[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f2gxvmk7i5qujx":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"publishedAt":13,"modifiedDate":12,"contentUpdatedAt":14,"source":15,"sourceUrl":16,"sourceUrls":17,"pwnCount":20,"affectedCount":20,"affectedCountStatus":21,"affectedCountLowerBound":13,"affectedCountUnit":22,"hasEnglishDescription":4,"contentLocale":23,"availableLocales":24,"translations":26,"severity":29,"dataClasses":30,"description":43,"seoTitle":44,"seoDescription":45,"logoUrl":46,"isVerified":4,"isSensitive":4,"isSpamList":47,"isMalware":47,"company":48},"6a4f795f94fd9e52b4ce5f47","Qantas 2025","Qantas 2025 Data Breach","qantas-2025","qantas.com","2025-06-30T00:00:00.000Z","2026-07-09T10:35:10.189Z",null,"2026-07-19T00:10:56.477Z","Official company cyber incident updates","https:\u002F\u002Fwww.qantasnewsroom.com.au\u002Fmedia-releases\u002Fupdate-on-qantas-cyber-incident-wednesday-9-july-2025",[16,18,19],"https:\u002F\u002Fwww.qantasnewsroom.com.au\u002Fmedia-releases\u002Fqantas-cyber-incident","https:\u002F\u002Fwww.qantasnewsroom.com.au\u002Fqantas-responds\u002Fupdate-on-july-cyber-incident",5700000,"known","unknown","en",[23,25],"tr",{"en":27,"tr":28},{"slug":9},{"slug":9},"Critical",[31,32,33,34,35,36,37,38,39,40,41,42],"Names","Email addresses","Frequent flyer numbers","Loyalty program details","Loyalty tier information","Loyalty points balance","Status credits","Physical addresses","Dates of birth","Phone numbers","Gender","Meal preferences","\u003Cp>The Qantas 2025 data breach is a large-scale security incident in which customer data held on a third-party customer service platform connected to the airline's call center was accessed without authorization. According to company statements, unusual activity was detected on June 30, 2025, the system was brought under control, and it was stated that Qantas systems remained secure. After duplicate records were removed, the number of affected unique customers was confirmed to be approximately 5.7 million.\u003C\u002Fp>\n\u003Cp>In this incident, credit card information, personal financial information, passport information, frequent flyer account passwords, PIN information, and login information were disclosed outside the scope. Nevertheless, the combination of fields such as name, email, frequent flyer information, address, date of birth, phone number, gender, and meal preference poses a serious risk, especially for targeted fraud and loyalty program-themed social engineering. A later company update also indicated that the stolen customer data had been published by the criminals.\u003C\u002Fp>\n\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\n\u003Cp>Verified data types include name, email address, Qantas Frequent Flyer number, loyalty program level, points balance, status credits, home or work address, date of birth, phone number, gender, and meal preference fields. The official update stated that 4 million records are limited to name, email, and frequent flyer details; the remaining 1.7 million records include, in addition to these fields, areas such as address, date of birth, phone number, gender, or meal preference.\u003C\u002Fp>\n\u003Cp>Although this data set does not contain bank or passport information, it is valuable for phishing and account takeover preparation. Attackers can combine frequent flyer numbers, flight brands, email, and phone information to create fake customer service messages, reward point updates, booking issues, baggage delivery, or account verification scenarios. For individuals with birth dates and addresses, the risk of guessing authentication questions and attempting fraud on other services is higher.\u003C\u002Fp>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\n\u003Cp>The verified scope of the breach is the third-party customer service platform associated with the Qantas call center. The company has stated that the incident did not affect operational flight safety, that Qantas's main systems remained secure, and that frequent flyer accounts were not directly compromised. Since passwords, PIN information, and login credentials were not accessed, this record has not been classified as a password leak.\u003C\u002Fp>\n\u003Cp>A total of 5.7 million people represent the unique customer coverage announced after duplicate records were removed. Data fields are not the same for each user. Approximately 1.2 million records contain name and email; approximately 2.8 million records contain name, email, and frequent flyer number; a large portion of this group includes loyalty level; a smaller portion includes points balance and status credits. For the remaining 1.7 million people, additional fields such as address, date of birth, phone, gender, and meal preference were included in varying combinations.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>The main group at risk are Qantas customers and frequent flyer program members. Individuals with a service record in the call center or customer service platform may have been affected by this incident, even if they did not make a direct flight reservation. The coverage of records for individuals with accounts or service records under multiple email addresses may appear different, as the company has evaluated customer records based on unique email addresses.\u003C\u002Fp>\n\u003Cp>The highest risk is concentrated among customers who have additional fields such as address, date of birth, and phone number. These individuals may encounter more convincing-looking frauds, such as fake call center calls, travel plan changes, points refunds, baggage delivery, identity verification, or loyalty account security alerts. Low-volume fields, such as food preferences, can also be used to generate personalized messages; therefore, even details that seem minor are important in the context of fraud.\u003C\u002Fp>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\n\u003Cp>Users who may be affected should first check which fields are included in notifications from Qantas. Links provided in unexpected emails, text messages, or phone calls should not be used; if it is necessary to contact the company, independent verification should be done through known official channels. In particular, if a request for a password, verification code, payment information, or documents is made under the pretext of points balance, account security, reservation correction, or baggage delivery, this request should not be considered secure.\u003C\u002Fp>\n\u003Cp>Users need to enable two-step verification on their personal email accounts and use unique passwords for frequent flyer accounts and travel-related accounts. Although Qantas stated that passwords were not accessed in this incident, scammers may use the leaked identity and contact information to try other accounts. People whose addresses or birthdates have been leaked should update security questions on other services and carefully review unexpected account recovery notifications.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>This incident demonstrates that call centers and third-party customer support platforms pose critical risks in terms of airline customer data. Passenger information, loyalty program details, and customer service records can provide a strong basis for targeted fraud even if they do not directly contain payment information. Organizations should implement data minimization, detailed access logs, strong authentication, behavioral anomaly monitoring, and regular vendor security audits on such platforms.\u003C\u002Fp>\n\u003Cp>Long-term protection on the user side should be considered more broadly than a one-time notification check. Travel accounts, email accounts, loyalty programs, and customer service communications should be monitored together. Individuals whose frequent flyer numbers and email addresses have been leaked should remain cautious against attempts such as points fraud, fake campaigns, reservation changes, and call center impersonation in the coming months. Since personal information does not change, the risk is not limited to the week the incident is announced.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\n\u003Cp>This record on LeakData has been prepared to clearly show the user the number of people affected, the date of the incident, the leaked fields, and the types of data excluded for the verified Qantas 2025 breach. The appearance of this record in an email query alone does not prove which fields of the individual were affected; however, it indicates that users who are Qantas customers or frequent flyer program members should check the company's notifications and account security settings.\u003C\u002Fp>\n\u003Cp>When users encounter this record, they should first check their Qantas account, registered contact information, frequent flyer details, and any travel notifications if available. If a suspicious message or call is received, verification should be done through the company's known support channel, and personal information or account verification codes should not be shared. While the record states that financial and passport data are out of scope, it classifies the risk of targeted social engineering as high priority due to the large customer base and loyalty program data.\u003C\u002Fp>","Qantas 2025 Data Breach (5.7 Million Reported Records)","Qantas 2025 Data Breach. 5.7 Million reported records are reported. Reported data: Names, Email addresses, Frequent flyer numbers. Review the scope, risks…","\u002Fuploads\u002Flogo\u002Fqantas-2025.svg",false,{"name":49,"sector":50,"country":51,"website":10,"websiteArchiveUrl":52,"websiteStatus":52,"websiteCheckedAt":13},"Qantas Airways Limited","Airline","Australia",""]