Australia's Qantas says 6 million customer accounts accessed in cyber hack

Australia's Qantas says 6 million customer accounts accessed in cyber hack

A cyber hacker broke into a database containing the personal information of millions of customers, Qantas said, in Australia's biggest breach in years and a setback for an airline rebuilding trust after a reputational crisis, according to Reuters.

The hacker targeted a call centre and gained access to a third-party customer service platform containing six million names, email addresses, phone numbers, birth dates and frequent flyer numbers, Qantas said in a statement on Wednesday.

The airline did not specify the location of the call centre or customers whose information was compromised. It said it learnt of the breach after detecting unusual activity on the platform and acted immediately to contain it.

"We are continuing to investigate the proportion of the data that has been stolen, though we expect it will be significant," Qantas said, reporting no impact on operations or safety.

Last week, the U.S. Federal Bureau of Investigation said cybercrime group Scattered Spider was targeting airlines and that Hawaiian Airlines (HAII.UL) and Canada's WestJet had already reported breaches. Qantas did not name any group.

"What makes this trend particularly alarming is its scale and coordination, with fresh reports that Qantas is the latest victim" of a hack, said Mark Thomas, Australia director of security services for cyber security firm Arctic Wolf.

Scattered Spider hackers are known to impersonate a company's tech staff to gain employee passwords and "it is plausible they are executing a similar playbook", Thomas said.

Charles Carmakal, chief technology officer of Alphabet-owned cybersecurity firm Mandiant, said it was too soon to say if Scattered Spider was responsible but "global airline organisations should be on high alert of social engineering attacks".

Qantas' share price was down 2.4% in afternoon trading against an overall market that was up 0.8%.

Source: azertag.az