Qantas detected unusual activity on a third-party customer service platform on 30 June 2025. The exposure was reported as affecting up to six million customers. In 2026, as part of a wider escalation by the extortion cluster now operating as Scattered Lapsus$ Hunters, records were published, with reporting describing around five million released.
The gap between those two paragraphs is the file. Roughly a year separates the incident from the publication, and during that year the affected customers had no way to know which outcome they were heading for.
Disclosure Timing Assumes A Resolution
Breach notification regimes are built around a moment: the organisation learns, assesses, and tells people within a defined window. That model fits an incident with an end.
Theft-and-extortion has no such end. The data is taken on day one and may be published in a year, or never, depending on decisions made by the group. Customers notified in 2025 received accurate information that became materially incomplete in 2026, and there is generally no mechanism requiring anyone to tell them so.
The Platform Was Somebody Else’s
The entry point was a third-party customer service platform, consistent with the broader pattern this desk has filed repeatedly this year: the airline’s own systems were not the failure, and the affected people had a relationship only with the airline.
For an aviation customer database the fields are more consequential than a generic contact list — travel patterns, frequent-flyer identifiers, and in many cases the identity documents required to fly.
Compiled from public reporting, listed below. Published-record counts originate with the group and are labelled as claims; the six-million figure is as reported by the company. We did not review the published data. Corrections: corrections@forensicpost.com.