HomeSecurityQantas: Cyberattack led to data breach

Qantas: Cyberattack led to data breach

Australian airline Qantas has detected a cyberattack on a third-party customer service platformthat stored sensitive personal data of millions of customers.

Qantas: Cyberattack led to data breach

According to an official statement, unknown cybercriminals managed to gain unauthorized access through a call center partnered with Qantas. The company noted that the breach was quickly contained and all of its core systems remain secure.

"On Monday, we detected unusual activity on a third-party platform used by a airline . We then took immediate action and restricted the system. We can confirm that all Qantas systems remain secure," Qantas said.

See also: Johnson Controls: Notifies individuals about 2023 data breach

Qantas has revealed that the breach affected the records of up to 6 million customers, with initial indications that information such as names, emails, phone numbers, dates of birth and frequent flyer numbers were exposed . However, it insists that no credit card details, financial data or passwords were compromised .

The company continues its investigation into the full scope of the breach, while cooperating with the relevant authorities and cyber security teams to manage the incident.

Qantas: Cyberattack raises concerns about targeting of aviation

The cyberattack on Qantas comes at a time of heightened concern, as experts warn of the growing activity of the cybercrime group Scattered Spider, which has begun to turn its attention to the aviation and transportation industries.

Although there are no official indications that Scattered Spider is behind the attack on Qantas, sources from BleepingComputer note that there are similarities with previous incidents that have been attributed to that group.

See also: 263,000 people affected by Esse Health breach

Protection: Technology, education and transparency

Protecting against cyberattacks in the aviation sector requires a multi-layered approach:

  • Investments in cutting-edge cyber defense: Development of strong firewalls, threat detection through AI, data encryption and continuous network monitoring.
  • Staff training: The human factor is often the weakest link. Training in phishing, password management, and incident response is essential.
  • Regulatory compliance and transparency: Companies must comply with international cybersecurity regulations and maintain a transparent notification policy in cases of breaches.
  • Collaboration with authorities and other companies: Sharing information about threats and vulnerabilities strengthens collective defense.
Qantas data breach cyberattack
Qantas: Cyberattack led to data breach

As digital transformation continues at a rapid pace, airlines must address cybersecurity as a critical issue. It is not just a matter of technology, but of trust and survival. Protecting their networks is not a luxury — it is a prerequisite for safe, reliable and transparent air travel.

Scattered Spider

Scattered Spider — also known by aliases such as 0ktapus, UNC3944, Scatter Swine, and Muddled Libra — uses sophisticated social engineering methods, such as phishing, SIM swapping, MFA bombing, and help desk to steal employee credentials.

One of the most high-profile examples was the attack on MGM Resorts in September 2023, where the group used employee credentials to encrypt more than 100 VMware ESXi hypervisors using the BlackCat ransomware. Scattered Spider has also reportedly collaborated with other criminal groups such as RansomHub, Qilin, and DragonForce, and has targeted companies such as Twilio, Coinbase, DoorDash, MailChimp, Riot Games, Reddit, and Caesars.

See also: Ahold Delhaize breach affects 2.2 million people

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

More recently, the group appears to have turned to the airline industry, with incidents at Hawaiian Airlines and WestJet considered related. In the WestJet case, cybercriminals used a self-service password reset feature to gain access to an employee account and infiltrate the company's network.

The group targets a different sector each time, with experts estimating that it is not clear which industry will be the next target.

Organizations are urged to strengthen their defenses by prioritizing critical infrastructure, such as platforms password recovery, help desks, and third-party providers. Google Threat Intelligence Group and Palo Alto Networks have already issued relevant guides with recommended protection measures.

It is noted that Scattered Spider is also linked to other recent attacks on companies such as M&S, Co-op, Erie Insurance and Aflac.

Source: www.bleepingcomputer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS