
Legal risk on Qantas radar as hack victims face scams
The cyber attack targeted a third-party platform used by one of the airline's call centres, exposing the personal details of up to six million customers.
Names, phone numbers, dates of birth and email addresses are among the data believed to be leaked.
Legal experts have suggested the incident could lead to a class action in a repeat of compensation claims lodged following major breaches at Optus and Medibank in 2022.
The hack of sensitive customer details at the health insurer could end up costing it $700 million or more, analysts have said.
The primary wrongdoing was clearly with the hackers, but Qantas could still face secondary liability if it was found to have breached its duties, Monash University associate law professor Michael Duffy said.
"Based on previous class actions that have been taken for data breaches, there is certainly a possibility of action being taken against Qantas," he told AAP.
"This issue of data and privacy breaches is not going to go away."
The exposure of customers' dates of birth was particularly sensitive, Assoc Prof Duffy said.
"While exposure of names and email addresses are a concern, any exposure of dates of birth is more serious because of the potential of wrongdoers to try and use them for nefarious purposes," he said.
Qantas has reassured customers their financial information, passport numbers, credit card details and frequent flyer PINs were not accessed.
It is not the first time an airline has faced a cyber attack, with America's Hawaiian Airlines and WestJet compromised in recent weeks.
Cybersecurity experts warn this might be a sign the aviation industry is being targeted.
"Airlines hold all kinds of sensitive information and cybercriminals are looking to take it," NordVPN chief technology officer Marijus Briedis said.
"The industry needs to implement proactive, multi-layered security approaches that assume breaches will happen and focus on minimising their impact."
There is speculation the hackers responsible for the airline attacks is Scattered Spider, a group of young cyber criminals living in the US and the UK.
Security experts are concerned about the risk of follow-on scams targeting affected customers.
Macquarie University's Dali Kaafar said the release of private details could lead to malicious actors building a more complete profile about individuals, making them more susceptible to other forms of cyber crime.
He warned Qantas customers to change their passwords and access codes to prevent potential hacks.
That was because many people used their date of birth as a PIN, but the information had now been compromised, Professor Kaafar said.
Qantas is investigating the cyber attack and its impacts, urging customers to be on high alert for future scam attempts.
Chief executive Vanessa Hudson confirmed the company was working closely with the National Cyber Security Coordinator, the Australian Cyber Security Centre and independent specialised cyber security experts.
A customer support line was established to provide customers with the latest information.
Qantas shares were slightly up on Thursday after initially shedding 3.6 per cent following news of the hack.
Airlines are being warned to tighten security after a hack affecting millions of Qantas customers leaves the aviation giant exposed to possible legal action.
The cyber attack targeted a third-party platform used by one of the airline's call centres, exposing the personal details of up to six million customers.
Names, phone numbers, dates of birth and email addresses are among the data believed to be leaked.
Legal experts have suggested the incident could lead to a class action in a repeat of compensation claims lodged following major breaches at Optus and Medibank in 2022.
The hack of sensitive customer details at the health insurer could end up costing it $700 million or more, analysts have said.
The primary wrongdoing was clearly with the hackers, but Qantas could still face secondary liability if it was found to have breached its duties, Monash University associate law professor Michael Duffy said.
"Based on previous class actions that have been taken for data breaches, there is certainly a possibility of action being taken against Qantas," he told AAP.
"This issue of data and privacy breaches is not going to go away."
The exposure of customers' dates of birth was particularly sensitive, Assoc Prof Duffy said.
"While exposure of names and email addresses are a concern, any exposure of dates of birth is more serious because of the potential of wrongdoers to try and use them for nefarious purposes," he said.
Qantas has reassured customers their financial information, passport numbers, credit card details and frequent flyer PINs were not accessed.
It is not the first time an airline has faced a cyber attack, with America's Hawaiian Airlines and WestJet compromised in recent weeks.
Cybersecurity experts warn this might be a sign the aviation industry is being targeted.
"Airlines hold all kinds of sensitive information and cybercriminals are looking to take it," NordVPN chief technology officer Marijus Briedis said.
"The industry needs to implement proactive, multi-layered security approaches that assume breaches will happen and focus on minimising their impact."
There is speculation the hackers responsible for the airline attacks is Scattered Spider, a group of young cyber criminals living in the US and the UK.
Security experts are concerned about the risk of follow-on scams targeting affected customers.
Macquarie University's Dali Kaafar said the release of private details could lead to malicious actors building a more complete profile about individuals, making them more susceptible to other forms of cyber crime.
He warned Qantas customers to change their passwords and access codes to prevent potential hacks.
That was because many people used their date of birth as a PIN, but the information had now been compromised, Professor Kaafar said.
Qantas is investigating the cyber attack and its impacts, urging customers to be on high alert for future scam attempts.
Chief executive Vanessa Hudson confirmed the company was working closely with the National Cyber Security Coordinator, the Australian Cyber Security Centre and independent specialised cyber security experts.
A customer support line was established to provide customers with the latest information.
Qantas shares were slightly up on Thursday after initially shedding 3.6 per cent following news of the hack.
Airlines are being warned to tighten security after a hack affecting millions of Qantas customers leaves the aviation giant exposed to possible legal action.
The cyber attack targeted a third-party platform used by one of the airline's call centres, exposing the personal details of up to six million customers.
Names, phone numbers, dates of birth and email addresses are among the data believed to be leaked.
Legal experts have suggested the incident could lead to a class action in a repeat of compensation claims lodged following major breaches at Optus and Medibank in 2022.
The hack of sensitive customer details at the health insurer could end up costing it $700 million or more, analysts have said.
The primary wrongdoing was clearly with the hackers, but Qantas could still face secondary liability if it was found to have breached its duties, Monash University associate law professor Michael Duffy said.
"Based on previous class actions that have been taken for data breaches, there is certainly a possibility of action being taken against Qantas," he told AAP.
"This issue of data and privacy breaches is not going to go away."
The exposure of customers' dates of birth was particularly sensitive, Assoc Prof Duffy said.
"While exposure of names and email addresses are a concern, any exposure of dates of birth is more serious because of the potential of wrongdoers to try and use them for nefarious purposes," he said.
Qantas has reassured customers their financial information, passport numbers, credit card details and frequent flyer PINs were not accessed.
It is not the first time an airline has faced a cyber attack, with America's Hawaiian Airlines and WestJet compromised in recent weeks.
Cybersecurity experts warn this might be a sign the aviation industry is being targeted.
"Airlines hold all kinds of sensitive information and cybercriminals are looking to take it," NordVPN chief technology officer Marijus Briedis said.
"The industry needs to implement proactive, multi-layered security approaches that assume breaches will happen and focus on minimising their impact."
There is speculation the hackers responsible for the airline attacks is Scattered Spider, a group of young cyber criminals living in the US and the UK.
Security experts are concerned about the risk of follow-on scams targeting affected customers.
Macquarie University's Dali Kaafar said the release of private details could lead to malicious actors building a more complete profile about individuals, making them more susceptible to other forms of cyber crime.
He warned Qantas customers to change their passwords and access codes to prevent potential hacks.
That was because many people used their date of birth as a PIN, but the information had now been compromised, Professor Kaafar said.
Qantas is investigating the cyber attack and its impacts, urging customers to be on high alert for future scam attempts.
Chief executive Vanessa Hudson confirmed the company was working closely with the National Cyber Security Coordinator, the Australian Cyber Security Centre and independent specialised cyber security experts.
A customer support line was established to provide customers with the latest information.
Qantas shares were slightly up on Thursday after initially shedding 3.6 per cent following news of the hack.
Airlines are being warned to tighten security after a hack affecting millions of Qantas customers leaves the aviation giant exposed to possible legal action.
The cyber attack targeted a third-party platform used by one of the airline's call centres, exposing the personal details of up to six million customers.
Names, phone numbers, dates of birth and email addresses are among the data believed to be leaked.
Legal experts have suggested the incident could lead to a class action in a repeat of compensation claims lodged following major breaches at Optus and Medibank in 2022.
The hack of sensitive customer details at the health insurer could end up costing it $700 million or more, analysts have said.
The primary wrongdoing was clearly with the hackers, but Qantas could still face secondary liability if it was found to have breached its duties, Monash University associate law professor Michael Duffy said.
"Based on previous class actions that have been taken for data breaches, there is certainly a possibility of action being taken against Qantas," he told AAP.
"This issue of data and privacy breaches is not going to go away."
The exposure of customers' dates of birth was particularly sensitive, Assoc Prof Duffy said.
"While exposure of names and email addresses are a concern, any exposure of dates of birth is more serious because of the potential of wrongdoers to try and use them for nefarious purposes," he said.
Qantas has reassured customers their financial information, passport numbers, credit card details and frequent flyer PINs were not accessed.
It is not the first time an airline has faced a cyber attack, with America's Hawaiian Airlines and WestJet compromised in recent weeks.
Cybersecurity experts warn this might be a sign the aviation industry is being targeted.
"Airlines hold all kinds of sensitive information and cybercriminals are looking to take it," NordVPN chief technology officer Marijus Briedis said.
"The industry needs to implement proactive, multi-layered security approaches that assume breaches will happen and focus on minimising their impact."
There is speculation the hackers responsible for the airline attacks is Scattered Spider, a group of young cyber criminals living in the US and the UK.
Security experts are concerned about the risk of follow-on scams targeting affected customers.
Macquarie University's Dali Kaafar said the release of private details could lead to malicious actors building a more complete profile about individuals, making them more susceptible to other forms of cyber crime.
He warned Qantas customers to change their passwords and access codes to prevent potential hacks.
That was because many people used their date of birth as a PIN, but the information had now been compromised, Professor Kaafar said.
Qantas is investigating the cyber attack and its impacts, urging customers to be on high alert for future scam attempts.
Chief executive Vanessa Hudson confirmed the company was working closely with the National Cyber Security Coordinator, the Australian Cyber Security Centre and independent specialised cyber security experts.
A customer support line was established to provide customers with the latest information.
Qantas shares were slightly up on Thursday after initially shedding 3.6 per cent following news of the hack.
Hashtags

Try Our AI Features
Explore what Daily8 AI can do for you:
Comments
No comments yet...
Related Articles

The Age
22 minutes ago
- The Age
Crisafulli's bid to bring Trump – and the Quad
'Based on where things are at the moment geopolitically, who those partners are, where it will be, the fact that we're about to become an Olympic city, the journey point where we are as a state, I think we can own it,' he said. 'The defence lens and the defence opportunities that come with that, and the investment opportunities, it would be a really big win for us and it's something I'm really pinning our hopes on. 'I'm going to keep fighting pretty hard for it.' Crisafulli said he would lead his first overseas delegation as premier within the next month to both India and Japan, during which Quad hosting rights would be 'top of the agenda'. Comment was sought from both Albanese and Foreign Minister Penny Wong. While the American Chamber of Commerce (AmCham) celebrated July 4 inside the Brisbane Sofitel ballroom, a small band of protesters outside demonstrated against Australia's military cooperation with Trump's United States, including through AUKUS, and the ongoing war in Gaza. Annette Brownlie, the chair of Independent and Peaceful Australia, said. 'We're very concerned about what sort of deals our premier might be doing with the American Chamber of Commerce,' she said. 'We don't know what sort of contracts, etc, they will sign. We are deeply enmeshed in the American military industry – the F35 fighter jets, parts of those fighter jets are made here in Brisbane. Loading 'It implicates us and makes us complicit for the genocide that's happening in Gaza and in Palestine.' Ferra Engineering, based at Tingalpa in Brisbane's east, manufactures components for the US's F-35 Joint Strike Fighters and Crisafulli appeared to single it out while on stage. 'That's one company employing 100 people doing one small element in the backblocks of Queensland,' he said. 'Now that's a massive opportunity, and what we can do is make sure that we allow the private sector to do their job and invest in those partnerships that get people to look here [for investment].'

Sydney Morning Herald
22 minutes ago
- Sydney Morning Herald
Rory Hutchings fit and focused on positives of ‘brain snap' ban
Jockey Rory Hutchings is keen to repay the faith of top trainer Chris Waller at Rosehill on Saturday after returning from a one-month suspension for improper conduct and trying to cheat the scales in what he described as a 'brain snap' moment. A three-time New Zealand champion apprentice, Hutchings had three rides for Waller without a win at his first meeting back, at Warwick Farm on Wednesday, and he has two – Barking Mad (race one) and Seafall (seven) – for him on Saturday. He also has the job on Elouyou for Victorian trainer Scott Cameron in the eighth. Hutchings was suspended for an incident on May 24 at Randwick when he attempted to weigh out pre-race for a ride on the Waller-trained Providence without his mandatory safety vest on. When caught by clerk of scales David Sylvester, Hutchings used the words, 'I'll look after you'. In the stewards inquiry, Hutchings pleaded guilty to a charge of trying to weigh out without the vest in an attempt to make the allotted weight, saying it was a 'brain snap'. He pleaded not guilty to an improper conduct charge in relation to his comments, saying how it was interpreted was not what he intended, but stewards found him guilty. Hutchings, 30, told stewards he struggled with his weight after being flooded in at his home in the lead-up. He was also under financial pressure after a three-month lay-off with a broken collarbone from a fall in New Zealand. Preparing for Saturday's chances, he said he regretted trying to come back too early. 'I live on the Central Coast and it was when we had all that rain, and there was only one road in and out, so we were in there for a couple of days,' said Hutchings, who has been based in Australia for 10 years. 'I might have come back a little bit soon, and I was trying to ride a little bit lighter at the same time, but the suspension I got, to take some positives out of it, I rode work every single day, got fit and got the weight down, and I rode my minimum, 56 [kilograms], first ride back on Wednesday.

Sydney Morning Herald
23 minutes ago
- Sydney Morning Herald
The world's unluckiest football club: Liverpool, a history of tragedy
In the mid-1980s, Liverpool, once a major port city, was struggling with mass unemployment following the decline of its maritime industry. There wasn't much to smile about for the people of Merseyside, so when their team made the European Cup final in 1985, large parts of the city got behind them. Liverpool were to play Juventus at the Heysel stadium in Brussels, Belgium, but an hour before kick-off, focus shifted from the pitch to a tragedy unfolding in the stands. Following an altercation between Juventus and Liverpool fans, a section of the Heysel Stadium collapsed after Liverpool fans charged at Juventus supporters, killing 39 people and injuring 600 others. Bizarrely, the match went ahead despite the collapse, with Juventus defeating Liverpool 1-0. An 18-month investigation would eventually reveal that Liverpool fans were partly culpable for the incident, with 26 arrested, and 14 of them later convicted of involuntary manslaughter. However, it was also ruled that the stadium was in a state of disrepair and had failed inspections before the match. In 2025, in a ceremony to mark 40 years since Heysel, Liverpool city mayor, Steve Rotheram, who was in the stadium that day, described the situation as 'an indelible stain on our city.' The Hillsborough disaster, 1989 The most devastating event in Liverpool's history still looms large over the club. On April 15, 1989, during an FA Cup semi-final match between Liverpool and Nottingham Forest at Hillsborough Stadium in Sheffield, a fatal crowd crush occurred. Things began to unravel when more than 2000 Liverpool fans managed to flood into a standing-room section behind one of the goals, despite the stadium already being at near capacity. The victims were crushed against metal anti-riot fences or trampled underfoot. Many suffocated. Ninety-four people died that day, with 766 others injured. It was the deadliest day in British sporting history. Three subsequent deaths would follow, bringing the final death toll for Hillsborough to 97. Compounding the grief for a devastated city was a back-and-forth blame game between victims' families and the local authorities, with police blaming the behaviour of fans for the tragedy. In 2016, a coroner's inquest into Hillsborough ruled that the supporters were unlawfully killed owing to grossly negligent failures by police and ambulance services to fulfil their duty of care. The Liverpool Parade incident, 2025 After securing a 20th league title, Liverpool fans had plenty to celebrate at the end of this season. Once it became clear that Liverpool were firm favourites to win this year's Premier League, talk turned to a full-scale parade. Supporters deserved to line the streets and celebrate their team, especially considering their last title came in 2020, when the COVID-19 pandemic rendered real-life celebrations impossible. On May 26, 2025, an estimated million Liverpudlians were out in full force. But in a situation that feels all too familiar, celebrations were cut short when tragedy struck. At 6 pm, a car drove into a crowd on Water Street in Liverpool, resulting in 109 non-fatal injuries, including people being taken to the hospital. A 53-year-old man was arrested and charged with multiple offences, including dangerous driving and causing grievous bodily harm. While no deaths were reported, the incident served as a painful reminder to Liverpool fans who have endured a history tarred with tragedy and triumph in equal measure.