Qantas Airways (ASX:QAN) has confirmed that up to 6 million customers have potentially been compromised, following a significant data breach involving a third-party platform used by its Manila-based call centre.
The airline said that while names, birthdates, phone numbers, frequent flyer numbers and email addresses may have been accessed, more sensitive data — such as credit card information, passport details and financial records — remained secure.
“We can confirm all Qantas systems remain secure,” Qantas said in a statement to the Australian Securities Exchange (ASX). “There are 6 million customers that have service records in this platform. We are continuing to investigate the proportion of the data that has been stolen, though we expect it will be significant.”
Chief executive Vanessa Hudson offered her “sincere apologies” and said, “Our customers trust us with their personal information, and we take that responsibility seriously.” Qantas has established a dedicated customer support line and online resources to assist affected individuals.
The Australian Federal Police has been notified due to the criminal nature of the incident. Qantas said it began investigating after detecting “unusual activity” on the third-party system.
Concerns over third-party risk
Elliot Dellys, chief executive of Australian cyber security firm Phronesis Security, said the incident highlights sector-wide vulnerabilities.
“Qantas is not alone — many Australian organisations struggle to ensure vendors adequately protect information,” Dellys said. “If this incident is the result of a third-party compromise, it adds to an increasing list of major Australian organisations that have done their utmost to secure data, just to have it exposed via a third party.
“Security ultimately depends on training and education, and secure processes, to ensure systems and data remain secure when technology fails.”
Possible links to Scattered Spider
Though it is unclear who has breached Qantas’ walls, cyber experts suggest the group known as “Scattered Spider” could be behind the attack. The group, also referred to as UNC3944, has previously targeted global companies using sophisticated social engineering techniques.
“The US Federal Bureau of Investigations (FBI) recently provided warning that the cybercriminal group Scattered Spider had been targeting the airline sector, impersonating legitimate users to gain access to systems and bypass multi-factor authentication (MFA), one of the most effective methods of preventing breaches,” Dellys said.
Cyber experts have warned the breach could result in heightened risks of phishing and identity fraud.
Political and academic reactions
Opposition cyber security spokeswoman Melissa Price said the breach was “concerning” and urged Qantas to maintain transparency while receiving support from agencies such as the Australian Cyber Security Centre.
Macquarie University Cyber Security Hub executive director Dali Kaafar said, “This type of data literally can enable a wide variety of possible major threats from a phishing attack to identity theft, and of course things like social engineering.”
Kaafar stressed the need for rigorous vendor risk assessments and contractual safeguards to strengthen supply chain cyber hygiene.
Timing and share price impact
The breach coincided with Qantas' planned celebration of its first A321XLR aircraft arrival in Sydney, which was cancelled due to poor weather.
The aircraft had safely completed a two-leg journey from Hamburg via Bangkok and marks the airline’s entry into extra-long-range narrow-body operations.
Qantas shares had fallen 3.3% to A$10.41 around midday on Wednesday afternoon.