Get all your news in one place.
100’s of premium titles.
One app.
Start reading
TechRadar
TechRadar
Sead Fadilpašić

Qantas admits 5 million customers have data leaked following ransomware attack - here's what you need to know

Code Skull.
  • Hackers reportedly leaked data of 5 million Qantas customers after failed extortion attempt
  • Attackers exploited Salesloft-Salesforce integrations to access and steal customer data
  • 44 companies were affected, including Disney, Toyota, McDonald’s, and Vietnam Airlines

Up to 5 million Qantas customers could be at risk of cyberattacks or scams after hackers claimed to release their stolen data online.

Scattered Lapsus$ Hunters say they released the stolen files on the dark web having had no response from Australia’s biggest airline over a ransomware demand.

The archive includes personal records of 5 million Qantas customers, including people’s names, email addresses, phone numbers, birth dates, and frequent flyer numbers. Credit card details, financial information, and passport details weren't stolen, it was said.

"Don't be the next headline"

In summer 2024, a group of hackers going by the name Scattered Lapsus$ Hunters broke into Salesforce accounts belonging to hundreds of organizations in different industries - although Salesforce itself was not breached.

The attackers compromised Salesloft accounts that were integrated with Salesforce and exploited the linked API tokens and OAuth connections to pivot into Salesforce environments and exfiltrate customer data.

The group tried to extort Qantas for money, offering to delete the stolen files in exchange. The airline, however, refused to even discuss the matter with the attackers, telling Guardian Australia it “will not engage, negotiate with, or pay any extortion demand”.

“Don’t be the next headline, should have paid the ransom,” the group posted on its data leak site.

However analysts at cybersecurity outfit Intel 471 claim Qantas is reportedly only one of 44 companies whose sensitive customer data ended up on the dark web, with Gap, Vietnam Airlines, Toyota, Disney, McDonald’s, Ikea, and Adidas all affected.

This means numerous cybercriminals have easy access to contact and flight information on millions of people, which they can use for phishing, identity theft, fraud, and other attacks.

Scattered Lapsus$ Hunters is a group comprising members of Scattered Spider, Lapsus$, and ShinyHunters. Soon after the Salesloft/Salesforce breach, they announced “going dark”, which the cybersecurity community interpreted as fear of too much publicity. Obviously, it didn’t last long.

Via The Guardian

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!

And of course you can also follow TechRadar on TikTok for news, reviews, unboxings in video form, and get regular updates from us on WhatsApp too.

You might also like

Sign up to read this article
Read news from 100’s of titles, curated specifically for you.
Already a member? Sign in here
Related Stories
Top stories on inkl right now
One subscription that gives you access to news from hundreds of sites
Already a member? Sign in here
Our Picks
Fourteen days free
Download the app
One app. One membership.
100+ trusted global sources.