Qantas Airways (ASX:QAN) has confirmed it’s been contacted by a “potential cybercriminal”, just a week after a major data breach exposed the personal details of up to 6 million customers.
In a statement issued late Monday, the airline said it would not comment on whether a ransom was being demanded or if a specific monetary sum was mentioned. “As this is a criminal matter, we have engaged the Australian Federal Police and won’t be commenting any further on the detail of the contact,” a Qantas spokesman said.
The airline is now working with cybersecurity experts to assess the legitimacy of the communication. “There is no evidence that any personal data stolen from Qantas has been released but, with the support of specialist cybersecurity experts, we continue to actively monitor,” the company added.
The incident stems from a breach on a “third-party platform” used by Qantas' Manila-based contact centre — a system believed to have been infiltrated by the cybercriminal group known as Scattered Spider. Qantas first disclosed the breach on July 2.
Qantas said stolen data includes customer names, email addresses, phone numbers, dates of birth and frequent flyer numbers. The airline assured customers no credit card, passport or personal financial details were compromised, and frequent flyer accounts remain secure.
Customers have been urged to stay vigilant against suspicious messages claiming to be from Qantas.
Qantas joins the ranks of high-profile Australian companies targeted in recent years, including Optus and Medibank Private. Unlike those incidents, experts say the absence of a ransom demand or dark web activity in this case is unusual.
Qantas CEO Vanessa Hudson said on Friday, “We’re going to review everything as a part of understanding what happened, why it happened, and we will take action and learnings from that.” She added that the investigation “is progressing well, with our cybersecurity teams working alongside leading external specialists.”