Qantas Data Breach Fallout Escalates as Jordan Detains Suspected Hacker Linked to ShinyHunters

Qantas Data Breach Fallout Escalates as Jordan Detains Suspected Hacker Linked to ShinyHunters

Ankita Neogi Khan Written by Ankita Neogi Khan

Updated

Published

10 mins to read
Qantas aircraft and traveller facing an international airline cybersecurity investigation
Image Credit Qantas Airlines

A reported detention in Jordan has widened the international investigation into the Qantas data breach, after authorities detained suspected ShinyHunters member Saif al-Din Khader. The hacker, reportedly known online as “Rey”, is said to be cooperating with the FBI and international investigators. The development could help investigators identify other members of the hacking network. Qantas confirmed that about 5.7 million customer records were compromised in the 2025 incident. Australia’s privacy regulator later put the figure at approximately 5.67 million records. The exposed information included contact details and frequent-flyer data. Some records also contained addresses, dates of birth, telephone numbers and meal preferences.

Jordan Detention Opens a New Investigative Front

Jordanian authorities reportedly detained Khader last week as the FBI continues a widening international investigation. Reuters reported that Khader is helping investigators examine digital devices and communications linked to the wider network. However, the FBI has not publicly confirmed his specific detention.

The reported cooperation could prove significant because ShinyHunters operates through a wider network of loosely connected actors. Investigators are now seeking information about communications, infrastructure and other suspected participants. The development follows the arrest of a 24-year-old Amsterdam man suspected of links to ShinyHunters.

The FBI has confirmed that international partners have already arrested multiple suspects. It also said investigators would continue pursuing those responsible for recent cyber incidents.

Advertisement

Advertisement

The latest development does not establish that Khader personally attacked Qantas. That distinction remains important because investigators have not publicly alleged his direct involvement in the airline incident.

Instead, the significance lies in the possibility that investigators could gain intelligence about the broader hacking ecosystem. Such information could assist authorities investigating attacks against airlines, technology companies and other major organisations.

Advertisement

Advertisement

What Happened Inside the Qantas Contact Centre

The original incident began on 28 June 2025 at an overseas contact centre operated by a third-party provider. According to Australia’s Office of the Australian Information Commissioner, a caller impersonated Qantas IT support.

The caller persuaded an employee to follow instructions involving the customer relationship management platform. The employee already had legitimate access to customer profiles as part of their role.

The attacker then connected the employee’s session to a malicious data-extraction tool. That enabled the unauthorised extraction of information from customer profiles available through the platform.

Qantas detected unusual activity on 30 June 2025. The airline subsequently froze the affected account, revoked access and investigated potential data exfiltration.

The airline notified the Australian privacy regulator on 2 July 2025. It later contacted affected customers with information about the categories of data involved.

The incident therefore illustrates a significant cybersecurity weakness. A legitimate employee account became the gateway to a major data theft operation.

Advertisement

Advertisement

The breach did not involve an intrusion into aircraft systems or flight-control infrastructure. Qantas also stated that its operational systems remained secure.

Key DevelopmentVerified Detail
Initial compromise28 June 2025
Qantas detected unusual activity30 June 2025
Public disclosure2 July 2025
Approximate records compromised5.67 million
Australian records affectedApproximately 5.12 million
Main information exposedNames, emails, phone numbers and frequent-flyer information
Additional information in some recordsAddresses, dates of birth, gender and meal preferences
Passport informationNot stored on the affected platform
Credit-card informationNot stored on the affected platform
Frequent-flyer passwords and PINsNot compromised

Which Traveller Details Were Exposed

The nature of the stolen information matters more to travellers than the headline figure alone. A database containing millions of records does not mean every customer lost the same information.

Australia’s privacy regulator found that approximately 4 million records contained names, phone numbers, email addresses and Qantas Frequent Flyer information. That information could include membership numbers, status levels, points balances and status credits.

Approximately 1.7 million additional records contained combinations of those details and other information. These fields included addresses, dates of birth, gender and meal preferences.

For travellers, the combination can be more revealing than any individual field. Frequent-flyer status can identify a customer’s relationship with an airline. Addresses and birth dates can also strengthen attempts at impersonation.

However, there is an important safeguard. Qantas said passwords, PINs and login credentials were not accessed through the compromised system.

Advertisement

Advertisement

The affected platform also did not store passport numbers or credit-card information. Therefore, those highly sensitive travel and payment credentials were not part of the compromised database.

Information CategoryExposure StatusTraveller Relevance
NameExposed for many customersCan support targeted impersonation
Email addressExposed for many customersPotential phishing target
Phone numberExposed for many customersPotential scam calls and messages
Frequent-flyer numberExposed for many customersCan identify airline relationship
Points and status creditsExposed in some recordsCould support convincing scam attempts
AddressExposed in some recordsSensitive identity information
Date of birthExposed in some recordsUseful in identity-based scams
Meal preferenceExposed in some recordsPersonal customer information
Passport detailsNot stored on platformNot compromised through this incident
Credit-card detailsNot stored on platformNot compromised through this incident
Passwords and PINsNot compromisedFrequent-flyer accounts were not directly breached

Why Frequent Flyers Face a New Scam Risk

The most immediate traveller concern is not necessarily another technical attack. It is social engineering after the breach.

Qantas warned customers about scammers impersonating the airline after the incident. Fraudsters can exploit public knowledge of a breach to make fake emails, calls and text messages appear credible.

A traveller may receive a message claiming that their frequent-flyer account requires verification. Another scam could falsely offer compensation or request confirmation of a booking.

The danger increases when a criminal already knows the customer’s name, email address or frequent-flyer number. The message can then appear far more convincing than generic spam.

Travellers should therefore avoid responding to unsolicited requests for passwords, verification codes or payment information. They should independently open the airline’s official website or application instead.

Advertisement

Advertisement

Qantas has specifically warned that it will not request passwords or sensitive login information through unsolicited communications.

Australia’s Privacy Rules Add Regulatory Pressure

The incident also sits within Australia’s Notifiable Data Breaches scheme, which has operated since February 2018.

Under the scheme, organisations covered by Australian privacy law must notify affected individuals and the privacy regulator when a breach is likely to cause serious harm. The system covers unauthorised access, disclosure and certain losses of personal information.

The Qantas investigation provides an important example of how regulators assess a major aviation-sector cyber incident. The OAIC conducted preliminary inquiries between July 2025 and June 2026.

In July 2026, the regulator concluded those preliminary inquiries without commencing a Commissioner-Initiated Investigation. It found that the information gathered did not reveal omissions or failings in Qantas’ steps to protect personal information or oversee its third-party contact-centre provider.

That finding does not erase the impact on affected travellers. Instead, it distinguishes between the harm suffered by customers and the regulator’s assessment of whether Qantas breached applicable privacy obligations.

Advertisement

Advertisement

The distinction is important for travel businesses using outsourced customer-service operations. Third-party platforms can become part of an airline’s effective cybersecurity perimeter.

Data Breaches Are Rising Across Australia

The Qantas incident arrived during a period of elevated cyber risk across Australia.

The OAIC recorded 1,205 data breach notifications in 2025, the highest annual number since mandatory reporting began. The total was 8% higher than the 1,112 notifications recorded during 2024.

Malicious or criminal attacks accounted for 716 notifications during 2025. That represented the largest category of reported breaches.

The regulator also found that data breaches remained a major privacy concern among Australians. Its 2026 community survey found that 82% of respondents viewed data breaches as a privacy risk.

Australian Data-Breach Indicator20242025
Notifications to OAIC1,1121,205
Annual change—+8%
Malicious or criminal attacks—716
Public concern over data breaches74% in 202382% in 2026

For airlines, these numbers underline a wider industry problem. Cybersecurity now affects the traveller journey far beyond airport check-in and online booking.

Advertisement

Advertisement

Airlines handle loyalty information, contact details, booking histories and identity-related information. That makes customer databases attractive targets even when aviation operations remain untouched.

What Travellers Should Do After the Incident

Affected Qantas customers should first establish whether they received an official notification from the airline. They should avoid relying on unsolicited emails, telephone calls or text messages claiming to explain the breach.

Travellers should also strengthen the security of email and other important online accounts. Multi-factor authentication can provide an additional barrier if a password becomes compromised elsewhere.

A password should be unique and difficult to predict. Travellers should also avoid entering sensitive information through public Wi-Fi networks or unfamiliar websites while overseas.

Cybersecurity agencies recommend limiting personal information shared publicly during travel. Flight numbers, hotel details and live locations can provide useful information to criminals.

The same principle applies to loyalty programmes. Frequent-flyer accounts contain commercially valuable information and can reveal travel patterns, status and accumulated rewards.

Advertisement

Advertisement

Traveller ActionWhy It Matters
Check official Qantas communicationsReduces exposure to impersonation scams
Avoid unsolicited linksHelps prevent phishing attacks
Never disclose passwords or verification codesProtects online accounts
Activate multi-factor authenticationAdds another security layer
Use official airline applicationsReduces fake-site risks
Avoid sensitive activity on public Wi-FiLimits exposure to network attacks
Monitor unusual account activityHelps identify possible compromise
Be cautious with phone calls claiming to be QantasCounters social-engineering attempts

The Wider Lesson for Travel Companies

The incident carries a broader lesson for airlines, airports and tourism companies. Cybersecurity cannot stop at the boundary of an organisation’s own technology.

Contact centres, reservation platforms, loyalty systems and external technology suppliers can all handle valuable traveller information. Each connection creates another potential route into sensitive customer data.

The Qantas case also demonstrates why employee awareness remains critical. The attacker reportedly relied on impersonation rather than defeating an advanced technical barrier.

That approach can be remarkably effective because employees often operate under pressure. A convincing caller who claims to be solving an IT problem can exploit routine workplace behaviour.

For travel companies, regular staff training should therefore complement technical safeguards. Vendor oversight, access controls, authentication and monitoring also need continuous attention.

International Investigation Could Gather Momentum

The reported Jordan detention comes as investigators intensify pressure on ShinyHunters and related actors.

Advertisement

Advertisement

The FBI has publicly linked the group to attacks across several countries. The bureau has also confirmed an arrest carried out with Dutch authorities involving an alleged ShinyHunters leader.

Investigators are now examining a network associated with attacks against major organisations. The reported cooperation of Khader could provide additional intelligence if investigators can lawfully access his devices and communications.

Still, authorities have not publicly connected him to the Qantas attack itself. That distinction should remain central as the investigation develops.

For travellers, the immediate concern is simpler. Personal information taken during a breach can remain useful to criminals long after an incident disappears from the headlines.

Traveller Privacy Remains a Long-Term Concern

The reported detention in Jordan adds another international dimension to an investigation that began with a social-engineering attack against an overseas contact-centre employee. Yet the central lesson for travellers remains the same: personal data can become a security risk long after a journey ends.

Qantas customers whose information was affected should remain cautious about convincing impersonation attempts. They should also use official airline channels when checking accounts, bookings or support information.

Advertisement

Advertisement

The regulator’s findings provide some reassurance about payment and passport information. However, names, contact details and loyalty information can still support targeted fraud.

For the travel industry, the episode reinforces a larger shift. Cybersecurity is now an essential component of passenger trust, alongside operational safety, punctuality and service quality.

As international investigators pursue additional suspects, travellers will continue to watch for one practical outcome. They need confidence that the information shared during their journeys remains protected.

Advertisement

Share On:
Share on: X in w
Download the TTW app