170.jpg

 

It has been confirmed that the personal information of about 5.7 million Qantas customers of Australian airlines was massively leaked onto the dark web. The attackers are a hacking group known as 'Scattered Lapsus$ Hunters,' and when Qantas refused to pay the ransom, the blackmail deadline expired and the data was disclosed. The disclosed data amounts to 150GB and includes names, dates of birth, emails, phone numbers, addresses, and Frequent Flyer membership numbers , yet Qantas stated, "No passport numbers or payment card information have been leaked." However, security experts warn that even this information alone could lead to secondary attacks such as phishing attacks, fraud, account hijacking, smishing texts, and mileage point theft . They warned. In particular, it is expected that malicious messages impersonating "airline payment refunds" or "mileage accrual confirmation" will likely increase. This attack was carried out not through Qantas's internal systems but through an external customer management (contact center) platform , where attackers are believed to have stolen access rights to the system and infiltrated Salesforce-based CRM data. This incident is known as "the largest personal information breach in Australia since the Optus and Medibank incidents in 2022 ." It is known to be the largest personal information breach." Qantas has begun providing identity protection services and 24-hour consultation support to affected customers,,, and stated, "We are working closely with the Australian Federal Police and government agencies to minimize customer damage."