Qantas has confirmed a major cyberattack that compromised the personal details of around 6 million customers. The breach occurred in July through a third-party call centre, highlighting once again how supply chain vulnerabilities can open doors to attackers.
Exposed information includes names, email addresses, phone numbers, dates of birth and frequent flyer membership details. Qantas has stressed that financial data, including payment information, was not affected.
Investigations suggest the attackers used “vishing” tactics-voice phishing calls designed to trick an employee into handing over access credentials. This social engineering approach allowed intruders to bypass technical safeguards and gain entry to the system.
Qantas is working closely with the Australian Federal Police and cybersecurity experts to investigate the incident. Impacted customers are being notified directly and offered support.
While payment details remain secure, the stolen information is highly valuable for phishing campaigns. Customers are urged to stay alert, verify any messages claiming to be from Qantas, and keep a close eye on their accounts for suspicious activity.
This is a stark reminder that cybercriminals often target the human element, not just technology. Training staff to recognise social engineering, enforcing multi-factor authentication, and auditing third-party partners are critical steps in reducing these risks.
Cybersecurity is not just about protecting systems it’s about protecting people.



