Qantas customer data leaked by hackers after ransomware attack
Scattered Lapsus$ Hunters started leaking files on the dark web

- Hackers reportedly leaked data of 5 million Qantas customers after failed extortion attempt
- Attackers exploited Salesloft-Salesforce integrations to access and steal customer data
- 44 companies were affected, including Disney, Toyota, McDonald’s, and Vietnam Airlines
Australia’s biggest airline, Qantas, is one of 44 companies whose sensitive customer data ended up on the dark web. Now, numerous cybercriminals have easy access to contact and flight information on millions of people, which they can use for phishing, identity theft, fraud, and other attacks.
Last summer, a group of hackers going by the name Scattered Lapsus$ Hunters broke into Salesforce accounts belonging to hundreds of organizations in different industries - although Salesforce itself was not breached.
The attackers compromised Salesloft accounts that were integrated with Salesforce and exploited the linked API tokens and OAuth connections to pivot into Salesforce environments and exfiltrate customer data.
"Don't be the next headline"
The group tried to extort Qantas for money, offering to delete the stolen files in exchange. The airline, however, refused to even discuss the matter with the attackers, telling Guardian Australia it “will not engage, negotiate with, or pay any extortion demand”.
In response, Scattered Lapsus$ Hunters released the stolen files on the dark web. The archive includes personal records of 5 million Qantas customers, including people’s names, email addresses, phone numbers, birth dates, and frequent flyer numbers. Credit card details, financial information, and passport details weren't stolen, it was said.
“Don’t be the next headline, should have paid the ransom,” the group posted on its data leak site.
But apparently, Qantas is not the only company whose data was leaked in this wave. Citing analysts at cybersecurity outfit Intel 471, the Guardian reported that 44 companies were included in the leak, and among them are Gap, Vietnam Airlines, Toyota, Disney, McDonald’s, Ikea, and Adidas.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
Scattered Lapsus$ Hunters is a group comprising members of Scattered Spider, Lapsus$, and ShinyHunters. Soon after the Salesloft/Salesforce breach, they announced “going dark”, which the cybersecurity community interpreted as fear of too much publicity. Obviously, it didn’t last long.
Via The Guardian
Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!
And of course you can also follow TechRadar on TikTok for news, reviews, unboxings in video form, and get regular updates from us on WhatsApp too.
You might also like
- Salesforce platforms are being cracked open for data theft - FBI warns of UNC6040 and UNC6395 IOCs
- Take a look at our guide to the best authenticator app
- We've rounded up the best password managers
Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.
You must confirm your public display name before commenting
Please logout and then login again, you will then be prompted to enter your display name.