Qantas Airways has confirmed a significant data breach affecting approximately 6 million customers, with hackers gaining unauthorized access to a third-party contact center system. The incident, detected on July 2, 2025, exposed customer information including names, email addresses, phone numbers, birth dates, and frequent flyer numbers. The breach follows a concerning pattern of cyber attacks targeting Australian organizations, including a major incident affecting pension funds earlier this year.
The airline has confirmed that no credit card details, personal financial information, passport numbers, or login credentials were compromised in the breach. Frequent flyer accounts themselves remain unaffected, which is especially important given Australia’s recent initiatives to strengthen digital identity security across its travel sector, including the launch of enhanced mobile ID verification systems for travel documentation.
Upon detecting unusual activity on the third-party platform, Qantas implemented immediate containment measures by isolating the affected system. The airline has notified relevant authorities, including the Australian Cyber Security Centre, which has recently been active in addressing large-scale cyber threats, the Office of the Australian Information Commissioner, and the Australian Federal Police.
Qantas CEO Vanessa Hudson addressed the incident, confirming that the Australian National Cyber Security Coordinator had been notified, while emphasizing that flight operations and passenger safety remain unaffected. The response is part of Australia’s broader cybersecurity strategy, supported by the government’s recent AUD $288 million investment in digital identity infrastructure.
“On Monday, we detected unusual activity on a third-party platform used by a Qantas airline contact centre,” the airline stated. “We then took immediate steps and contained the system. We can confirm all Qantas systems remain secure. There are 6 million customers that have service records in this platform. We are continuing to investigate the proportion of the data that has been stolen, though we expect it will be significant.”
The airline’s core IT systems continue to operate securely, with no impact on flight operations. Following the announcement, Qantas Airways’ stock price decreased by 3 percent on the Sydney exchange. The incident highlights ongoing challenges in securing third-party systems, even as Australia continues to advance its national digital identity framework and cybersecurity measures.
Sources: AppleInsider, BBC News, BleepingComputer