The Australian federal government has reaffirmed its strict policy: it will not negotiate with cybercriminals or pay ransoms, following a major data breach involving Qantas and the public release of stolen customer information.
The hacking group behind the breach leaked millions of Qantas customer records to the dark web after its ransom deadline passed.
What happened: Qantas data exposed, hackers issue threat
- In July 2025, Qantas was one of 40 global firms targeted in a cyberattack linked to Salesforce, a cloud services provider.
- The hackers — identifying as Scattered Lapsus$ Hunters — demanded ransom from Salesforce, threatening to publish Qantas customer data if demands were not met.
- After the ransom deadline passed without compliance, the hackers published the data on the dark web.
- The exposed information includes names, email addresses, frequent flyer data, and in some cases addresses, phone numbers, dates of birth, and gender. Qantas maintains that no credit card, passport, or login credentials were compromised.
Government stands firm: no ransom, no backing down
The Attorney-General and other senior officials have reiterated that Australia’s policy is non-negotiation. No part of government supports paying ransoms as a response to illicit hacking demands.
Transport Minister Catherine King, who was among those whose data was affected, urged Australians to tighten security measures: change passwords, enable two-factor authentication, and be wary of phishing attempts.
The government also noted its commitment to bolstering data protection laws, increasing penalties for data breaches, and enhancing the Office of the Australian Information Commissioner’s enforcement powers.
Risks, reactions and potential fallout
Rising cyber threats & copycats
By refusing to pay ransoms, the government aims to deter future attacks. But experts warn this stance might push hackers to increase pressure tactics, leak data piecemeal, or target more vulnerable organisations.
Consumer vulnerability
With personal data already released, affected individuals face heightened risks: phishing, identity fraud, and social engineering. The onus is on firms and individuals to remain vigilant.
Legal and corporate accountability
Qantas could face regulatory action or fines under Australia’s data breach regime. The incident may also trigger scrutiny of how companies manage third-party cloud vendors and enforce cyber resilience.
Diplomatic & strategic implications
The breach underscores global vulnerability in tech supply chains and cloud infrastructure. It may prompt more aggressive cooperation among nations on cybercrime, extradition, and digital law enforcement.


