Qantas
Jul 2025 · Graded Attested · Transportation and Logistics · Beyond the filings
Incident summary
QantasJul 2025
Not yet quantified
AAttestedAn unnamed threat actor impersonating "Qantas IT help" contacted the airline's call centre. The agent was tricked into connecting a customised version of Salesforce's Data Loader tool to the customer relationship management platform used by Qantas, which enabled mass data extraction. 5.67 mm customer records were exposed. The cost of cyber losses and recovery has never been disclosed, with Qantas executives agreeing to forfeit $800k AUD in bonuses due to the incident.
Transportation and Logistics
Company statement
Initial attack type phishing or social engineering confirmed · Impact data theft confirmed
About this record
This incident is beyond the filings: attributed to a company statement, a regulator or court record, or a news report, and graded Attested or Inferred. Every figure links to the source it was read from; if we have read one wrong, tell us at info@hackerinahoodie.com. This index never sums figures across incidents. See the methodology.