Data leak

Qantas Salesforce Breach via ShinyHunters Vishing - 5.7M Customers

πŸ“… 2025-07-01 🏒 Salesforce CRM; Salesforce Data Loader (malicious OAuth app abuse)
Primary Source β†—

Incident Details

In July 2025, Qantas Airways (Australia’s flag carrier) suffered a Salesforce data breach attributed to ShinyHunters/Scattered Lapsus$ Hunters via a vishing campaign. Approximately 5.7 million customer records were exfiltrated. Exposed data included customer names, email addresses, phone numbers, frequent flyer program details, and for a subset: home/business addresses, dates of birth, gender preferences, and meal selections. Credit card details, financial information, and passport data were not compromised. This attack is part of a broader ShinyHunters Salesforce vishing campaign that started around June 2025 and affected at least 91 organizations worldwide, including Allianz Life, LVMH, Adidas, Cartier, Air France-KLM, Cisco, and others (see 2025-07_allianz-life-shiny-hunters.yaml).

Technical Details

Initial Attack Vector
ShinyHunters (Scattered Lapsus$ Hunters) used vishing (voice phishing) to impersonate IT support staff, tricking employees into visiting Salesforce's connected app setup page and entering a 'connection code' that linked a malicious OAuth app (malicious Salesforce Data Loader) to the employee's Salesforce environment
Vendor / Product
Salesforce CRM; Salesforce Data Loader (malicious OAuth app abuse)

Timeline

  1. 2025-07-01 Breach occurred
  2. 2025-08-01 Publicly disclosed
  3. 2025-08-01 Customers notified