EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/data-breach/2025-qantas-data-breach
061/430

File EL-0370HighOngoingData Breach / Extortion with Data Exfiltration

Qantas Data Breach

Also filed as Qantas Salesforce Breach · Qantas Third-Party Contact Centre Hack

Major data breach affecting 5.7 million Qantas customers through a compromised third-party contact centre platform (Salesforce). Data was later leaked on the dark web after ransom demands were not met.

  • #aviation
  • #pii
  • #frequent-flyer-data
  • #third-party-breach
  • #vishing
  • #extortion
Notoriety8/10
Event
30 Jun 2025
Disclosed
2 Jul 2025
Target
Qantas
Actor
Scattered LAPSUS$ Hunters
Scale
5.7M people
Status
Ongoing

01Summary

On June 30, 2025, Qantas detected unusual activity on a third-party customer service platform used by its Manila-based contact centre. Hackers gained access via social engineering (vishing) and exfiltrated customer records. The airline confirmed 5.7 million unique customers were impacted. In October 2025, the group Scattered LAPSUS$ Hunters leaked the data on the dark web after a ransom deadline passed.

02Background

Qantas is Australia's largest airline and national carrier. Like many large organisations, it relies on third-party vendors for contact centre operations, creating supply-chain security risks.

03Key revelations

  1. 01High risk of third-party / supply chain attacks in aviation.
  2. 02Effectiveness of vishing against offshore contact centres.
  3. 03Data eventually leaked after ransom deadline.

04Technical analysis

Attackers used vishing/social engineering to compromise a call centre worker, gaining access to a Salesforce-based third-party platform. The platform stored customer service records but did not contain payment card data or passports.

Attack vector
Vishing / Social Engineering on third-party vendor
Attack method
Credential compromise and data exfiltration
Initial access
Vishing (Voice Phishing)
Exfiltration
Bulk data extraction

Vulnerabilities exploited

  • Human vulnerability to vishing
  • Third-party platform access controls

05Threat actor

Scattered LAPSUS$ Hunters (linked to Scattered Spider tactics) – known for aggressive social engineering, vishing, and targeting large organisations via third-party vendors.

Aliases

  • Scattered Spider
  • SH

Attribution sources

  • Qantas statements
  • BleepingComputer
  • The Guardian
  • Cybersecurity researchers

06Victims and impact

Countries affected

  • Australia
  • Global

07Data exposed

Data types

  • PII
  • Names
  • Email addresses
  • Phone numbers
  • Dates of birth
  • Frequent Flyer numbers
  • Addresses
  • Meal preferences

08Financial damage

Reputational damage, increased scam activity targeting customers, regulatory scrutiny, and potential fines.

09Timeline

  1. 2025-06-30Unusual activity detected on third-party platform.
  2. 2025-07-02Qantas publicly discloses the incident.
  3. 2025-07-09Qantas confirms 5.7 million customers affected.
  4. 2025-10-11Data leaked on dark web after ransom deadline.

10Reaction and fallout

Public reaction

Significant customer frustration and concern over increased phishing/scam risks.

Political impact

Increased Australian government and regulatory focus on airline cybersecurity and third-party risk management.

11Legal

Ongoing investigations by OAIC and potential class actions.

Civil lawsuits

  • Anticipated class-action lawsuits and regulatory actions

12Aftermath

Policy changes

  • Stronger oversight of third-party vendors in critical industries.

Security improvements

  • Enhanced vendor security assessments
  • Improved monitoring of third-party platforms

13Significance and legacy

Significance

One of Australia's largest customer data breaches in 2025, highlighting systemic third-party risks.

Legacy

Accelerated industry-wide improvements in supply chain security and third-party risk management.

14Disclosure and media

Authentication
Hacker leak site and Qantas official confirmations

Publishing organisations

  • The Guardian
  • BleepingComputer
  • Reuters
  • ABC News

15Field notes

  1. 01The breach occurred through an offshore (Philippines) contact centre using a Salesforce platform.

16Resolution

Data leaked on dark web in October 2025; Qantas continues notifying customers and supporting scam prevention.

17Sources

Official documents

  • Qantas Cyber Incident Customer Page

References

  1. [1]Qantas official statements
  2. [2]The Guardian coverage
  3. [3]Reuters reports
  4. [4]BleepingComputer
Fact sheetEL-0370

Dates

Event
30 Jun 2025
Started
30 Jun 2025
Discovered
30 Jun 2025
Disclosed
2 Jul 2025
Ongoing
Yes

Target

Organisation
Qantas Airways Limited
Type
Airline
Sector
Aviation / Transportation
Country
Australia

Actor

Name
Scattered LAPSUS$ Hunters
Type
Criminal Gang
Motivation
Financial gain through ransomware-style extortion and eventual public data leak.
Attribution
High
Status
Active
Arrested
No
Convicted
No

Data

People
5,700,000
Records
5,700,000
Sensitivity
High
Published
Yes
Sold (dark web)
Yes

Money

Crypto
Likely Bitcoin

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.