Company · Passenger air transportation · Commercial airline · Australia / Global
Australian flag carrier airline.
The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.
On 30 June 2025, Qantas detected unauthorized access to a third-party Salesforce platform used by its Manila call center, achieved through voice-phishing of a call-center operator. Data on about 5.7 million customers was later dumped on 12 October 2025. Exposed data included names, email addresses, dates of birth, frequent-flyer numbers, and for some customers phone numbers and addresses. Credit-card and passport details were not exposed.
Full threat analysis, exploitation vectors, and principal guidance below.
12 additional sections · verified field analysis · defensive doctrine
6.0M records analyzed
Qantas is the flag carrier airline of Australia, operating domestic and international flights and the Frequent Flyer loyalty program.
Airlines and travel brands collect customer identity, contact, support, and loyalty-program data across booking and service systems. In this case, leaked data reportedly included emails, phone numbers, home addresses, frequent-flyer numbers, tier status, and in some cases meal preferences from a third-party customer service platform.
Qantas detected the intrusion on a third-party customer-service platform in late June 2025; the stolen data was posted publicly in October 2025 after failed extortion.
The name/DOB/email/loyalty combination is well suited to convincing spear-phishing and loyalty-account takeover; addresses and phone numbers for a subset add targeting depth.
• SIM swap attacks where phone numbers are present | • Targeted phishing campaigns using exposed email addresses | • Doxxing risk from physical address exposure
A travel or hospitality breach: itinerary, loyalty and contact data supports pattern-of-life inference and travel-themed phishing. For a high-profile principal this is targeting-grade, not merely identity-theft-grade: the combination lets an adversary locate, impersonate, or pressure the principal with little additional work.
Motivation: Financial, notoriety, extortion
A 2025 claimed fusion of Scattered Spider, LAPSUS$, and ShinyHunters branding. It used Telegram and forum channels for threats, leak theatrics, and extortion pressure.
Enter your email to check whether your data appears in this breach. We’ll send a 6-digit code to confirm it’s your address.
Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.
Request Consultation