Qantas Data Breach: Customer Info Leaked via Vendor
Show Links
Qantas has confirmed a cyber incident where customer data was exposed — not through their own systems, but via a third-party vendor. In this special episode, Leigh Kefford breaks down what really happened, why vendor risk is one of the biggest threats to your business today, and how you can take practical steps to stay protected.
You’ll learn:
What customer data was compromised in the Qantas incident
How third-party vendors can quietly expose your entire organisation
Why even trusted brands can fall victim
Key actions your business must take to manage supply chain cyber risk
Resources Mentioned:
Episode Transcript
Aussie icons aren’t immune to cybercrime — and Qantas, our national carrier, has just joined the long and growing list of high-profile data breach victims.
In a public statement, Qantas confirmed a cyber incident involving a third-party provider, with customer data including names, dates of birth, contact details, and frequent flyer numbers potentially exposed.
What actually happened? How serious is it? And what should you — as a business leader or consumer — take away from it?
In this special episode, we’ll break down the Qantas breach, the wider risks of third-party platforms, and the practical steps your business can take to reduce its risk of becoming the next headline.
Welcome to the Don’t Be A Sitting Duck Podcast, I’m Leigh Kefford — let’s dive in.
On June 30th, 2025, Qantas confirmed that cybercriminals gained access to customer data through a third-party provider used by one of their offshore contact centres.
The exposed information included:
Full names
Phone numbers
Email addresses
Dates of birth
Qantas Frequent Flyer numbers
Qantas says no payment details, passwords, or passport data were accessed — but the kind of data that was compromised can still be used for identity theft, phishing, and social engineering attacks.
Affected customers were notified, and a dedicated support hotline has been launched.
How It Happened & Why It Matters
This wasn’t a breach of Qantas’ core systems — the attackers targeted a third-party platform. And that’s what makes this case such a wake-up call.
Supply chain risk is now one of the biggest blind spots in cybersecurity. It’s not enough to secure your own systems — you also need to vet and monitor every vendor, tool, or partner that touches your data.
Here’s the danger: clients trust you, not your vendors. When a partner gets breached, it’s your reputation on the line.
Why it matters:
These types of breaches are hard to detect early.
Most businesses have little to no visibility into third-party data handling.
Threat actors are exploiting this — and businesses that don’t prepare will pay the price in reputational damage, customer churn, and regulatory scrutiny.
Qantas is a billion-dollar company with access to world-class security teams. If it can happen to them, it can happen to anyone.
Take Action – How to Protect Your Business
Here’s what you need to do right now:
Audit Your Vendors – Know who handles your data, where it’s stored, and how it’s protected. Build a vendor risk register.
Data Minimisation – Only collect and store the data you absolutely need. The less you hold, the less you expose.
Contracts & Due Diligence – Every third-party you work with should have a clear data protection policy, and you should hold them to it.
Incident Response Planning – If your vendor is breached, you still need a plan. Prep your comms, reporting obligations, and internal processes.
Cyber Insurance Readiness – Policies are now demanding proof that you assess third-party risk. Tools like Empower SHIELD and our Cyber Insurance Fast Track can help you stay compliant.



