A major class action complaint has been filed on behalf of millions of Qantas customers whose personal data was compromised in a cyberattack. The complaint, lodged by law firm Maurice Blackburn, accuses the airline of failing to adequately protect customer information.
According to the firm, a cybercriminal accessed a third-party customer service platform at a Qantas call centre in Manila, affecting nearly 5.7 million individuals. The breach, which took place on June 30, exposed sensitive customer details, including names, email addresses, and frequent flyer data.
Elizabeth O’Shea, principal lawyer at Maurice Blackburn, confirmed the firm has filed an official complaint. The complaint was submitted to the Office of the Australian Information Commissioner (OAIC). This office is responsible for enforcing the country’s privacy laws.
“We’ve asked the OAIC to investigate whether Qantas took reasonable steps to safeguard personal data,” O’Shea said. “While we wait for the Commissioner’s response, we’re encouraging affected customers to register with us. There may be compensation available depending on how the matter unfolds.”
Registration with the firm is free and non-binding. O’Shea added that anyone whose information was exposed is eligible to stay updated through the firm’s website.
Meanwhile, Qantas secured an interim court order from the NSW Supreme Court. This order aims to stop the release or sharing of the stolen data. The airline stated this was a necessary step to protect customer privacy.
“As of now, there is no indication that the stolen data has been published,” Qantas said in a statement. “We are working closely with cybersecurity experts and continuing to monitor the situation.
Qantas had earlier revealed that 5.7 million customers were affected by the data breach. Out of these, about four million had their names accessed. Their email addresses and loyalty program details were also exposed.


