Australia-based airline Qantas Airways has announced that data belonging to millions of its customers was stolen following a global cyberattack that took place in July.
In an official statement, Qantas reported that cyber attackers targeted a third-party customer service platform, gaining unauthorised access to approximately 5.7 million customer records. The airline stated that the incident was part of a broader attack that affected many organisations worldwide, not just Qantas.
While the company did not share detailed information about which customer data was leaked, it revealed that most of the stolen records included names, email addresses, and frequent flyer details. A smaller subset of data was said to contain personal information such as date of birth, address, phone number, gender, or meal preferences.
Qantas emphasised that no other system breaches had occurred and that it has been working closely with Australian security agencies since the incident. The airline also announced that it had obtained a court injunction to prevent the stolen data from being shared online.
Australian cybersecurity expert Troy Hunt noted that the incident was a reflection of the global cyberattack that took place in July. Hunt stated that such court orders are usually ineffective against cybercriminals, commenting, “This is purely a symbolic step. Similar injunctions have been issued before, but they are often ignored.”
The attack once again brought attention to the rise in data breaches occurring in Australia in recent years. Telecommunications giant Optus announced in 2022 that identity data of 9.8 million customers had been leaked, while health insurance company Medibank Private reported in the same year that medical data belonging to 9.7 million policyholders had been stolen.
According to the Office of the Australian Information Commissioner, a total of 1,113 data breach notifications were recorded across the country in 2024. This figure represents an increase of about 25% compared to the 893 incidents reported the previous year.
Following the Qantas incident, cybersecurity experts called on companies operating in the aviation, healthcare, and telecommunications sectors to strengthen their security measures against potential threats originating from third-party service providers.



