Security

CSO

Qantas app glitch sees boarding passes fly to other accounts

Issue now resolved and isn't thought to be the work of criminals


Aussie airline Qantas says its app is now stable following a data breach that saw boarding passes take off from passengers' accounts.

Customers and local media reported on Wednesday seeing other customers' boarding passes, airline points, and personal information such as names being displayed in their Qantas mobile app.

Trevor Long, a tech journalist speaking to local broadcaster 9News Australia, said he was able to view as many as eight other people's details and boarding passes in his account.

Qantas said in a statement that there were two periods throughout the day in which "some customers" were being issued with wrong details, but the blunder isn't thought to be the result of a cybersecurity breach.

"Current investigations indicate that it was caused by a technology issue and may have been related to recent system changes," it said. "At this stage, there is no indication of a cybersecurity incident."

To further reassure users, it added that financial information wasn't among the data shared with other customers, and despite airline points being displayed, they weren't usable or transferable.

Qantas also said it received no reports of individuals trying to board flights using other flyers' passes, and even if they did, the airline has processes in place that would prevent the pass from being used fraudulently.

The airline issued an apology to customers, saying that it's continuing to monitor the app for any other glitches that arise.

"We sincerely apologize to customers impacted by the issue with the Qantas app this morning, which has now been resolved."

Qantas also urged customers to be on high alert for social media scams that could be spun up to capitalize on the incident.

It certainly wouldn't be the first time scammers have tried to use current events to their advantage. In 2019, following the fall of what was at the time the world's oldest travel agency, Thomas Cook, there was a huge spike in phishing sites being created to exploit former staff and customers.

Researchers said the lures were most commonly focused on those seeking advice about compensation claims. Targeting the vulnerable, essentially, as scammers often do.

A similar situation could feasibly unfold in the wake of the Qantas app debacle too, with customers fearing their data was stolen, for example.

Qantas app users have also been advised to reauthenticate into their frequent flyer account within the app. ®

Send us news
8 Comments

Affirm fears customer info pilfered during ransomware raid at Evolve Bank

Number of partners acknowledging data theft continues to rise

Not-so-OpenAI allegedly never bothered to report 2023 data breach

Also: F1 authority breached; Prudential victim count skyrockets; a new ransomware actor appears; and more

Call, text logs for 110M AT&T customers stolen from compromised cloud storage

Snowflake? Snowflake

Snowflake lets admins make MFA mandatory across all user accounts

Company announces intent following Ticketmaster, Santander break-ins

Malware that is 'not ransomware' wormed its way through Fujitsu Japan's systems

Company says data exfiltration was extremely difficult to detect

Indonesian government didn't have backups of ransomwared data, because DR was only an option

President has ordered a datacenter audit and made backups mandatory

Microsoft tells yet more customers their emails have been stolen

Plus: US auto dealers still offline; Conti coders sanction; Rabbit R1 hardcoded API keys; and more

Evolve Bank & Trust confirms LockBit stole 7.6 million people's data

Making cyberattack among the largest ever recorded in finance industry

Cancer patient forced to make terrible decision after Qilin attack on London hospitals

Skin-sparing mastectomy and breast reconstruction scrapped as result of ransomware at supplier

Microsoft blamed for million-plus patient record theft at US hospital giant

Probe: Worker at speech-recog outfit Nuance wasn't locked out after firing

Europol nukes nearly 600 IP addresses in Cobalt Strike crackdown

Private sector helped out with week-long operation – but didn't touch China

Levi's and more affected in pants-dropping week of data breaches

A busy few days for security teams