Qantas Confirms 5.7 Million Customers Potentially Impacted in Cyberattack
Qantas has started informing customers about a recent data breach at one of its call centres. The airline is actively addressing the cyber incident, working to identify compromised personal information and support affected customers.
Here’s a detailed update on the situation, the data involved, and the steps Qantas is taking to protect its customers.
Details of the Compromised Data
Following the cyber incident, Qantas has conducted a thorough forensic analysis of the affected system. The investigation shows no evidence that stolen data has been publicly released.
With the help of cybersecurity experts, the airline continues to monitor the situation closely to ensure customer data remains secure.
Importantly, no credit card details, personal financial information, or passport details were stored in this system and therefore have not been accessed. Magnetometer data was not stored in the compromised system, so these details remain safe.
Additionally, Qantas Frequent Flyer accounts are unaffected, as passwords, PINs, and login credentials were not accessed. The compromised data alone is insufficient to access these accounts.
After removing duplicate records, Qantas identified approximately 5.7 million unique customer records in the affected system. The specific data fields vary by customer, but the analysis revealed the following approximate figures:
4 million records included only name, email address, and Qantas Frequent Flyer details:
- 1.2 million contained just name and email address.
- 2.8 million included name, email address, and Qantas Frequent Flyer number, with most also containing tier status and a smaller subset including points balance and status credits.
1.7 million records included a combination of the above data plus one or more of the following:
- Address: 1.3 million (including residential and business addresses, such as hotels for lost baggage delivery).
- Date of birth: 1.1 million.
- Phone number (mobile, landline, or business): 900,000.
- Gender: 400,000 (separate from name or salutation).
- Meal preferences: 10,000.
Customer records are tied to unique email addresses, so individuals with multiple email addresses may have multiple records.

Notifying Affected Customers
Qantas is proactively contacting affected customers via email to inform them of the specific personal data compromised in the breach.
The airline is also providing guidance and support to help customers protect themselves. For assistance, Qantas has set up a dedicated 24/7 support line at 1800 971 541 (or +61 2 8028 0534 for international callers), offering access to specialized identity protection advice and resources.
Vanessa Hudson, Qantas Group Chief Executive Officer, emphasized the airline’s commitment to its customers. “Our top priority since the incident has been to understand exactly what data was compromised for each of the 5.7 million affected customers and to communicate this to them quickly.”
“Starting today, we’re notifying customers about the specific personal data involved and providing guidance on accessing support services.”
Hudson added that Qantas has implemented additional cybersecurity measures to enhance customer data protection and is continuing to investigate the incident.
The airline is working closely with the National Cyber Security Coordinator, the Australian Cyber Security Centre, and the Australian Federal Police, expressing gratitude for their ongoing support.

Advice for Customers
Qantas is urging customers to stay vigilant and take precautions to protect their personal information. Here are some recommended steps to reduce the risk of misuse:
Be cautious with communications: Verify the identity of anyone claiming to be from Qantas by contacting them through official channels. Be wary of emails, text messages, or phone calls that seem suspicious.
Enable two-step authentication: Use an authentication app or similar method for personal email accounts and other online services to add an extra layer of security.
Stay informed: Visit the Australian Cyber Security Centre and the National Anti-Scam Centre’s Scamwatch webpage for updates on current threats.
Access resources: Check IDCARE’s Learning Centre and the Office of the Australian Information Commissioner’s website for tips on safeguarding personal information.
Protect sensitive information: Never share online account passwords, booking references, or sensitive login details. Qantas will not request this information from customers.
Those suspecting they have been targeted by scammers should report the incident to Scamwatch immediately.
Moving Forward
Qantas commits to transparency and customer support as it navigates this cybersecurity challenge. By promptly notifying affected customers, enhancing security measures, and collaborating with authorities, the airline is working to maintain trust and protect personal data.
the airline encouraged customers to stay alert, use the provided resources, and contact the dedicated support line for assistance.
This proactive approach reflects Qantas’ dedication to addressing the breach responsibly and ensuring customers have the tools and information needed to stay secure.
If you’re an affected customer, check your email for updates from Qantas and follow the recommended steps to safeguard your information.

