Qantas has confirmed a cyber incident involving one of its offshore call centres. The breach was linked to a third-party platform used for customer service.
What’s happened?
On Monday, Qantas detected unusual activity on the external platform and moved quickly to contain it. Flight operations and internal systems were not affected.
The company is still confirming how much data was accessed but expects the number of affected records to be significant. The company has stated that 6 million customer records were held with the service that was exploited.
What data was accessed?
- Names
- phone numbers
- email addresses
- birth dates
- Frequent flyer numbers
No payment details, passport information, logins or PINs were stored in the affected system.
What’s being done by Qantas?
Qantas is contacting affected customers directly and has set up a dedicated support line. Identity protection advice is being offered.
The breach has been reported to the AFP, the National Cyber Security Coordinator and the Office of the Australian Information Commissioner.
External cybersecurity experts have also been brought in to conduct a forensic examination and repair their systems.
Why this matters
Most businesses use third party platforms to manage normal daily operations. Things like payroll systems, websites and tools that store customer information. They sit outside core infrastructure but still hold valuable data. This is why they’re such a common path for attackers.
What customers should do
No banking or passport details were involved, which is a sign that Qantas was practicing proper data separation. But with names and contact details exposed, customers should:
- Beware of increase phishing messages, especially using your full name or flight history
- Watch for unexpected messages about your Qantas or frequent flyer accounts
- Avoid clicking links or entering your login information into sites that look suspicious
If you’re concerned, Qantas has more support options listed on their official page.



