{"id":205847,"date":"2025-10-11T16:53:12","date_gmt":"2025-10-11T16:53:12","guid":{"rendered":"https:\/\/www.newsbeep.com\/au\/205847\/"},"modified":"2025-10-11T16:53:12","modified_gmt":"2025-10-11T16:53:12","slug":"hackers-release-qantas-customers-data-on-dark-web","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/au\/205847\/","title":{"rendered":"Hackers release Qantas customers&#8217; data on dark web"},"content":{"rendered":"<p class=\"paragraph_paragraph__iYReA\">A cybersecurity expert has told the ABC that the personal data of Qantas customers has been released on the dark web.<\/p>\n<p class=\"paragraph_paragraph__iYReA\">Up to six million Qantas customer records were exposed in July during a cyber attack on a third-party platform used by Qantas.<\/p>\n<p class=\"paragraph_paragraph__iYReA\">The stolen data included some customers&#8217; names, email addresses, phone numbers, birth dates, and frequent flyer numbers.<\/p>\n<p><a href=\"https:\/\/www.abc.net.au\/news\/2025-10-08\/qantas-responds-to-cyber-hacker-threat-to-release-data\/105866656\" data-component=\"FullBleedLink\" class=\"RelatedCard_link__rsgR9 FullBleedLink_root__lTw_U interactive_focusContext__yRhc_ interactive_defaults__AKxUU FullBleedLink_showVisited__g3Xvz\" rel=\"nofollow noopener\" target=\"_blank\">Qantas responds to hackers threat<\/a><\/p>\n<p class=\"Typography_base__sj2RP RelatedCard_synopsis__cFwMW Typography_sizeMobile14__u7TGe Typography_lineHeightMobile20___U7Vr Typography_regular__WeIG6 Typography_colourInherit__dfnUx\" data-component=\"Typography\">Qantas says it is continuing to support customers as a hacking group threatens to release personal data from around 40 companies to the dark web.<\/p>\n<p class=\"paragraph_paragraph__iYReA\">A cybercrime collective, Scattered Lapsus$ Hunters, had reportedly threatened to release stolen data from around 40 global firms linked to the cloud software giant Salesforce \u2014 including Disney, Google, IKEA, Toyota, and airlines Qantas, Air France and KLM \u2014 unless a ransom was paid.<\/p>\n<p class=\"paragraph_paragraph__iYReA\">The hackers had given Salesforce a deadline of 3pm AEDT on Saturday to pay the ransom, or it would release the data.<\/p>\n<p class=\"paragraph_paragraph__iYReA\">Australian online security expert Troy Hunt from Have I Been Pwned said he had confirmation that the Qantas customer data had since been leaked on the dark web.<\/p>\n<p class=\"paragraph_paragraph__iYReA\">While Mr Hunt was speaking to the ABC, he received a text message from a friend overseas saying they thought they had found his personal data in the leak.<\/p>\n<p class=\"paragraph_paragraph__iYReA\">&#8220;I just gave them the last two digits of my frequent flyer number. So we&#8217;ll see if they can confirm the whole thing, but I&#8217;m quite sure it is what it is,&#8221; he said.<\/p>\n<p class=\"paragraph_paragraph__iYReA\">Within seconds, he had confirmation.<\/p>\n<p class=\"paragraph_paragraph__iYReA\">&#8220;They&#8217;ve just confirmed the email address that was on file, which is unique to Qantas,&#8221; Mr Hunt said.<\/p>\n<p class=\"paragraph_paragraph__iYReA\">It appeared the hackers did not release the data of all the companies involved.<\/p>\n<p class=\"paragraph_paragraph__iYReA\">&#8220;They&#8217;ve only released six at this point in time,&#8221; Mr Hunt said.<\/p>\n<p class=\"paragraph_paragraph__iYReA\">&#8220;The guys responsible for this have been pretty erratic in their communication; there were threats that everything was going to be leaked.&#8221;<\/p>\n<p><img decoding=\"async\" alt=\"A thumb gripping a red Qantas Frequent Flyer card\" class=\"Image_image__5tFYM ContentImage_image__DQ_cq\"  src=\"https:\/\/www.newsbeep.com\/au\/wp-content\/uploads\/2025\/10\/11b9a11aa34dfbd44ebf46a62ffe9df3\" loading=\"lazy\" data-component=\"Image\" data-lazy=\"true\"\/><\/p>\n<p class=\"Typography_base__sj2RP FigureCaption_text__zDxQ5 Typography_sizeMobile12__w_FPC Typography_lineHeightMobile20___U7Vr Typography_regular__WeIG6 Typography_colourInherit__dfnUx\" data-component=\"Typography\">The stolen data included some customers&#8217; names, email addresses, phone numbers, birth dates, and frequent flyer numbers. (ABC News: Stephanie Chalmers)<\/p>\n<p class=\"paragraph_paragraph__iYReA\">Qantas said in a statement on its website that there was no impact to frequent flyer accounts and that financial details had not been compromised.<\/p>\n<p class=\"paragraph_paragraph__iYReA\">&#8220;Passwords, PINs, and login details were not accessed or compromised,&#8221; the statement said.<\/p>\n<p class=\"paragraph_paragraph__iYReA\">&#8220;Qantas confirms that no identity documents, credit card numbers, or personal financial details were accessed or compromised as a result of the incident.&#8221;<\/p>\n<p class=\"paragraph_paragraph__iYReA\">Mr Hunt told the ABC that the data that was published earlier had been removed from the service it was placed on for download.<\/p>\n<p class=\"paragraph_paragraph__iYReA\">&#8220;But it&#8217;s already in thousands of hands and will likely just be re-uploaded to a new service,&#8221; he said.\u00a0<\/p>\n<p class=\"paragraph_paragraph__iYReA\">&#8220;The genie is out of the bottle.<\/p>\n<p class=\"paragraph_paragraph__iYReA\">&#8220;If anything, the situation is worse now \u2014 the hackers just launched a new clear website that anyone can easily access.\u00a0<\/p>\n<p class=\"paragraph_paragraph__iYReA\">&#8220;The data will likely reappear there soon.&#8221;<\/p>\n<p><a href=\"https:\/\/www.abc.net.au\/news\/2025-10-10\/article-qantas-data-breach-website-seizure\/105879120\" data-component=\"FullBleedLink\" class=\"RelatedCard_link__rsgR9 FullBleedLink_root__lTw_U interactive_focusContext__yRhc_ interactive_defaults__AKxUU FullBleedLink_showVisited__g3Xvz\" rel=\"nofollow noopener\" target=\"_blank\">FBI &#8216;seizes&#8217; site run by hackers threatening to release Qantas customers&#8217; data<\/a><\/p>\n<p class=\"Typography_base__sj2RP RelatedCard_synopsis__cFwMW Typography_sizeMobile14__u7TGe Typography_lineHeightMobile20___U7Vr Typography_regular__WeIG6 Typography_colourInherit__dfnUx\" data-component=\"Typography\">The seizure comes less than 24 hours before a deadline set by the hackers for around 40 global firms to pay a ransom to prevent the release of sensitive information.<\/p>\n<p class=\"paragraph_paragraph__iYReA\">Mr Hunt advised affected Australians to carefully verify any incoming communication.<\/p>\n<p class=\"paragraph_paragraph__iYReA\">&#8220;In the Qantas situation, when we think about the data that&#8217;s been exposed, that sort of data can be useful for things like social engineering attacks, phishing scams,&#8221; he said.<\/p>\n<p class=\"paragraph_paragraph__iYReA\">&#8220;Someone can contact me even outside the context of Qantas and say, &#8216;Look, I know you live at this address and I know this is your phone number and we are a legitimate organisation offering some service and you need to give us some personal information or log on to a site&#8217;.<\/p>\n<p class=\"paragraph_paragraph__iYReA\">&#8220;The more an attacker has about you in terms of your personal info, the better a scam they&#8217;re able to execute.&#8221;<\/p>\n<p class=\"paragraph_paragraph__iYReA\">In a statement, the hackers confirmed the data leak and have threatened that they have the resources to continue these types of attacks.<\/p>\n<p class=\"paragraph_paragraph__iYReA\">Salesforce confirmed on Saturday that it would &#8220;not engage, negotiate with, or pay any extortion demand&#8221;.<\/p>\n<p class=\"paragraph_paragraph__iYReA\">The company continues to maintain that there is no indication that its platform has been compromised.<\/p>\n","protected":false},"excerpt":{"rendered":"A cybersecurity expert has told the ABC that the personal data of Qantas customers has been released on&hellip;\n","protected":false},"author":2,"featured_media":169526,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[77455,41523,126273,94961,43,44,127655,3861,116709,41,39,42,40],"class_list":["post-205847","post","type-post","status-publish","format-standard","has-post-thumbnail","category-headlines","tag-customer-data","tag-dark-web","tag-data-leak","tag-frequent-flyer","tag-headlines","tag-news","tag-personal-details","tag-qantas","tag-ransomware","tag-top-news","tag-top-stories","tag-topnews","tag-topstories"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/posts\/205847","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/comments?post=205847"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/posts\/205847\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/media\/169526"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/media?parent=205847"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/categories?post=205847"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/tags?post=205847"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}