Just days after confidently assuring the public that its systems remained secure following a major cyber attack, Qantas Airways has been forced into an embarrassing about-face.
The airline disclosed last night that cyber criminals have now made contact – a development that exposes the premature nature of its earlier reassurances.
The sequence of events paints a troubling picture of corporate communications gone awry. Last Tuesday, Australia’s flag carrier detected a security breach at one of its contact centres, affecting approximately six million customers’ personal information.
By Friday, the airline was fielding over 5,000 concerned enquiries through a dedicated support line while simultaneously downplaying the severity of the incident.
The airline’s initial response seemed designed more to calm markets than inform customers. Officials emphasised that Qantas Frequent Flyer accounts remained unaffected and stressed that no credit cards, financial information, or passport details were stored on the compromised system.
“Right now we’re focused on providing the answers and transparency they deserve,” Qantas Group chief executive officer Vanessa Hudson said before the weekend.
“Our investigation is progressing well with our cybersecurity teams working alongside leading external specialists to determine what information has been accessed.
“We’re finalising a process that will enable us to provide affected customers with more information about their personal information that was potentially compromised.”
Hudson’s words about “transparency” particularly ironic given the rapid deterioration of the situation.
At the time of her statement, Qantas maintained that no criminals had contacted them regarding the stolen data. That narrative has now collapsed entirely.
“A potential cyber criminal has made contact and we are currently working to validate this,” the airline said in a statement.
“As this is a criminal matter, we have engaged the Australian Federal Police and won’t be commenting any further on the detail of the contact.
“There is no evidence that any personal data stolen from Qantas has been released but, with the support of specialist cyber security experts, we continue to actively monitor.”
The timing couldn’t be worse for an airline already struggling with public trust issues. The incident appears to align with broader industry warnings that Qantas either ignored or failed to adequately prepare for.
According to Elliot Dellys, CEO of Australian cyber security company Phronesis Security, the breach follows a recent FBI warning about criminal organizations specifically targeting the airline sector.
The warning concerned a group known as Scattered Spider, which Dellys describes as a “disparate group of young hackers living in the US and UK.”
“Scattered Spider had been targeting the airline sector, impersonating legitimate users to gain access to systems and bypass multi-factor authentication, one of the most effective methods of preventing breaches,” Dellys said.
“It would therefore be little surprise if the Australian aviation sector had come within its crosshairs, as a high value target with a complex, and historically challenging, environment to secure.”
The question now is whether Qantas was caught off guard by a predictable threat, or whether its initial confidence was simply misplaced corporate bravado.

