Yet another breach in our digital world.
QANTAS DATA LEAKED
Cybercriminals have published 153GB of alleged Qantas customer data after the airline refused to co-operate with hacker ransom demands.
After exploiting a third-party call centre and gaining access to Qantas’ data in June, hackers last week threatened to release it to the dark web unless a ransom was paid.
With a deadline of 10 October, hackers dumped an apparent five million customer records to both the dark web and the open internet.
“Qantas is one of a number of companies globally that has had data released by cybercriminals following the airline’s cyber incident in early July, where customer data was stolen via a third-party platform,” said Qantas.
Qantas told customers the impacted data included customer names, email addresses, phone numbers, birth dates, and Qantas Frequent Flyer numbers.
They also say that no credit card details, passports, personal financial information or login credentials were compromised.
Troy Hunt, Chief Executive of breach tracking platform Have I Been Pwned, told reporters he had confirmed with a trusted third-party that the data was legitimate.
The data was first leaked to a clear-web hacking forum at approximately 2.30pm AEDT Saturday, where users could purchase access to it for approximately $27.
About an hour later, the download was made available for free on the dark web.

We have not downloaded or viewed the stolen information – doing so would violate an interim injunction which Qantas obtained through the New South Wales Supreme Court – though Hunt says his source was able to locate his details as an example of the data.
“They were able to relay my date of birth, my phone number… other things related to Qantas,” said Hunt.
“My kids are in there, and my wife is in there.”
Qantas said it will “continue to share updates” through its website and provide “ongoing access to specialist identity protection services” through its 24/7 support line.
“With the help of specialist cybersecurity experts, we are investigating what data was part of the release,” said Qantas.
Here we are yet again with another breach of sensitive personal information, in an era where this type of news story is becoming increasingly commonplace.
As we continue to hand over data to giant corporations, they continue to drop the ball when it comes to protection – proving that we need better solutions to this digital world.
BREACH SEASON
There have been endless news stories of breaches and hacks in recent years, most notably with Optus in 2022 and Latitude Financial in 2023.
In 2022 alone, a total of 890 data breaches were reported to OAIC across 2022, in an unprecedented year that saw millions of Australians impacted by cybercrime.
Hundreds of data breaches reported to commissioner in 2022
RELATED ARTICLE
Just last month, it was revealed that Queensland’s most vulnerable children could be at risk of harm or even death following a major IT blunder at the Department of Child Safety, where incidents reports and information of thousands ‘have gone missing’.
Child safety information missing in QLD after system ‘IT bungle’
RELATED ARTICLE
From licenses, to health records, nothing is safe in a world of digital hacking and fraud.
Data breach exposes tens of thousands of licences
RELATED ARTICLE
My Health Record data breached 77 times in 24 months
RELATED ARTICLE
Meanwhile, even data that is ‘secured’ is not completely kept privately.
Australian authorities love asking Big Tech for user data. They love it so much that our access statistics are more than four times the international average, actually.
This is according to a recent report on data surveillance from VPN provider, Surfshark,
Australian authorities love asking Big Tech for user data
RELATED ARTICLE
Whether it is by bad actor hackers, or by governments and police services, your personal data is being watched, analysed, traded and used for nefarious means.
Legal and illegal.
Despite this, organisations are pushing full steam ahead with digital-only systems, many of them hosted by third-party companies not inside of Australia.
Commonwealth Bank moves entire core system to Amazon Cloud service
RELATED ARTICLE
With social media verification laws set to come into effect in a matter of months, and the eventual implementation of the myID Digital ID platform across almost every vital service, not only does it spell trouble for what the world will become in terms of mass surveillance and tracking – but also if the data being analysed is even safe.
Now is a good time to start de-tangling your data from the internet if you haven’t already.

KEEP UP-TO-DATE
For more TOTT News:
Facebook — Facebook.com/TOTTNews
YouTube — YouTube.com/TOTTNews
Instagram — Instagram.com/TOTTNews
Twitter — Twitter.com/EthanTOTT
Bitchute — Bitchute.com/TOTTNews
Gab — Gab.com/TOTTNews


Couldn’t give a flying F@$%, thanks to the morons who are wrecking the joint. They can all go to hell. People need to stop flying and the shit show is over. And I doubt it was international hackers. All this crap is an inside job.
Whatever happens on the internet these days. “they” will use it as another pretext/”justification” to impose digital IDs.
Is this a second time now. Julia