Close Menu
thewitness.com.au
  • Home
  • Latest
  • National News
  • International News
  • Sports
  • Business & Economy
  • Politics
  • Technology
  • Entertainment

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Curnow, Petracca, Merrett and Oliver headline deals needing completion

October 12, 2025

Beloved actress Diane Keaton dies at the age of 79

October 12, 2025

‘DWTS’ star Derek Hough celebrates Hayley Erbert’s birthday on babymoon

October 12, 2025
Facebook X (Twitter) Instagram Threads
thewitness.com.au
Facebook X (Twitter) Instagram
Subscribe
  • Home
  • Latest
  • National News
  • International News
  • Sports
  • Business & Economy
  • Politics
  • Technology
  • Entertainment
thewitness.com.au
Home»Latest»Airline caught in major extortion attempt by Scattered Lapsus$ Hunters hacking group
Latest

Airline caught in major extortion attempt by Scattered Lapsus$ Hunters hacking group

info@thewitness.com.auBy info@thewitness.com.auOctober 8, 2025No Comments4 Mins Read
Airline caught in major extortion attempt by Scattered Lapsus$ Hunters hacking group
Share
Facebook Twitter Pinterest Threads Bluesky Copy Link


The saga for Qantas began on June 30, when cyber-criminals accessed nearly 6 million customer accounts through a third-party vendor at a Qantas call centre in Manila. A week later, Qantas was approached by what it labelled a “potential” cybercriminal.

The airline later confirmed that 5.7 million customers had their information accessed, including name, phone numbers, business phone numbers, addresses and even the food preferences of thousands of travellers. It revealed later that the “majority” of a subset of 2.8 million customer records had frequent flyer information, including the level of Qantas membership accessed.

Rather than directly hacking Salesforce’s systems – which remain secure – the hackers exploited the human element. Using voice phishing calls, they convinced IT helpdesk staff to install what appeared to be legitimate software: a modified version of Salesforce’s Data Loader tool, which is normally used to bulk-import data.

Once installed, this Trojan horse gave hackers unfettered access to customer databases.

Qantas chief executive Vanessa Hudson.

Qantas chief executive Vanessa Hudson.Credit: Oscar Colman

The Scattered Lapsus$ Hunters collective has already claimed responsibility for earlier attacks on British retailers including Marks & Spencer, Co-op and Jaguar Land Rover. Security researchers at Google’s Threat Intelligence Group warn the group has “proven particularly effective at tricking employees”.

The hackers’ technical infrastructure suggests ties to “The Com” – a loosely organised cybercriminal ecosystem comprising small, disparate groups known for increasingly brazen attacks and, in some cases, violent activity. British police arrested four suspects under 21 in July following the breaches targeting UK retailers.

Loading

Salesforce has told its clients it won’t pay the ransom. “I can confirm Salesforce will not engage, negotiate with, or pay any extortion demand,” a company spokesman told this masthead.

Sophos security researcher Aiden Sinnott warns the group’s October 10 deadline should be taken seriously. “A lot of what they post is intentional misinformation and trolling,” he said. “But they aren’t averse to leaking huge amounts of data.”

This comes at a sensitive time for the airline, given the prominent role its lounges have in catering to influential politicians, judges and policymakers.

Qantas has pursued a legal strategy of trying to minimise the legal public disclosure of the personal details of the affected customers, including the status as members of Qantas’ loyalty programs.

On October 2, Qantas received final orders from the NSW Supreme Court on an injunction against the hacking group, even though the exact details of their identity were unclear.

This legal strategy, while protecting the identity of victims, prevents media, social media and other lawful entities from publishing the sensitive information, even as it may be sold on the dark web to criminals.

The NSW judge suppressed the names of a Qantas expert, and the lawyers and barristers representing the airline in court, according to AAP.

The stolen data reportedly includes customer dates of birth, passport numbers and purchase histories.

The stolen data reportedly includes customer dates of birth, passport numbers and purchase histories.
Credit: Bloomberg

Clayton Utz partner James Neil said Qantas’ injunction is an example of where “litigation can be used to indirectly target parties”, in this case primarily media and social media platforms.

Loading

“I don’t think their main concern though is nefarious actors working through the dark web. It really is the larger organisations who might have a broader reach in publishing information.”

The airline, in a period of rebuilding public trust under CEO Vanessa Hudson, has taken pains to show it takes customer privacy seriously.

Hudson’s 2025 annual bonus was cut by 15 percentage points in September as a result of the impact the cyber incident had on customers. “This reflects their shared accountability while acknowledging the ongoing efforts to support customers and put in place additional protections for customers,” said chairman John Mullen.

Hudson’s short-term incentive plan was cut by $250,000, with $550,000 cut for all other executives.

The Business Briefing newsletter delivers major stories, exclusive coverage and expert opinion. Sign up to get it every weekday morning.

Share. Facebook Twitter Pinterest Bluesky Threads Tumblr Telegram Email
info@thewitness.com.au
  • Website

Related Posts

Curnow, Petracca, Merrett and Oliver headline deals needing completion

October 12, 2025

Beloved actress Diane Keaton dies at the age of 79

October 12, 2025

‘DWTS’ star Derek Hough celebrates Hayley Erbert’s birthday on babymoon

October 12, 2025
Add A Comment
Leave A Reply Cancel Reply

Demo
Top Posts

Widower, doctor call for disgraced surgeon to be stripped of NSW Australian of the Year award

September 14, 202511 Views

Sex offender Daniel Hume’s successful application sparks controversy

September 1, 20257 Views

To join urgent meeting on Ukraine crisis with Emmanuel Macron and NATO leaders

September 3, 20254 Views
Don't Miss

Curnow, Petracca, Merrett and Oliver headline deals needing completion

By info@thewitness.com.auOctober 12, 2025

LoadingClayton OliverWe know two things: Oliver is about to become a Giant, and Melbourne will…

Beloved actress Diane Keaton dies at the age of 79

October 12, 2025

‘DWTS’ star Derek Hough celebrates Hayley Erbert’s birthday on babymoon

October 12, 2025

Tradie escapes fiery crash on highway

October 12, 2025
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Top Trending
Demo
Most Popular

Widower, doctor call for disgraced surgeon to be stripped of NSW Australian of the Year award

September 14, 202511 Views

Sex offender Daniel Hume’s successful application sparks controversy

September 1, 20257 Views

To join urgent meeting on Ukraine crisis with Emmanuel Macron and NATO leaders

September 3, 20254 Views
Our Picks

Curnow, Petracca, Merrett and Oliver headline deals needing completion

October 12, 2025

Beloved actress Diane Keaton dies at the age of 79

October 12, 2025

‘DWTS’ star Derek Hough celebrates Hayley Erbert’s birthday on babymoon

October 12, 2025

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

Facebook X (Twitter) Instagram Pinterest
  • Home
© 2025 ThemeSphere. Designed by ThemeSphere.

Type above and press Enter to search. Press Esc to cancel.