Security

CSO

Qantas app glitch sees boarding passes fly to other accounts

Issue now resolved and isn't thought to be the work of criminals


Aussie airline Qantas says its app is now stable following a data breach that saw boarding passes take off from passengers' accounts.

Customers and local media reported on Wednesday seeing other customers' boarding passes, airline points, and personal information such as names being displayed in their Qantas mobile app.

Trevor Long, a tech journalist speaking to local broadcaster 9News Australia, said he was able to view as many as eight other people's details and boarding passes in his account.

Qantas said in a statement that there were two periods throughout the day in which "some customers" were being issued with wrong details, but the blunder isn't thought to be the result of a cybersecurity breach.

"Current investigations indicate that it was caused by a technology issue and may have been related to recent system changes," it said. "At this stage, there is no indication of a cybersecurity incident."

To further reassure users, it added that financial information wasn't among the data shared with other customers, and despite airline points being displayed, they weren't usable or transferable.

Qantas also said it received no reports of individuals trying to board flights using other flyers' passes, and even if they did, the airline has processes in place that would prevent the pass from being used fraudulently.

The airline issued an apology to customers, saying that it's continuing to monitor the app for any other glitches that arise.

"We sincerely apologize to customers impacted by the issue with the Qantas app this morning, which has now been resolved."

Qantas also urged customers to be on high alert for social media scams that could be spun up to capitalize on the incident.

It certainly wouldn't be the first time scammers have tried to use current events to their advantage. In 2019, following the fall of what was at the time the world's oldest travel agency, Thomas Cook, there was a huge spike in phishing sites being created to exploit former staff and customers.

Researchers said the lures were most commonly focused on those seeking advice about compensation claims. Targeting the vulnerable, essentially, as scammers often do.

A similar situation could feasibly unfold in the wake of the Qantas app debacle too, with customers fearing their data was stolen, for example.

Qantas app users have also been advised to reauthenticate into their frequent flyer account within the app. ®

Send us news
8 Comments

Check your IP cameras: There's a new Mirai botnet on the rise

Also, US offering $2.5M for Belarusian hacker, Backpage kingpins jailed, additional MOVEit victims, and more

US sues Georgia Tech over alleged cybersecurity failings as a Pentagon contractor

Rap sheet spells out major no-nos after disgruntled staff blow whistle

Plane tracker app FlightAware admits user data exposed for years

Privacy blunder alert omits number of key details

National Public Data tells officials 'only' 1.3M people affected by intrusion

Investigators previously said the number was much, much higher

RansomHub-linked EDR-killing malware spotted in the wild

Also: Your external-facing NetSuite sites need a review; five popular malware varieties for Q2, and more

Brain Cipher claims attack on Olympic venue, promises 300 GB data leak

French police reckon financial system targeted during Summer Games

Deadline looms: Google Workspace mandates OAuth by September 30

27 days to get your users' third-party apps on Google’s sign-in

RansomHub hits 210 victims in just 6 months

The ransomware gang recruits high-profile affiliates from LockBit and ALPHV

Tired of airport security queues? SQL inject yourself into the cockpit, claim researchers

Infosec hounds say they spotted vulnerability during routine travel in the US

Boom Supersonic takes baby steps toward breaking the sound barrier

Twitchy roll resolved, landing gear works on one-third size demonstrator

Enzo Biochem ordered to cough up $4.5 million over lousy security that led to ransomware disaster

Three state attorneys general probed the company and found plenty to chastise

Ransomware batters critical industries, but takedowns hint at relief

Whether attack slowdown continues downward trend is the million dollar question that security researchers can't answer