Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

Hackers published Qantas customer data after a ransom deadline expired on October 11, 2025, according to ABC News. The records came from a June 2025 compromise of a third-party customer-service platform. Australia’s privacy regulator later put the number of compromised records at about 5.67 million, including approximately 5.12 million Australians. Qantas said passwords, payment-card details, passport information and login credentials were not exposed.

Despite the deadline often being described as a ransomware deadline, the available evidence describes data theft followed by extortion—not encryption of Qantas’ airline systems. The main customer risk is that criminals may use exposed details to make phishing and impersonation attempts more convincing.

What happened after the deadline?

Qantas disclosed unauthorized access to a third-party customer-servicing platform on July 2, 2025. Months later, a cybercrime group threatened to publish data it said it had stolen from companies connected to the Salesforce ecosystem. The group set a 3 p.m. AEDT deadline on October 11, 2025, for payment. ABC News reported that Qantas customer data appeared on the dark web after that deadline.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The publication report did not establish that every affected record—or data from every company named in the threat—was released. ABC reported that material from only some of the targeted companies appeared to have been published at that point. Security researcher Troy Hunt told ABC that Qantas data in the leak matched a person’s unique email address and Frequent Flyer information. That supports the authenticity of at least some material; it does not prove that every record attributed to Qantas was genuine, complete or current.

#1 Best Overall
RFID Wallet Women, Small Slim Trifold Wallet Anti-Theft Pop up Card Holder
  • 【RFID Protection】This women's RFID-blocking wallet features advanced technology to protect your personal information from electronic theft, keeping you safe while traveling or on the go
  • 【Compact Design】This slim women's wallet is perfect for those who prefer minimalist designs. Its compact size lets you carry all your essentials without bulk, making it ideal for everyday use
  • 【Spacious Capacity】With room for 9–11 cards, this wallet holds all your essential credit cards and IDs while staying slim. The inner pockets also provide extra storage for cash and additional cards
  • 【Quality Craftsmanship】Made from premium leather and aircraft-grade aluminum, this women's wallet combines durability with elegance. Its carefully crafted design ensures both style and long-lasting use, making it a reliable everyday accessory
  • 【Perfect Gift Choice】Whether for birthdays, graduations, valentine’s day, anniversaries, or other special occasions, this leather women’s wallet comes elegantly packaged—a thoughtful gift for wife, girlfriend, mother, daughters or loved ones who appreciate quality and style.

The report concerns a publication event in October 2025. It does not establish whether copies remain available today. Do not search for or download alleged leaked files: they may expose people’s personal information and can lead to scams or malicious downloads.

Was this a ransomware attack?

“Ransomware deadline” is an imprecise description here. The original Qantas incident involved theft of customer data from a customer-service platform, followed by an extortion threat and reported publication. The cited evidence does not say that malware encrypted Qantas systems or disrupted flights, bookings or airline operations.

Rank #2
SaiTech IT 5 Pack Premium RFID Blocking Card for Credit Debit Card, Black
  • SECURE YOUR WALLET FROM e-PICKPOCKETING: Prevent potential identity and financial theft through your contactless cards. Don’t become a victim e-theft in our growing contactless society. This is the simplest and most effective prevention solution! Block all RFID and NFC signal to secure your details and have peace of mind.
  • JAMMING CHIP: An antenna and jamming chip makes up the main components of the card. The antenna will sense incoming radio waves and draw power for the chip to create a jamming signal. Lifetime usage as the card does not require battery.
  • BROAD WORKING DISTANCE: A large working distance of 2.4” provides complete protection for your whole wallet. Cards 1.2” either side of the card will be fully secure from e-pickpocketing.
  • ULTRA-THIN & COMPACT: At the size of a standard credit card and at only 0.03” thick, the card will fit into any wallet, purse or card case. Keep your wallet compact with no added bulk from this card. Best for travel, business, and everyday use.
  • TEST THE CARD: Test the card is working at your local supermarket. At the self-service checkout machines, combine the card and a contactless card on the payment reader. Payment with the contactless card will be blocked and an error message should occur on the reader.

The Office of the Australian Information Commissioner (OAIC) says the initial access began with a phone-based social-engineering attack, also called vishing. On June 28, 2025, someone impersonating Qantas IT support called an overseas contact-centre employee, directed them to a website related to the customer relationship management (CRM) platform, and induced actions that connected the employee’s session to an attacker-controlled extraction tool. The attacker then used the employee’s legitimate access to take customer profiles.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Qantas detected unusual activity on June 30, revoked the relevant access and contained the incident. It announced the breach on July 2 and began notifying affected customers about the specific information involved around July 9, according to the OAIC’s account. Qantas said airline operations were unaffected. ABC also reported that Salesforce said it had found no indication that its platform had been compromised; the available reporting does not establish that Salesforce itself was breached.

Rank #3
Sale
RUNBOX Wallet for Men Slim Leather Bifold RFID Blocking with 2 ID Windows
  • Slim and Thin Wallet - This minimalist bifold wallet measures 4.3x3.2x0.6 inches and stores up to 15 cards. The bifold wallet perfectly fits in your pocket and is well-suited for everyday carry
  • Elite Features - 2 ID windows (DL & Other ID Cards) and 2 quick slots allow for quick access during travel, shopping or work. With 15 card slots and 2 more slots behind them, it is easy to carry all your important cards,cash and bills, meet all your daily needs
  • RFID Blocking- Our wallets are equipped with advanced RFID SECURE Technology, a unique metal composite, engineered specifically to block 13.56 MHz or higher RFID signals and protect the valuable information stored on RFID chips from unauthorized scans.License and ID cards will be protected effectively. No more worrying about unauthorized scans during travel, shopping, or daily commuting!
  • Durable Surface - Our leather wallets are pressed with high quality 3 layers leather, which is more durable than 2 layers leather wallets. The surface of the leather is made more scratch-resistant by special treatment, which can effectively prevent small scratches caused by keys and buttons in life
  • Gifts for him - The thin wallet comes in classy gift packaging. It is a perfect present for birthdays, anniversaries, Father's Day, Valentine's Day, Christmas and other special occasions, so you can easily gift it to someone you love

How many records were affected?

Qantas’ initial July 2 disclosure said the platform held service records for approximately six million customers, while the investigation was still determining how many were affected. The OAIC’s later report identified approximately 5.67 million compromised records overall, including overseas customers, and described approximately 5.12 million affected Australians. The early six-million figure described the platform’s customer-record population; it should not be treated as the regulator’s final count of compromised records.

What information was exposed?

The OAIC grouped the compromised records into two broad sets:

Rank #4
Kaabao Credit Card Holder Small RFID Blocking Wallet Business Metal Slim Mini Aluminum Hard Case for Women Men Gift (Lrises)
  • RFID Blocking Technology: This credit card holder is made of aluminum shells and ABS plastic, designed with RFID-blocking technology to help protect your credit, ID, debit, and driver's license cards from unauthorized scanning
  • Slim Compact: Slim and compact design measures 4.3 x 3 x 0.86 inches, ideal for front pockets or purses
  • Card Organizer: With 7 accordion-style slots, this wallet can hold up to 10 standard credit cards or over 20 business cards
  • Artistic Expression: Features a variety of artistic designs on the aluminum shell, inspired by famous paintings, flowers, and animals, to complement your personal style
  • Thoughtful Gift Idea: Makes a thoughtful gift for any occasion, combining functionality and style
  • About four million records: names, phone numbers, email addresses, Qantas Frequent Flyer numbers, membership tiers, points balances and status credits.
  • About 1.7 million other records: some of those details, plus one or more additional fields such as residential or business addresses, hotel addresses used to deliver misplaced baggage, dates of birth, gender or meal preferences.

Not every affected person had every listed field exposed. The exact information varied by record; Qantas’ notification to an individual is the better guide to that person’s exposure.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What was not exposed?

Qantas and the OAIC said the compromised platform did not contain or expose credit-card details, personal financial information, passport details or identity documents, passwords, PINs or login details. Qantas also said Frequent Flyer accounts themselves were not compromised.

Best Value
HIMI Wallet for Men-Genuine Leather RFID Blocking Bifold Stylish Wallet With 2 ID Window (Vintage Black)
  • GENUINE LEATHER: Precious Genuine Vegetable Tanned Cowhide Leather with nice and smooth texture, really soft & comfortable to touch. Vegetable tanned Leather is a luxury leather. It uses natural ingredients instead of chemicals, so it is environmentally friendly.
  • ELITE FEATURES: 2 ID windows (DL & Other ID Cards) allow for quick access when traveling or at the store /working place. With 8 card slots and 2 more slots behind them, it’s easy to carry all your important cards, meet all your daily needs.
  • RFID BLOCKING SECURITY: Our wallets are equipped with advanced RFID SECURE Technology, a unique metal composite, engineered specifically to block 13.56 MHz or higher RFID signals and protect the valuable information stored on RFID chips from unauthorized scans.
  • COMPACT DESIGN: Making this bifold superb for travel, and everyday use, keeping cards safe and organized! It holds 10+ cards, and lots of cash!
  • GIFT BOX PACKING: It is one of the most special gifts for Groomsmen, Birthdays, Anniversaries, Father's Day, Christmas and other Special Occasions.

That distinction matters: Frequent Flyer numbers, points balances, tiers and status credits were among the exposed data, but their exposure is not the same as someone obtaining the credentials needed to sign in. It also does not eliminate risk. A scammer can use contact details and loyalty information to make a fake airline message or call sound plausible.

What Qantas customers should do

  1. Be alert for tailored messages. Treat unexpected calls, texts and emails claiming to be from Qantas, a bank, a travel provider or a government agency with caution. A message that includes your name, Frequent Flyer number or other personal details is not automatically genuine.
  2. Do not share security codes or sensitive information in response to an unsolicited contact. Never give a caller or message sender your password, one-time code, payment details, passport information or identity documents.
  3. Verify independently. Open the official Qantas app or type the known website address yourself rather than following a link in a message. If you need help, use Qantas’ official support channels.
  4. Review your Frequent Flyer account. Check for unfamiliar activity. The reported breach did not expose login details, but reviewing the account is a sensible precaution.
  5. Change reused passwords. The breach does not mean your Qantas password was exposed. But if you reused that password on another service—or learn that credentials for another service were exposed—change it there, too. Use a unique password for each account.
  6. Turn on multifactor authentication where available. An additional sign-in check can help protect an account even if a password is exposed elsewhere.
  7. Watch for unusual account and identity activity. Pay attention to unexpected password-reset messages, new-account notifications, financial activity or identity-related applications. Contact the relevant provider directly if something looks wrong.
  8. Use trusted support, not “recovery” offers from strangers. In Australia, Scamwatch provides government scam guidance and reporting, while IDCARE offers identity and scam support if you suspect misuse. Qantas said its support team could also provide affected customers with identity-protection advice and resources.

A breach-checking service such as Have I Been Pwned can alert you if an email address appears in breaches it tracks, but a result—or the absence of one—does not confirm whether you were included in this specific Qantas incident. No service can prevent every scam. Start with account security, careful verification and official support.

What did the privacy regulator conclude?

In a report published July 16, 2026, the OAIC said it had completed preliminary inquiries covering July 11, 2025, to June 1, 2026. Based on the material it reviewed, the regulator said it had found no indication that Qantas failed to take reasonable steps to protect the information or manage its overseas provider. It closed those preliminary inquiries without starting a Commissioner-initiated investigation or taking regulatory action on that basis.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

This was not a blanket finding that every aspect of Qantas’ privacy practices was lawful or flawless. The OAIC described the work as preliminary inquiries, not a concluded investigation. It said individual and representative complaints remained separate matters and that a future investigation was possible. The regulator’s qualified outcome does not change what was exposed or the precautions customers can take.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.