#Qantas

James Cridlandjames@bne.social
2025-10-13

Made a formal complaint to the OAIC - which has a purpose of "making sure that Australian Government agencies and organisations with an annual turnover of more than $3 million, and some other organisations, follow the Privacy Act 1988 and other laws when handling personal information" - about the #Qantas data leak.

If they get away with a slap on the wrist, and not a big fine (and ideally a payment to each customer), I'll be annoyed. The OAIC's purpose is to ensure adherence to the law. Without a massive bloody fine, they'll be as useless as ACMA (and that's pretty useless).

#AusPol

2025-10-13

Qantas faces major cyberattack exposing sensitive customer data, prompting urgent security investigation.

mysearch.ai/qantas-news-today-

woodchuckhuels at KillBaitwoodchuckhuels@killbait.com
2025-10-12

Qantas Data Breach Exposes 5 Million Customer Records After Ransom Deadline

A hacker collective named Scattered Lapsus$ Hunters has leaked personal data of around 5 million Qantas customers on the dark web after a ransom deadline passed. The airline is one of 44 companies worldwide affected by a widespread cyber-attack that has exposed up to 1 billion customer records. The ... [More info]

The Japan Timesthejapantimes
2025-10-12

Australian airline Qantas said Sunday that data from 5.7 million customers stolen in a major cyberattack this year had been shared online, part of a leak affecting dozens of firms. japantimes.co.jp/business/2025

N-gated Hacker Newsngate
2025-10-11

🚨 Breaking news: joins the elite club of companies that think ignoring hackers will make them go away. 🙄 5 million customers can now enjoy the thrill of identity theft, courtesy of an airline that thought a "ransom deadline" was just a suggestion. ✈️🔓
theguardian.com/business/2025/

David HollingworthDavid_Hollingworth
2025-10-11

Welp, there it is. Can't say much about the data due to the injunction Qantas took out, but it's now public, on both the clear- and dark webs.

cyberdaily.au/security/12759-q

Dissent Doe :cupofcoffee:PogoWasRight@infosec.exchange
2025-10-11

Quick update for those wondering if #ScatteredLAPSUSHunters actually started leaking the Salesforce victims on the onion leak site:

Yes. They started with 6 of the 39 companies: #Qantas, #Albertsons, #GAP, #VietnamAirlines, #Fujifilm, and #EngieResources.

Clicking on the download link in the company's listing takes you to a Limewire link for downloading the data.

When the onion was timing out, links were posted in the Telegram channel that would take users to the listings on Breachsta[.]rs forum. To download any of these leaks from their forum listings costs 4 credits.

So the same Shiny who wrote a statement claiming forums are dead planned and implemented a plan to leak the data in a forum in the event there was interference with, or problems with, the onion leak site.

And yes, I tested a download, and it worked.

With that, I bid you all good night, and see you tomorrow.

#databreach #Salesforce

2025-10-10

What if SLSH did not release the Qantas or Salesforce data BUT stated that the company paid the ransom. They could move bitcoin around from unknown accounts to backup their claim.

How could Qantas or any company refute that statement. In countries where paying a ransom is illegal the company could get into a heap of trouble.

#ransomware #qantas #salesforce #lapsus

Queen 1066Queen1066
2025-10-10

@spmatich So when said he never saw corruption in the federal government he actually meant it is hard to see it when your up to your neck in it. .

2025-10-09

lol, my #qantas flight was delayed by 15 min, now they've just announced the dunny is broken so make sure you go before we leave

GupperduckGupperduck
2025-10-09

… Further, Qantas won't be notifying the owners of the domains that their customers' email addresses are on. Many people will be using their work email address for their Qantas account, and when you tie that together with the other exposed data attributes, that creates organisational risk. Companies want to know when corporate assets (including email addresses) are exposed in a data breach, and unfortunately, we won't be able to provide them with that information.

GupperduckGupperduck
2025-10-09

"Court Injunctions are the Thoughts and Prayers of Data Breach Response"

@ troyhunt @ infosec.exchange

troyhunt.com/court-injunctions


As such, I was particularly interested when they applied for, and were granted, a court injunction of their own. Why? What possible upside does this provide? …

From an HIBP perspective, we obviously can't load that data. It's very likely that hundreds of thousands of our subscribers will be impacted, and we won't be able to let them know …

2025-10-08

youtu.be/AzbztNQ3Dm0?si=gyDHuv

Valid points all around. Work rules based on human science enforced for one work group and blown off for another takes its toll. Not just on the ramp, but in all service areas attached to this airline.

#qantas #Jetstar #racetothebottom

2025-10-08

Qantas among nearly 40 companies facing ransom demand from hacker group

Hacker collective Scattered Lapsus$ Hunters reportedly threatening to leak stolen personal data from dozens of firms in major extortion attempt

theguardian.com/business/2025/

No doubt the Aus gov will get the wet lettuce leaf out

#News #Qantas #Hacked #DataLeak

2025-10-05
2025-10-02

Qantas Frequent Flyer Program sparks backlash as travelers criticize sudden point devaluation impacting rewards.

mysearch.ai/qantas-frequent-fl

2025-10-01

What is Australia’s worst company?

It’s been a rotten… year… well, decade, for Australian business. No sooner did the big banks get busted…
#NewsBeep #News #Headlines #AlanBondAwardforCorporateEvil #AU #Australia #bigfourbanks #coles #Companies #NewsCorp #Qantas #santos #woodside #Woolworths
newsbeep.com/158283/

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst