Qantas Airways is investigating a major cyberattack that may be linked to the Scattered Spider hacking group, the same criminal network that previously targeted UK retailer Marks and Spencer, according to a report by the Financial Times.
The Australian flag carrier said on Wednesday that hackers breached a third-party customer service platform used by one of its call centres, potentially compromising the personal data of up to six million customers. The exposed information includes names, email addresses, phone numbers, dates of birth, and frequent flyer details.
Qantas clarified that no financial data—such as credit card numbers—was compromised, as such information is stored on separate, secure servers.
The attack came just days after the FBI issued a warning that Scattered Spider had begun targeting the global airline sector. The agency described the group as highly sophisticated, known for using social engineering tactics such as impersonating employees to gain access to corporate systems. Recent victims of the group reportedly include Hawaiian Airlines, Canada’s WestJet, and MGM Casinos.
“They target large corporations and their third-party IT providers, which means anyone in the airline ecosystem, including trusted vendors and contractors, could be at risk,” the FBI said in its alert last week. The agency added that the group often engages in extortion after stealing sensitive data.
Qantas, Australia’s largest airline, said it acted swiftly to secure its systems and has notified the Australian Federal Police and other government agencies. The airline will also begin contacting affected customers directly.
Chief Executive Vanessa Hudson issued a formal apology, stating, “We sincerely apologise to our customers and we recognise the uncertainty this will cause. Our customers trust us with their personal information and we take that responsibility seriously.”
Shares in Qantas fell 3.6% following the announcement of the breach.
The airline now joins a growing list of major Australian companies targeted by cybercriminals in recent years, including telecommunications giant Optus, healthcare provider Medibank Private, several pension funds, and port operator DP World.
The Financial Times was among the first to report on the possible connection between the Qantas breach and the Scattered Spider group.

