QANTAS AIRWAYS LIMITED
bd_14ad3dd35e3ec7be · schema v1 · pii pii-v1
Full breach record for QANTAS AIRWAYS LIMITED →Press / market disclosure — not a breach-notification filing
A media or market posting that confirms an incident but carries no breach-notification fields, so compliance clocks aren't assessable. The summary below is extracted from the coverage — verify against the source.
QANTAS CYBER INCIDENT. Qantas: Qantas has confirmed it suffered a cyberattack targeting a contact center, potentially exposing the personal data of several million customers. Although the compromised system was quickly isolated and Qantas' core systems remain secure, information such as names, emails, phone numbers, dates of birth, and loyalty numbers may have been accessed. The company is collaborating with Australian authorities, strengthening its security, informing affected customers, and issuing an apology. Linked ransomware group: shinyhunters.
J jump to incidentP pin to compareR raw source
Incident timeline — mostly unverified
? — ?
Breach window unknown
Jun 30, 2025
Press report
—
Corroborated · see linked filings
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Attack → press
—
Compliance clock
Not assessable
Linked disclosures
Why this link?Ransomware claims (1)
- Leak Siteshinyhuntersbd_9ad83e44a20a5d7c2025-06-28 · +2dCandidate
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.
Source ceiling
- incident type + narrative only (may be machine-translated)
- discovery date
- materiality
- affected count
- data types
- compliance clock
The ✕ fields stay blank until a regulatory filing or victim disclosure lands.
shinyhunters
According to ransomware.live, ShinyHunters is a financially motivated data-theft and extortion group active since 2020, responsible for high-profile breaches including Ticketmaster (via Snowflake) and PowerSchool; by 2025 they launched a RaaS offering called "shinysp1d3r," and in August 2025 French authorities arrested four members.