Qantas customer data has now been confirmed on the dark web following a ransom campaign led by a hacker group calling itself Scattered Lapsus$ Hunters.
The group had claimed to hold up to one billion records from 39 companies connected to Salesforce, including Disney, Toyota, and Google. After the ransom deadline passed on October 10, portions of the data began surfacing on leak forums, including information linked to Qantas customers.
What Was Stolen
The exposed data includes names, phone numbers, email addresses, and frequent flyer details for up to 5.7 million customers. In some cases, the leaked records also include dates of birth, gender, home and business addresses.
No financial details or passwords were part of the leak, but threat actors are still able to use this information to carry out targeted attacks.
How It Happened
The breach originated through an offshore Qantas call centre that used Salesforce software.
The hacker group claimed to have gained access to Salesforce databases through social engineering and voice phishing, where employees were tricked into providing access credentials.
Qantas was one of nearly 40 companies named in the ransom note, which warned that all customer data would be released if Salesforce did not pay by the 10th of October. Salesforce has since confirmed it will not engage with ransom demands and has found no evidence that its platform itself was compromised.

Screenshot of Scattered Lapsus$ Hunters ransom post on the dark web (Source).
Why the Data Was Published
When ransom negotiations fail, stolen data becomes leverage. Releasing it publicly serves two purposes to these threat groups. First, to damage the companies involved. Second, to prove credibility to their future victims.
Once published, the data is often shared between multiple groups, sold for small profits, or repackaged for new scams. Even partial records hold value on the dark web, where identity data is reused for phishing, credential stuffing and extortion attempts.
How Far Back It Goes
Qantas confirmed the data relates to records collected between 2022 and mid-2024, overlapping with the airline’s earlier June breach that exposed up to six million records.
That breach had already led to legal action, with Qantas obtaining an injunction from the NSW Supreme Court to stop any of the stolen data from being accessed or circulated.
The order bans anyone from viewing, sharing, publishing, or distributing the material in any form.
What Happens Next
Cybersecurity Minister Tony Burke also warned that it’s illegal to search for or access the leaked data, even if individuals are trying to check their own records. Many dark web sites also take advantage of curiosity and host malicious files designed to infect users.
There’s a good chance we will now see a second wave of scams that impersonate Qantas or government agencies, offering apologies, refunds or compensation to steal more personal information.
Qantas says affected customers will continue to receive support through its dedicated identity protection service and 24 hour hotline.



