← Qantas Airways

2025 Qantas — third-party contact-centre CRM breach; 5.7M customer records (Jul updates)

2025 5.7M records affected Share on X

Data compromised

Qantas said 5.7M customer records were affected: ~4M limited to name/email/Frequent Flyer details (with subsets including tier, points balance, status credits) and ~1.7M with additional fields such as address, date of birth, phone number, gender, and meal preferences. Qantas stated no passwords, PINs, financial/payment data, or passport details were stored in the impacted system

Technical writeup

Verified company disclosure — June to October 2025. Qantas said it detected unusual activity on June 30, 2025 on a third-party platform used by an airline contact centre and contained the incident, while confirming core Qantas systems remained secure. In July updates, Qantas stated data for approximately 5.7 million customers was stolen from the external platform and began notifying impacted customers by data-field type; BleepingComputer reported extortion contact from threat actors and linked the event to broader Salesforce-targeting social-engineering campaigns claimed under the ShinyHunters brand. Qantas obtained NSW Supreme Court injunctions to block access/publication of stolen data, coordinated with the Australian Cyber Security Centre and Australian Federal Police, and later stated cybercriminals had released data while investigations continued. Qantas said Frequent Flyer passwords/PINs/login details, payment/financial data, and passport details were not in the impacted system.

Root cause

Unauthorized access to a third-party cloud customer-service/CRM platform used by a Qantas airline contact centre; campaign linked in trade reporting to social-engineering and support-impersonation activity seen across Salesforce customer environments

References