Qantas

Jul 2025 · Graded Attested · Transportation and Logistics · Beyond the filings

Incident summary

QantasJul 2025
Not yet quantified
AAttested
An unnamed threat actor impersonating "Qantas IT help" contacted the airline's call centre. The agent was tricked into connecting a customised version of Salesforce's Data Loader tool to the customer relationship management platform used by Qantas, which enabled mass data extraction. 5.67 mm customer records were exposed. The cost of cyber losses and recovery has never been disclosed, with Qantas executives agreeing to forfeit $800k AUD in bonuses due to the incident.
Transportation and Logistics
Company statement
Initial attack type phishing or social engineering confirmed · Impact data theft confirmed

About this record

This incident is beyond the filings: attributed to a company statement, a regulator or court record, or a news report, and graded Attested or Inferred. Every figure links to the source it was read from; if we have read one wrong, tell us at info@hackerinahoodie.com. This index never sums figures across incidents. See the methodology.

Cite this incident

← The complete Beyond the Filings ledger ← Back to the index