Qantas Cyber Attack: Insights on Data Breach and Customer Notification
Qantas Airways has initiated the process of reaching out to its Frequent Flyer customers regarding a recent cyber attack that compromised personal data. This incident, which came to light on June 30, has raised concerns among the airline’s clientele, prompting Qantas to assure transparency about the scope and nature of the breach.
Details of the Data Breach
The airline’s communication to customers, penned by CEO Vanessa Hudson and sent on July 9, outlined the events surrounding the cyber attack. The breach was first detected when unusual activity was noticed on a third-party platform associated with a Qantas contact center. Qantas acted swiftly to contain the situation, underscoring their commitment to customer security.
In the message to customers, Hudson expressed regret over the confusion this incident has caused. The airline’s cybersecurity teams have since been investigating to determine exactly what data was affected. Early findings indicate that specific personal information, including names, Qantas Frequent Flyer numbers, and tier statuses, may have been compromised.
Customer Notification Process
Qantas has made it clear that if customers have multiple email addresses linked to their Frequent Flyer accounts, they might receive separate notifications for each affected email. The company has emphasized that there is currently no evidence suggesting that any of the stolen data has been publicly disclosed. They continue to monitor the situation closely, with assistance from cybersecurity experts.
Scope of Impacted Data
The airline confirmed that approximately 5.7 million customers were affected by the breach. Among these, around 4 million had names and email addresses compromised, with some records also containing the Frequent Flyer number. A detailed breakdown reveals the following specifics:
- Total Customers Affected: 5.7 million
- Names and Email Addresses: 1.2 million customers had their names and email addresses compromised.
- Comprehensive Data Set: 2.8 million customer records included names, email addresses, and Frequent Flyer numbers, alongside tier information in some instances.
Additional Data Compromised
The remaining 1.7 million customers experienced varying degrees of data exposure, which included:
- Residential and Business Addresses: 1.3 million (including hotel addresses for baggage delivery)
- Dates of Birth: 1.1 million
- Phone Numbers: 900,000 (covering mobile, landline, and business)
- Gender Information: 400,000 (not including names or salutations)
- Meal Preferences: 10,000
While Qantas assured that no passwords or PINs were impacted and that Frequent Flyer accounts remain secure, they are working on features to allow customers to view the specifics of their compromised data by logging into their accounts.
Enhancing Cyber Security Measures
In response to this incident, Qantas has implemented additional cyber security protocols to better protect customer data from future threats. The airline is actively reviewing the events that led to the breach and has reaffirmed its collaboration with various authorities, including the National Cyber Security Coordinator and the Australian Cyber Security Centre. Hudson expressed appreciation for the continuous support received from these entities.
Insights from Security Analysts
Security experts speculate that the attack may be tied to a hacking group known as Scattered Spider, which has been implicated in other recent attacks against retailers in the UK. This points to a broader trend of sophisticated cyber threats targeting businesses globally.
Qantas’s commitment to transparency and customer security will be critical as they navigate the aftermath of this cyber incident. The ongoing investigation and improvements in data protection measures will hopefully restore customer confidence in the airline’s ability to safeguard personal information.


