Australia’s Qantas says cyber criminal contacts one week after data breach


A cyber criminal has made contact with Australia’s Qantas following a data breach last week that exposed personal information of six million customers, a company spokesperson told Reuters on Tuesday.

The hacker had targeted a call centre and gained access to a third-party customer service platform containing the customers’ names, email addresses, phone numbers, birth dates and frequent flyer numbers. “As this is a criminal matter, we have engaged the Australian Federal Police and won’t be commenting any further on the detail of the contact,” the spokesperson said.

Read more…
Source: MSN News


Sign up for the Cyber Security Review Newsletter
The latest cyber secnews and insights delivered right to your inbox.


Related:

  • OpenAI explains how its AI agent breached Hugging Face

    July 29, 2026

    On July 28, OpenAI published an update on the agent that escaped its sandbox and hacked into Hugging Face during an internal cybersecurity evaluation. In the update, OpenAI reiterates that the “rogue” system was a more capable, pre‑release research model, not something intended for public deployment, and that it has now been deactivated and locked down for restricted research ...

  • Iran-linked CyberAv3ngers suspected in attacks on Minnesota water systems

    July 29, 2026

    Security researchers at Tenable suspect the Iran-linked faux hacktivist outfit CyberAv3ngers was behind the cyberattack that disrupted more than 30 Minnesota water facilities. Neither state-level nor federal officials have made any claims regarding attribution for the attacks, however, Tenable reckons the operational pattern is consistent with the crew’s previous raids, noting the timing relative to recent government warnings. The ...

  • Google goes it alone with a new cybercrime crew taxonomy

    July 27, 2026

    Google has created a new taxonomy to describe cybercrime outfits, seemingly abandoning a Microsoft-led effort to create consistent names. The Big G announced its new schema on Saturday in a post that notes its 2022 acquisition of Mandiant and its subsequent incorporation into a new team called the Google Threat Intelligence Group (CTIG). Now that two have become one, Google reckons ...

  • Hugging Face CEO calls for ‘radical transparency’ after ‘unprecedented’ OpenAI hack

    July 26, 2026

    After OpenAI recently admitted that one of its models had breached the systems of AI platform Hugging Face, Hugging Face’s CEO Clem Delangue posted on X that he was flying to San Francisco to have “a little chat with that ‘rogue agent.’” Then, in a follow-up post on Saturday, Delangue outlined what he’d asked for from OpenAI. He said he called ...

  • What the First Autonomous Ransomware Case Confirms

    July 24, 2026

    Security researchers have documented an AI agent running a full ransomware operation on its own against a live production target, planning, adapting, and executing every step from the first exploit through data destruction. This is early real-world evidence of the shift to autonomous criminal operations that our research forecast. Agent-run attacks change what defenders can rely ...

  • CISA has expanded the scope of its alert on Iranian-affiliated hackers attacking critical infrastructure

    July 23, 2026

    The US Cybersecurity and Infrastructure Security Agency (CISA) has expanded the scope of its alert on Iranian-affiliated hackers attacking critical infrastructure, including water and energy facilities. The original advisory focused on programmable logic controllers (PLCs) manufactured by Rockwell Automation/Allen-Bradley. The update warns that the activity may also target devices from Schneider Electric, Siemens, “and potentially other branded/manufactured PLCs.” The conflict between ...