TechForge

October 13, 2025

  • A Salesforce breach exposed data from 5.7 million Qantas customers.
  • The same attack hit global brands like Disney, Google, and Toyota.

Data from around 5.7 million Qantas customers has appeared online following a cyberattack earlier this year, adding the Australian airline to a growing list of companies affected by a breach linked to software provider Salesforce.

As reported by AFP, the leak is part of a wider incident that has also impacted major brands including Disney, Google, IKEA, Toyota, McDonald’s, and airlines Air France and KLM. Attackers are reportedly holding the stolen information for ransom.

Salesforce confirmed in early October that it was aware of ongoing extortion attempts by cybercriminals targeting its systems. Qantas said the hackers had accessed one of its third-party platforms—later identified as Salesforce—through a customer contact centre in July.

The intruders gained access to personal details including names, email addresses, phone numbers, and dates of birth. While most of the leaked data includes frequent flyer information and contact details, some records contain home or business addresses, gender, and meal preferences. The airline said no credit card, passport, or banking information had been compromised.

Qantas has since taken legal action to limit the spread of the data, securing an injunction from the Supreme Court of New South Wales to prevent the information from being published or shared. But cybersecurity experts say the order may have little effect beyond Australia’s borders.

“It’s frankly ridiculous, said Troy Hunt, a cybersecurity researcher. “It obviously doesn’t stop criminals anywhere, and it also really doesn’t have any effect on people outside of Australia.”

A growing list of victims

Google, one of the affected companies, said one of its Salesforce servers was targeted in the same campaign. The firm said it had analysed the breach and notified potentially affected partners. “Google responded to the activity, performed an impact analysis and has completed email notifications to the potentially affected businesses, said Melanie Lombardi, who leads Google Cloud’s security communications.

Cybersecurity researchers have traced the breach to Scattered Lapsus$ Hunters, a group of hackers reportedly working together to steal corporate data and demand payment. Research team Unit 42 described the campaign as a “coordinated effort to steal data and hold it for ransom, adding that the attackers had given victims until October 10 to meet their demands.

Using social tricks, not advanced code

Investigators believe the hackers relied on social engineering, a manipulation technique that involves tricking people into giving up access or information. In this case, they are said to have posed as IT staff or trusted company representatives to persuade support employees to share credentials or grant system access.

The FBI recently warned that similar scams are being used against Salesforce clients, noting that attackers often appear convincing enough to bypass standard checks.

“They have been very effective, Hunt said. “And it hasn’t been using any sophisticated technical exploits… they have exploited really the oldest tricks in the books.”

Part of a broader cybersecurity concern

The Qantas breach adds to a series of major cyber incidents in Australia that have raised questions about the country’s data protection practices.

Last year, the airline apologised after a technical glitch in its mobile app exposed some passengers’ names and flight details. In another high-profile case, hackers crippled operations at DP World, a port operator that manages roughly 40 per cent of Australia’s freight trade, forcing terminals across the country to shut down temporarily.

The latest breach underscores how data shared across global software platforms can expose multiple companies at once. While Qantas said no further intrusions have occurred since July and that it continues to cooperate with Australian authorities, the scale of this attack shows how difficult it is for even large organisations to stay ahead of cybercriminals.

 

 

 

Want to learn more about Cloud Computing from industry leaders? Check out Cyber Security & Cloud Expo taking place in Amsterdam, California, and London. The comprehensive event is part of TechEx and is co-located with other leading technology events, click here for more information.

CloudTech News is powered by TechForge Media. Explore other upcoming enterprise technology events and webinars here.

About the Author

Muhammad Zulhusni

As a tech journalist, Zul focuses on topics including cloud computing, cybersecurity, and disruptive technology in the enterprise industry. He has expertise in moderating webinars and presenting content on video, in addition to having a background in networking technology.

Related

September 15, 2026

September 15, 2026

September 14, 2026

September 11, 2026

Join our Community

Subscribe now to get all our premium content and latest tech news delivered straight to your inbox

Popular

35546 view(s)
18239 view(s)
18003 view(s)
17445 view(s)

Subscribe

All our premium content and latest tech news delivered straight to your inbox

This field is for validation purposes and should be left unchanged.