Australia's Qantas says 6mln customer accounts accessed in cyber hack
The hacker targeted a call centre and gained access to a third-party customer service platform containing six million names, email addresses, phone numbers, birth dates and frequent flyer numbers, Qantas said in a statement on Wednesday.
The airline did not specify the location of the call centre or customers whose information was compromised. It said it learnt of the breach after detecting unusual activity on the platform and acted immediately to contain it.
"We are continuing to investigate the proportion of the data that has been stolen, though we expect it will be significant," Qantas said, reporting no impact on operations or safety.
Last week, the U.S. Federal Bureau of Investigation said cybercrime group Scattered Spider was targeting airlines and that Hawaiian Airlines and Canada's WestJet had already reported breaches. Qantas did not name any group.
"What makes this trend particularly alarming is its scale and coordination, with fresh reports that Qantas is the latest victim" of a hack, said Mark Thomas, Australia director of security services for cyber security firm Arctic Wolf.
Scattered Spider hackers are known to impersonate a company's tech staff to gain employee passwords and "it is plausible they are executing a similar playbook", Thomas said.
Charles Carmakal, chief technology officer of Alphabet-owned cybersecurity firm Mandiant, said it was too soon to say if Scattered Spider was responsible but "global airline organisations should be on high alert of social engineering attacks".
Qantas' share price was down 2.4% in afternoon trading against an overall market that was up 0.8%.
UNWELCOME ATTENTION
The breach is Australia's most high-profile since those of telecommunications network operator Optus and health insurance leader Medibank in 2022 prompted cyber resilience laws including mandatory reporting of compliance and incidents.
It brings unwelcome attention to Qantas which is trying to win public trust after actions during and after the COVID-19 pandemic saw it plunge on airline and brand league tables.
Qantas was found to have illegally sacked thousands of ground workers during the 2020 border closure while collecting government stimulus payments. It also admitted selling thousands of tickets for already-cancelled flights.
The airline drew the ire of opposition politicians who said it lobbied the federal government in 2022 to refuse a request from Qatar Airways to sell more flights. Qantas denied pressuring the government which eventually refused the request - a move the consumer regulator said hurt price competition.
Qantas CEO Vanessa Hudson has improved the airline's public standing since taking office in 2023, reputation measures showed.
"We recognise the uncertainty this will cause," Hudson said of the data breach. "Our customers trust us with their personal information and we take that responsibility seriously."
Qantas said it notified the Australian Cyber Security Centre, the Office of the Australian Information Commissioner and the Australian Federal Police.
ACSC declined to comment and AFP said only that it was aware of the incident. The OAIC was not immediately available for comment.
The airline said the hacker did not access frequent flyer accounts or customer passwords, PIN numbers or log in details.
(Reporting by Shivangi Lahiri in Bengaluru and Byron Kaye in Sydney; Editing by Rashmi Aich and Christopher Cushing)
Hashtags

Try Our AI Features
Explore what Daily8 AI can do for you:
Comments
No comments yet...
Related Articles


Khaleej Times
10 hours ago
- Khaleej Times
UAE authorities warn residents against online fraud, phishing attempts via phone
UAE residents are urged to exercise caution when dealing with phone messages or calls from unknown sources, as per a new note issued by the country's Cybersecurity Council and Abu Dhabi Police on Friday. Authorities called on the public to be mindful when receiving these calls or messages that can be gateways to phishing attempts or online fraud, which has become one of the growing challenges facing the community. "This is particularly evident with the diversity of its forms, the sophistication of its methods, the evolution of digital tools... Online fraud is no longer limited to traditional methods, but now exploits digital services, smart applications, and online networks to lure victims in ways that are often difficult to detect until after the crime has been committed," the UAE Cybersecurity Council said in a statement. Last month, a Khaleej Times investigation uncovered an online trading syndicate in the UAE operating a high-stakes scam through fraudulent call centres, fake trading platforms, and shell companies set up to siphon investor funds. For its part, Abu Dhabi Police warned the public against online fraud attempts, highlighting some methods of deception, including fake advertisements appearing in search engines, fraudulent job offers, and real estate scams. They stressed the importance of using approved applications when making purchases or requesting services. Recommendations Authorities shared tips, saying the public was urged to: Verify the authenticity of electronic links Avoid sharing banking or personal information with untrusted parties Rely only on official applications approved by government entities or available on trusted app stores such as the App Store and Google Play Do not share confidential information with anyone, whether related to bank accounts, cards, online banking passwords, ATM PINs, or the security code (CCV), or other sensitive details. Avoid clicking direct links sent via personal messages Refuse to install programmes under false pretences Never share two-factor authentication codes Review app permissions before installation Deny unnecessary access, such as to messages or administrative settings Continuously update operating systems to fix security gaps, and using certified antivirus software. Apart from these precautionary measures, UAE residents are advised to immediately report any fraud attempts through the Aman Service or via the contact centre at 8002626, SMS at 2828, the Abu Dhabi Police smart app, the email aman@ or the 'Police at Your Phone' service.


Zawya
15 hours ago
- Zawya
Jordan: NCSC says over 6,700 incidents handled in 2024
AMMAN – The National Cybersecurity Centre (NCSC) has reported a 'sharp' spike in cyber attacks over the past year, handling 6,758 incidents in 2024, marking a 175 per cent increase compared with 2023. According to the centre's annual report released on Thursday, the surge is largely due to expanded monitoring efforts across government networks and systems, the Jordan News Agency, Petra, reported. These efforts enabled cybersecurity teams to detect 97 per cent of the incidents before they could cause significant harm. The report revealed that the NCSC issued 6,922 cybersecurity alerts this year, more than doubling the 2,609 alerts issued in 2023. The national cyber incident response team, known as JOCERT, managed 3 per cent of the total incidents and released 75 technical reports analysing their nature and impact. Also, JOCERT handled 3 per cent of the incidents and issued 75 technical reports on them, the report said. The report indicated that 2 per cent of the recorded incidents were classified as serious, while 88 per cent were of medium severity and 10 per cent of low severity. The report said that no incidents reached the 'critical' level in 2024, in contrast to the 1 per cent classified as critical in 2023. The centre said that some attacks were linked to espionage and data theft operations, while others involved malware and various types of computer viruses. The NCSC conducted extensive security assessments, identifying 7,846 vulnerabilities across key government websites, servers, and digital infrastructure projects, according to the report. © Copyright The Jordan Times. All rights reserved. Provided by SyndiGate Media Inc. (


Zawya
16 hours ago
- Zawya
Blackstone emerges as frontrunner to buy Enverus, sources say
NEW YORK - Blackstone Inc has emerged as the frontrunner to buy energy-focused data provider Enverus for around $6 billion, according to sources familiar with the matter. Reuters reported in May that Hellman & Friedman was looking to sell Texas-based Enverus. Blackstone recently returned to the process after dropping out earlier this month, three of the sources said. Veritas Capital, which owns energy research firm Wood Mackenzie, was among others to have shown interest in Enverus, although this may now be in vain with Blackstone set to prevail in the auction, said the sources who are not authorized to discuss the private talks publicly. Blackstone declined to comment. Hellman & Friedman and Veritas could not be immediately reached for comment. The talks have been going on for several months, but the sources cautioned it is not certain a deal will be reached and noted other suitors could still emerge. Austin, Texas-based Enverus provides data, analytics, and software solutions to oil and gas companies. In 2021, Hellman & Friedman acquired majority interest in Enverus from Genstar Capital for $4.25 billion, including debt. Deal activity involving software businesses has maintained a brisk pace this year, even amid a slowdown in transactions in other parts of the economy. (Reporting by Milana Vinn and Amy-Jo Crowley; Editing by Chris Reese)