06-30Unusual activity detected on third-party platform.
- 2025-07-02Qantas publicly discloses the incident.
- 2025-07-09Qantas confirms 5.7 million customers affected.
- 2025-10-11Data leaked on dark web after ransom deadline.
10Reaction and fallout
Public reaction
Significant customer frustration and concern over increased phishing/scam risks.
Political impact
Increased Australian government and regulatory focus on airline cybersecurity and third-party risk management.
11Legal
Ongoing investigations by OAIC and potential class actions.
Civil lawsuits
- Anticipated class-action lawsuits and regulatory actions
12Aftermath
Policy changes
- Stronger oversight of third-party vendors in critical industries.
Security improvements
- Enhanced vendor security assessments
- Improved monitoring of third-party platforms
13Significance and legacy
Significance
One of Australia's largest customer data breaches in 2025, highlighting systemic third-party risks.
Legacy
Accelerated industry-wide improvements in supply chain security and third-party risk management.
14Disclosure and media
- Authentication
- Hacker leak site and Qantas official confirmations
Publishing organisations
- The Guardian
- BleepingComputer
- Reuters
- ABC News
15Field notes
- 01The breach occurred through an offshore (Philippines) contact centre using a Salesforce platform.
16Resolution
Data leaked on dark web in October 2025; Qantas continues notifying customers and supporting scam prevention.
17Sources
Official documents
- Qantas Cyber Incident Customer Page
References
- [1]Qantas official statements
- [2]The Guardian coverage
- [3]Reuters reports
- [4]BleepingComputer









