Thousands of Qantas customers are voicing anger and alarm after learning their personal details were exposed online following a major data breach. While Qantas has obtained legal protections, critics say the airline’s response has been slow and inadequate.
What was leaked — and how it happened
- Hackers released the personal data of 5.7 million Qantas customers, including names, addresses, dates of birth, phone numbers, and frequent flyer numbers.
- The breach stemmed from social engineering tactics used on a Qantas call centre worker in the Philippines, targeting a third-party service platform (Salesforce).
- Although Qantas secured a court injunction in July to prevent access or publication of stolen data, the hackers still pushed the records onto the dark web after a ransom deadline lapsed.
Customer complaints: “Lack of communication” and “self-cleanup required”
Many affected customers say they’ve heard about the breach only from media reports, not directly from Qantas.
“I still haven’t had any communication directly from Qantas … that’s really frustrating,” said one affected customer, Ebe Ganon.
“My only option is to pay for identity monitoring myself — costly and anxiety-provoking.”
Critics have accused Qantas of placing the burden of remediation on individuals — rather than taking decisive, transparent action.
Legal uncertainty and possible penalties
Experts suggest Qantas might face significant fines under the Privacy Act if it’s found to have breached obligations to protect customer data.
Lawyers note key questions hinge on whether Qantas “held” the data or whether the responsibility lies partly with third parties like Salesforce.
The Office of the Australian Information Commissioner has so far declined to comment on potential penalties.
What to watch next
- Regulatory action — whether the Privacy Commissioner opens an investigation or issues fines
- Class action suits — whether groups of customers pursue damages
- Qantas remediation — how fast and transparently the airline improves security, communicates updates, and supports victims
- Further data dumps — whether more stolen data surfaces beyond the initial leak
- Cybersecurity reforms — whether this incident triggers stricter rules or oversight over third-party platforms


