Breach Watch
Qantas
Qantas — Third-party compromise discovered June 2025
- Update to a previously disclosed incident
- Third-party compromise
- Verified from an official regulator or organisation notice
What this record states
Qantas has reported a data breach through a platform operated by a third party.
The source states that information about customers and Frequent Flyer accounts was involved, across 11 categories of personal information.
Qantas identified the incident on 30 June 2025.
No source consulted for this record states when the incident occurred and when it was first publicly disclosed.
The number of people affected has not been stated.
Record overview
- Incident date
- Not confirmed
- Discovery date
- 30 June 2025
- Disclosure date
- Not confirmed
- Notification date
- Not confirmed
- People affected
- Not stated
- Who was affected
- customers and Frequent Flyer accounts
Each date is either established by a quoted source or explicitly not confirmed.
Affected people and data
Categories of affected data
- Name
- Email address
- Qantas Frequent Flyer number
- tier
- status credits
- points balance
- Address
- Date of Birth
- Phone number
- Gender
- Meal preferences
Notifications and response
Regulators notified
- National Cyber Security Coordinator
- Australian Cyber Security Centre
- Office of the Australian Information Commissioner
Law enforcement notified
- Australian Federal Police
Legal and formal response
- interim injunction in the NSW Supreme Court
Technical and organisational remediation
- further restrict access
- strengthen system monitoring and detection
- requiring additional identification for account changes
Official sources
Further official sources
Regulatory update
Privacy Commissioner completes preliminary inquiries into Qantas 2025 data incident | OAIC