Qantas passengers’ personal details exposed as airline app logs users into wrong account

Airline investigating whether privacy breach allowing customers to view others’ account details was caused by ‘recent system changes’

Potentially thousands of Qantas customers have had their personal details made public via the airline’s app, with some frequent flyers able to view strangers’ account details and possibly make changes to other users’ bookings.

Qantas said late Wednesday its app had been fixed and was stable, after two separate periods that day “where some customers were shown the flight and booking details of other frequent flyers”.

The airline said this didn’t include displaying financial information, and that users were not able to transfer Qantas points from another account or board flights with their in-app boarding passes.

Clare Gemmell from Sydney said that she and four colleagues encountered the problem shortly after 8.30 on Wednesday morning.

“My colleague logged in and said ‘I think the Qantas app has been hacked because it’s not my account when I log in’.”

When Gemmell logged into the app, she was greeted with a message saying “Hi Ben”. The app told her Ben had more than 250,000 points and an upcoming international flight.

“Another colleague of mine said it looked like she was able to cancel somebody’s flight ticket,” she said.

“You could see boarding passes for other people, one of my colleagues could see a flight going to Melbourne and it looked like you could interact and actually affect the booking.”

The app has more than 115,000 ratings and reviews in the Apple store, where it has a star rating of 4.8.

Gemmell, who works in customer data technology, said the security lapse was “pretty shocking”.

“It’s a privacy breach and other people having access to my information and being able to cancel flights on my behalf is terrible customer service and very concerning,” she said.

“It’s basic 101 security that they should have tested any app changes before they released it into production,” she said, referring to the moment when the app went live.

She said she hadn’t been aware of an update to the app but that she since understood the app may have been updated overnight.

By shortly after 8.50am on Wednesday, the app appeared to have reverted to normal, she said.

Qantas launched an investigation into the breach and said in a statement that there was no indication of a cyber security incident.

The spokesperson said customers would not have been able to transfer or use the Qantas Points of other frequent flyers and was not aware of any customers travelling with incorrect boarding passes.

“We sincerely apologise to customers impacted by the issue with the Qantas app this morning, which has now been resolved,” they said.

“Current investigations indicate that it was caused by a technology issue and may have been related to recent system changes.

“At this stage, there is no indication of a cyber security incident.

“The issue was isolated to the Qantas app with some frequent flyers able to see the travel information of other customers, including name, upcoming flight details, points balance and status. No further personal or financial information was shared and customers would not have been able to transfer or use the Qantas Points of other frequent flyers. We’re not aware of any customers travelling with incorrect boarding passes.”

Contributor

Daisy Dumas

The GuardianTramp

Related Content

Article image
Top public servants told to declare airline lounge memberships amid Qantas controversy
Australian Public Service Commission updates guidelines for agency heads as questions swirl over influence of invitation-only Chairman’s Lounge

Elias Visontay and Sarah Basford Canales

23, Oct, 2023 @5:14 AM

Article image
Qantas worst airline operating across Pacific for CO2 emissions, analysis reveals
For each kilometre Qantas transports a passenger across Pacific, it uses 64% more fuel than two most fuel-efficient airlines

Michael Slezak

16, Jan, 2018 @5:00 PM

Article image
Passengers escorted off Qantas flight by police after Sydney airport security breach
All passengers were escorted out of the screened area of Melbourne airport because one passenger had bypassed screening in Sydney

Natasha May

07, Sep, 2022 @11:47 PM

Article image
Qantas staff consider class action alleging airline failed to protect them against Covid-19
Move comes after more than 59 employees become infected and amid dissatisfaction with how company handled risks

Anne Davies

12, Apr, 2020 @8:00 PM

Article image
‘Qantas needs to invest’: airline faces uphill battle to fix damage to reputation, experts say
Exclusive: Businesses with staff travel contracts with Qantas are reconsidering future arrangements, says commercial director at corporate travel management company

Elias Visontay and Jonathan Barrett

06, Sep, 2023 @3:00 PM

Article image
Qantas in crisis: Alan Joyce has departed but the airline still has plenty of baggage
Qantas’ board is hoping Vanessa Hudson’s ascension will wipe the slate clean. But there are five big issues still plaguing the airline

Elias Visontay Transport and urban affairs reporter

05, Sep, 2023 @3:00 PM

Article image
Frequent flyer programs: which is best for Australians – and is there a catch?
Qantas, Velocity and KrisFlyer will earn you free flights or upgrades but you’ll have to give something too – your data

Katie Cunningham

01, Dec, 2023 @2:00 PM

Article image
Watchdog launches investigation into Qantas flight that issued mayday after losing engine
QF144 landed safely at Sydney airport on Wednesday after one of its engines failed over the Tasman Sea

Elias Visontay Transport and urban affairs reporter

19, Jan, 2023 @4:15 AM

Article image
Qantas slashes flights as coronavirus hits passenger numbers
Alan Joyce – Australia’s highest paid boss – will take no salary as staff asked to take unpaid leave

Ben Doherty

09, Mar, 2020 @11:40 PM

Article image
Qantas faces shareholder rebellion over role in forced deportations
Investors will vote on AGM motion saying policy could damage the airline’s reputation and share value

Naaman Zhou

24, Oct, 2018 @5:00 PM