Qantas detected an incident on 30 June 2025 in which an attacker targeted a call centre and obtained access to a third-party customer servicing platform. The airline subsequently confirmed that as many as 5.7 million customers were affected.
Two Structures This Database Files Separately, Combined
The call centre is the identity-led route — the human who can be persuaded, filed at 25-0512 and throughout the identity theme. The third-party servicing platform is the concentration route — the supplier holding everybody’s customers, filed at 25-0801 and 25-0814.
Here they compose. A single conversation produced access to an estate holding 5.7 million records, because the person being deceived was authorised on a platform whose scope was the entire customer base.
The lesson is not that call centres need better training. It is that the blast radius of a successful social-engineering call is set by an architectural decision made elsewhere — how much a servicing agent’s session can reach — and nobody makes that decision while thinking about social engineering.
An Airline’s Customer File Is A Travel History
Frequent-flyer records are not simply contact details. They describe where a person has been, how often, with whom they were booked, and what they paid — a longitudinal movement record accumulated over years.
That is the dataset described at 25-0725 as a component of pattern-of-life collection. This desk is not suggesting any such purpose here; the point is that the same records support entirely different uses depending on who holds them, and an airline’s risk assessment considers only fraud.
Same-Day Detection, Again
The incident was detected on the day it occurred. As at 25-1027, that deserves stating plainly against a corpus full of multi-month dwell times.
It also did not prevent the outcome. When the access route is a legitimate session on a platform designed for bulk customer servicing, extraction is fast, and detection speed stops being the control that matters.
Compiled from public reporting of company statements, listed below. The servicing platform is not named. The affected figure is the company’s upper bound as reported. Corrections: corrections@forensicpost.com.
- Top 10 cyber-attacks of 2025Infosecurity Magazine
- Top data breaches in 2025, month-wiseSecurity Boulevard