One of the most effective ways to learn about cybersecurity and data backups is by studying the mistakes made by others. This allows you to examine the real-world context that emergencies play out in, and understand the many factors involved. You can then apply this information more readily to your own business.
One recent attack making headlines is the Qantas data breach. This incident exposed the information of millions of users, causing serious harm to both the company and their customers. So what can we learn from this devastating attack? How can you make sure your business isn’t next?
The Qantas Data Breach: What Happened?
On the 9th of July, 2025, Qantas confirmed that a “Cyber incident” had taken place. The details at that time were sparse, with the company only admitting that the attack had taken the form of fraudulent phone calls made to one of their airport contact centres. The true extent of the damage would not become clear until later.
It was eventually uncovered that this had been part of a larger supply chain attack carried out on Salesforce, a US-based cloud provider that Qantas had relied heavily on. Supply chain attacks involve the use of a third-party platform to gain access to the main target’s systems without raising suspicion. In this case, the attack vector used was a website called GitHub.
GitHub is a developer platform used to store and share code, which unfortunately makes it highly vulnerable to attack. Malicious code can be easily inserted into a repository, where companies will often download it accidentally. It is believed that this is precisely what occurred during the Qantas breach.
The Consequences
This attack carried severe consequences for Qantas and the general public. Almost 1 billion customer records were stolen, affecting an estimated 5.7 million individuals. Many of these were likely employees or business leadership who were traveling back and forth from work events. In October, the worst-case scenario was confirmed: some of this data had been leaked onto the dark web.
The impact on Qantas was immediate and devastating. Their brand has been tarnished, with plenty of customers looking elsewhere for future flights. The Minister for Home Affairs and Cyber Security has also announced that Qantas will be facing legal consequences. Last but certainly not least are the financial implications. The downtime, recovery, and investigative measures made necessary by this attack have all cost Qantas substantial amounts of money. It will likely take years to fully heal from an incident of this scale and severity.
5 Lessons Learned from the Data Breach in Qantas
1. Vendors Can Be Part of Your Attack Surface
This attack passed through a series of other companies before it ever reached Qantas. This meant that by the time threat actors were in communications with the company, they had gathered enough resources to launch an incredibly sophisticated scam. Supply chain attacks are especially devastating, because they exploit the trust that businesses have in their vendors and partners. You need to consider these third-parties part of your attack surface, and act accordingly.
2. Social Engineering is Still a Major Threat
Ultimately, the attackers got what they wanted through impersonation. Social engineering scams are only becoming more convincing, and the stakes are higher than ever. This demonstrates the importance of protecting your sensitive data through strong security awareness training. Staff must be able to identify a threat before it has the opportunity to reach your systems.
3. Data Segmentation and Access Controls are Crucial
One question being asked is why a vendor platform had this level of access to so much sensitive data in the first place. The truth is, this whole situation could have been avoided with stronger access controls and data segmentation. Where you store information, and who has the ability to access it, can make an enormous difference during an attack.
4. Immutable, Isolated Backups Are Non‑Negotiable
While Qantas has not reported any damage or destruction of data, this is always a possibility during a breach. You must keep multiple isolated, secured, and immutable backups at all times. Test them regularly to ensure that recovery is possible, and do not ever reuse credentials across multiple backup platforms.
5. Your Response Must Be Honest, Swift, and Actionable
Qantas did one thing right during this whole debacle: they kept customers updated, apologised, established support lines, and contacted the authorities immediately. Data breaches are not always avoidable, and how you respond when they do occur can make or break your business. Your first actions should be to isolate and remove the threat, contact authorities, inform affected individuals, and restore your backups – in that order.
FAQs
What Data Was Stolen in the 2025 Qantas App Data Breach?
The exact data stolen varied from one customer to another, depending on what information was stored within their accounts. We know for a fact that home addresses, email addresses, phone numbers, birth dates, and frequent flyer accounts were likely compromised. If anyone in your company has entered any of this information into Qantas systems previously, be on the lookout.
How Many Customers Were Affected?
It is believed that there are approximately 5.7 million affected customers.
How Did the Attackers Gain Entry?
It is currently believed that the attackers first gained entry to Salesforce information using malware on GitHub, then leveraged the data collected to launch convincing social engineering attacks against Qantas.
Can Backups Help Me if I Experience a Similar Attack?
Backups can definitely help you should your business experience a similar attack. They allow you to return to normal operations faster and mitigate ransomware. Strong backup procedures are an essential part of business continuity and disaster recovery planning.
What Can We Do if Business Data Was Affected?
If you have ever used Qantas to schedule work trips, then it is possible business data was compromised. Encourage all staff to change their passwords immediately. Provide additional security awareness training. Consider using a different airline for the foreseeable future, and monitor all accounts for suspicious activity. Most importantly: implement strong backup procedures immediately.
Got more questions about data protection? We’ve got answers
Discover How Backups Can Save Your Business
Major breaches such as the Qantas ransomware attack demonstrate the importance of strong security measures and reliable backups. At any moment, it could be your business on the line. And how prepared you are could mean the difference between a minor roadbump and a total catastrophe.
Worried that you might be next? Cybersecure is here to make sure your data backups can withstand any incident, from brief outages to the most devastating cyber-attacks. Our history of success proves that we know what we’re doing. Learn about our process if that sounds interesting to you.