Desk live·
ForensicPost
Breaches/Aviation/File 26-0702

Qantas Customer Data Published a Year After Third-Party Platform Breach

Qantas detected unusual activity on a third-party customer service platform in mid-2025, affecting up to six million customers. In 2026 the data was published. The negotiation ended; the exposure did not.

Constructed geometry · not a chart of case data
TargetQantas
ActorScattered Lapsus$ Hunters
S. Rosler10 min readConfidence: high2 sources reviewed

Qantas detected unusual activity on a third-party customer service platform on 30 June 2025. The exposure was reported as affecting up to six million customers. In 2026, as part of a wider escalation by the extortion cluster now operating as Scattered Lapsus$ Hunters, records were published, with reporting describing around five million released.

The gap between those two paragraphs is the file. Roughly a year separates the incident from the publication, and during that year the affected customers had no way to know which outcome they were heading for.

Disclosure Timing Assumes A Resolution

Breach notification regimes are built around a moment: the organisation learns, assesses, and tells people within a defined window. That model fits an incident with an end.

Theft-and-extortion has no such end. The data is taken on day one and may be published in a year, or never, depending on decisions made by the group. Customers notified in 2025 received accurate information that became materially incomplete in 2026, and there is generally no mechanism requiring anyone to tell them so.

The Platform Was Somebody Else’s

The entry point was a third-party customer service platform, consistent with the broader pattern this desk has filed repeatedly this year: the airline’s own systems were not the failure, and the affected people had a relationship only with the airline.

For an aviation customer database the fields are more consequential than a generic contact list — travel patterns, frequent-flyer identifiers, and in many cases the identity documents required to fly.

How we reported this

Compiled from public reporting, listed below. Published-record counts originate with the group and are labelled as claims; the six-million figure is as reported by the company. We did not review the published data. Corrections: corrections@forensicpost.com.

Sources
  1. ShinyHunters behind Salesforce data theft attacks at Qantas, Allianz Life, and LVMHBleepingComputer
  2. Salesforce breach escalates: Qantas and Vietnam Airlines data leaked on dark webOutpost24
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary