What happened
Qantas Airways detected unusual activity on a third-party customer service platform on June 30, 2025, and confirmed a cyber attack two days later affecting approximately 5.7 million customer records. [qantas-official] The breach involved social engineering (“vishing”) targeting a Manila-based call centre operator to gain access to the platform. [qantas-official] Qantas notified affected customers and obtained a permanent injunction from the NSW Supreme Court (October 4, 2025) to prevent publication or distribution of the stolen data. [qantas-injunction] Despite the legal action, the threat actor collective (Scattered Lapsus$ Hunters) released approximately 153GB of stolen data on the dark web between October 11–13, 2025, after Qantas refused to pay ransom. [threat-actor]
Data exposed
Qantas confirmed that the following customer data was compromised: [qantas-official]
- Names and email addresses: 5.7 million customers
- Frequent Flyer account details: 5.7 million customers
- Business/residential addresses: ~1.3 million customers
- Phone numbers: ~900,000 customers
- Dates of birth: ~1.1 million customers
- Gender and meal preferences: affected subset
Qantas explicitly confirmed that credit card details, personal financial information, passwords, PINs, and passport details were NOT stored in the affected system and therefore were not accessed. [qantas-official]
Timeline
- 2025-06-30 — Qantas detects unusual activity on third-party customer service platform.
- 2025-07-02 — Qantas confirms cyber attack and begins notifying Australian Federal Police, ACSC, and OAIC.
- 2025-07-09 — Qantas notifies affected customers with specifics of their exposed data; launches 24/7 support line.
- 2025-07-? — Ransomware actor makes contact demanding payment; Qantas refuses.
- 2025-10-04 — NSW Supreme Court grants permanent injunction prohibiting access, viewing, release, transmission, or publication of stolen data by anyone. Justice Francois Kunc approves order; six-month non-publication order also issued over names of legal advisors. [qantas-injunction]
- 2025-10-11–13 — Threat actor (Scattered Lapsus$ Hunters) releases ~153GB of stolen Qantas data on dark web and open internet after ransom deadline passes. [threat-actor]
- 2025-10 — Health Minister Tony Burke warns public against seeking data online and confirms law enforcement engagement.
Regulatory outcome
Qantas has reported the incident to the Australian Federal Police, the Australian Cyber Security Centre (ACSC), and the Office of the Australian Information Commissioner (OAIC). As of September 10, 2026, no civil penalty proceedings have been filed by the OAIC. The NSW Supreme Court permanent injunction remains in force; its effectiveness is undermined by the public data release on the dark web.
Why it matters
The Qantas breach is the largest reported cyber incident against an Australian airline and one of the most significant breaches of Australian consumer data in recent years. It demonstrates the limitations of court injunctions in preventing data publication in the digital era, the sophistication of modern ransomware operations targeting large organisations, and the privacy risks facing customers of digital platforms operated by third-party service providers. The case may inform future OAIC enforcement decisions regarding reasonable steps obligations for companies outsourcing customer service functions.
Status note: No OAIC civil penalty proceedings announced as of September 10, 2026, though the incident meets established enforcement criteria. This record will be updated if the OAIC launches formal action.