Australian airline Qantas faced a data breach that potentially exposed the personal information of six million customers after it detected “unusual activity” on a system used by its contact centre.
Once detected, Qantas said it took “immediate steps” to contain the affected system. It has assured customers that the “system is now contained.”
A third-party platform used by the airline company’s call centre was affected, but Qantas says that all of its systems remain secure.
“The incident occurred when a cyber criminal targeted a call centre and gained access to a third-party customer servicing platform,” Qantas said in a statement.
A proportion of data has been stolen, Qantas confirms, including names, email addresses, and phone numbers of customers.
Qantas is continuing its investigation into the extent of the data breach, but expects it to be “significant.”
Payment, password, and passport details, as well as frequent flyer numbers, were not contained on the compromised system.
The company’s other platforms have not faced interruptions and those flying with Qantas can still access flight details via the company’s app or websites.
Qantas is contacting effected customers, and is working with government agencies and cybersecurity experts to support their investigation.
Customers concerned about their data can call a dedicated helpline, Qantas Group CEO Vanessa Hudson informed customers.
“We sincerely apologise to our customers and we recognise the uncertainty this will cause,” she said.
The data breach comes just days after the US Federal Bureau of Investigation (FBI) issued a warning about alleged action from infamous ransomware group Scattered Spider targeting the aviation industry, though recent attacks have been contained to North American firms.
Hawaiian Airlines, based in the US, and WestJet, based in Canada, faced cyber-attacks in the past two weeks, with similar patterns.
Google Cloud Mandiant also issued a warning about Scattered Spider targeting the aviation industry, with both the FBI and the security firm pointing to contact centres and third parties as particular vulnerabilities.
Recommended reading
- How Scattered Spider’s Web Brought UK Retail to its Knees
- FBI and Google Mandiant Point to Scattered Spider Over Airline Cyber-attacks
- Google Warns US Retailers Could Be Next Following UK Cyber-attacks
While these cyber incidents have yet to be officially affiliated with any cyber group or threat actor, patterns point to Scattered Spider.
The prolific ransomware group which targeted UK retail giants including M&S and Co-op earlier this year, is known to use social engineering techniques, often targeting third-parties and contact centres. The gang, mainly made of young, native-English speakers, is also known to target various companies in the same industry over a number of weeks.
“While investigations continue, some indicators suggest this incident may align with recent FBI warnings about the Scattered Spider group, known for targeting SaaS platforms and cloud environments through social engineering and extortion attacks,” Darren Argyle, former groups CISO for Qantas, said in a LinkedIn post.
“No organisation is immune from the evolving threat landscape, particularly when sophisticated groups like Scattered Spider target critical industries.”
These attacks may also be strategically timed to lessen trust in airline system security during the busy summer travel season.





