🔒breach.co.nz · the NZ & Australia breach register 🛡️ A Govern service
Register › 🇦🇺 AU › Other
Other sector · leaderboard
Own the Other leaderboard
The top banner across the Other overview and every Other record — one advertiser, exclusively.
Own this leaderboard → breach@govern.co.nz

Qantas Airways Limited

🇦🇺 Australia (national carrier) · Qantas Airways Limited · Record AU-2025-0009
● Confirmed
People affected
5,700,000
Breach date
2025-06-30
Regulator
OAIC
Trust tier
A · Confirmed

Data exposed

Customer names, email addresses, Frequent Flyer account details — ~5,700,000 Company-confirmed
Business and residential addresses — ~1,300,000 Company-confirmed
Phone numbers — ~900,000 Company-confirmed
Dates of birth — ~1,100,000 Company-confirmed
Gender and meal preferences Company-confirmed
Credit card details, passwords, PINs Company-confirmed

Confidence: Confirmed = regulator/court · Company-confirmed = the organisation's own disclosure · Media-reported = press. Figures without an official source are labelled, not estimated.

What happened

Qantas Airways detected unusual activity on a third-party customer service platform on June 30, 2025, and confirmed a cyber attack two days later affecting approximately 5.7 million customer records. [qantas-official] The breach involved social engineering (“vishing”) targeting a Manila-based call centre operator to gain access to the platform. [qantas-official] Qantas notified affected customers and obtained a permanent injunction from the NSW Supreme Court (October 4, 2025) to prevent publication or distribution of the stolen data. [qantas-injunction] Despite the legal action, the threat actor collective (Scattered Lapsus$ Hunters) released approximately 153GB of stolen data on the dark web between October 11–13, 2025, after Qantas refused to pay ransom. [threat-actor]

Data exposed

Qantas confirmed that the following customer data was compromised: [qantas-official]

  • Names and email addresses: 5.7 million customers
  • Frequent Flyer account details: 5.7 million customers
  • Business/residential addresses: ~1.3 million customers
  • Phone numbers: ~900,000 customers
  • Dates of birth: ~1.1 million customers
  • Gender and meal preferences: affected subset

Qantas explicitly confirmed that credit card details, personal financial information, passwords, PINs, and passport details were NOT stored in the affected system and therefore were not accessed. [qantas-official]

Timeline

  • 2025-06-30 — Qantas detects unusual activity on third-party customer service platform.
  • 2025-07-02 — Qantas confirms cyber attack and begins notifying Australian Federal Police, ACSC, and OAIC.
  • 2025-07-09 — Qantas notifies affected customers with specifics of their exposed data; launches 24/7 support line.
  • 2025-07-? — Ransomware actor makes contact demanding payment; Qantas refuses.
  • 2025-10-04 — NSW Supreme Court grants permanent injunction prohibiting access, viewing, release, transmission, or publication of stolen data by anyone. Justice Francois Kunc approves order; six-month non-publication order also issued over names of legal advisors. [qantas-injunction]
  • 2025-10-11–13 — Threat actor (Scattered Lapsus$ Hunters) releases ~153GB of stolen Qantas data on dark web and open internet after ransom deadline passes. [threat-actor]
  • 2025-10 — Health Minister Tony Burke warns public against seeking data online and confirms law enforcement engagement.

Regulatory outcome

Qantas has reported the incident to the Australian Federal Police, the Australian Cyber Security Centre (ACSC), and the Office of the Australian Information Commissioner (OAIC). As of September 10, 2026, no civil penalty proceedings have been filed by the OAIC. The NSW Supreme Court permanent injunction remains in force; its effectiveness is undermined by the public data release on the dark web.

Why it matters

The Qantas breach is the largest reported cyber incident against an Australian airline and one of the most significant breaches of Australian consumer data in recent years. It demonstrates the limitations of court injunctions in preventing data publication in the digital era, the sophistication of modern ransomware operations targeting large organisations, and the privacy risks facing customers of digital platforms operated by third-party service providers. The case may inform future OAIC enforcement decisions regarding reasonable steps obligations for companies outsourcing customer service functions.


Status note: No OAIC civil penalty proceedings announced as of September 10, 2026, though the incident meets established enforcement criteria. This record will be updated if the OAIC launches formal action.

GGOVERN Tabletop Exercises · Govern house Strengthen your cyber resilience — rehearse the decisions that matter. Book a Discovery Call →