---
title: "Qantas Cyberattack: the real failure was what | Firevault"
description: "Why data availability became aviation’s weakest link, and how Firevault makes breaches irrelevant by design. Just days before Australia’s national airline…"
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Firevault has rewritten the rules for data protection & storage via its offline secure storage (OSS) platform, for users to vault everything that matters.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": "GB"
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Firevault has rewritten the rules for data protection & storage via its offline secure storage (OSS) platform, for users to vault everything that matters.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/news/qantas-hit-by-cyberattack-after-fbi-alert-but-the-real-failure-was-what-remained-online#webpage",
      "url": "https://fire-vault.com/news/qantas-hit-by-cyberattack-after-fbi-alert-but-the-real-failure-was-what-remained-online",
      "name": "Qantas Cyberattack: the real failure was what",
      "description": "Why data availability became aviation’s weakest link, and how Firevault makes breaches irrelevant by design. Just days before Australia’s national airline…",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/__l5e/assets-v1/63e4c0b8-2b4d-4117-b973-7ea9deba5b14/qantas-cyberattack-fbi-1771248361477-2x.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/news/qantas-hit-by-cyberattack-after-fbi-alert-but-the-real-failure-was-what-remained-online#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/news/qantas-hit-by-cyberattack-after-fbi-alert-but-the-real-failure-was-what-remained-online#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Learn",
          "item": "https://fire-vault.com/learn"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Knowledge Vault",
          "item": "https://fire-vault.com/learn/knowledge"
        },
        {
          "@type": "ListItem",
          "position": 4,
          "name": "Qantas Cyberattack After FBI Alert, What Stayed Online",
          "item": "https://fire-vault.com/news/qantas-hit-by-cyberattack-after-fbi-alert-but-the-real-failure-was-what-remained-online"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "NewsArticle",
      "headline": "Qantas Cyberattack After FBI Alert, What Stayed Online",
      "description": "Why data availability became aviation’s weakest link, and how Firevault makes breaches irrelevant by design. Just days before Australia’s national airline…",
      "url": "https://fire-vault.com/news/qantas-hit-by-cyberattack-after-fbi-alert-but-the-real-failure-was-what-remained-online",
      "image": [
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/__l5e/assets-v1/63e4c0b8-2b4d-4117-b973-7ea9deba5b14/qantas-cyberattack-fbi-1771248361477-2x.jpg",
          "width": 1200,
          "height": 1200
        },
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/__l5e/assets-v1/63e4c0b8-2b4d-4117-b973-7ea9deba5b14/qantas-cyberattack-fbi-1771248361477-2x.jpg",
          "width": 1200,
          "height": 900
        },
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/__l5e/assets-v1/63e4c0b8-2b4d-4117-b973-7ea9deba5b14/qantas-cyberattack-fbi-1771248361477-2x.jpg",
          "width": 1200,
          "height": 675
        }
      ],
      "thumbnailUrl": "https://fire-vault.com/__l5e/assets-v1/63e4c0b8-2b4d-4117-b973-7ea9deba5b14/qantas-cyberattack-fbi-1771248361477-2x.jpg",
      "author": {
        "@type": "Person",
        "name": "Mark Fermor",
        "jobTitle": "Director & Co-Founder",
        "worksFor": {
          "@id": "https://fire-vault.com/#organization"
        },
        "url": "https://fire-vault.com/why-oss/about"
      },
      "publisher": {
        "@type": "NewsMediaOrganization",
        "name": "Firevault",
        "url": "https://fire-vault.com",
        "logo": {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/logo.png",
          "width": 600,
          "height": 60
        }
      },
      "datePublished": "2025-07-02T11:15:47+00:00",
      "dateModified": "2026-08-28T08:03:22.256672+00:00",
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://fire-vault.com/news/qantas-hit-by-cyberattack-after-fbi-alert-but-the-real-failure-was-what-remained-online"
      },
      "inLanguage": "en-GB",
      "articleSection": "News",
      "wordCount": 948,
      "keywords": "Qantas, News, data breach, cyber security, offline secure storage, data protection, physical air gap",
      "articleBody": "Why data availability became aviation’s weakest link, and how Firevault makes breaches irrelevant by design. Just days before Australia’s national airline Qantas was breached, the FBI issued a formal alert warning of an imminent campaign by Scattered Spider , a cybercriminal group known for infiltrating major infrastructure and aviation brands. The warning was clear. The target profile was known. ",
      "dateline": "United Kingdom",
      "speakable": {
        "@type": "SpeakableSpecification",
        "cssSelector": [
          "h1",
          ".article-summary",
          "h2"
        ]
      },
      "isAccessibleForFree": true,
      "copyrightHolder": {
        "@id": "https://fire-vault.com/#organization"
      },
      "copyrightYear": 2025
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](https://www.bleepingcomputer.com)[2026 DISA Global Solutions 3.3M records ](https://techcrunch.com)[2026 Globe Life 850K records ](https://www.securityweek.com)[2026 Lidl GB Customer contact data ](https://www.theguardian.com/business/2026/jun/11/lidl-gb-third-party-data-breach)[2026 Asahi Group Production systems disrupted ](https://www.reuters.com/technology/cybersecurity/asahi-says-cyberattack-disrupted-operations-japan-2025-09-29/)[2026 Kido International 8K records ](https://www.bbc.co.uk/news/articles/c623d7v0e5xo)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](https://www.bbc.co.uk/news/articles/c789e7l1z7po)[2026 Jaguar Land Rover Production and IT systems disru... ](https://www.bbc.co.uk/news/articles/cx2gx8p3rzeo)[2026 Peter Green Chilled Order and logistics data ](https://www.bbc.co.uk/news/articles/c0k7yy8n3g5o)[2026 Adidas UK Customer contact details ](https://www.bbc.co.uk/news/articles/c78jkev1el2o)[2026 PowerSchool 62.4M records ](https://www.bleepingcomputer.com)[2026 DISA Global Solutions 3.3M records ](https://techcrunch.com)[2026 Globe Life 850K records ](https://www.securityweek.com)[2026 Lidl GB Customer contact data ](https://www.theguardian.com/business/2026/jun/11/lidl-gb-third-party-data-breach)[2026 Asahi Group Production systems disrupted ](https://www.reuters.com/technology/cybersecurity/asahi-says-cyberattack-disrupted-operations-japan-2025-09-29/)[2026 Kido International 8K records ](https://www.bbc.co.uk/news/articles/c623d7v0e5xo)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](https://www.bbc.co.uk/news/articles/c789e7l1z7po)[2026 Jaguar Land Rover Production and IT systems disru... ](https://www.bbc.co.uk/news/articles/cx2gx8p3rzeo)[2026 Peter Green Chilled Order and logistics data ](https://www.bbc.co.uk/news/articles/c0k7yy8n3g5o)[2026 Adidas UK Customer contact details ](https://www.bbc.co.uk/news/articles/c78jkev1el2o)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

[Help](/help)[Get started](/get-started)

Overview

When Data Is Always Available, I…A Familiar Adversary Exploiting …What Should Never Have Been OnlineFirevault: What Disconnection Ma…A Strategic Rethink for Aviation…What This Breach Should Change, …The Takeaway: Live Files Invite …More Resources

[Knowledge Vault](/learn/knowledge)/ [News](/learn/knowledge?filter=news)

News · 2 July 2025 

# Qantas Cyberattack After FBI Alert, What Stayed Online

Why data availability became aviation’s weakest link, and how Firevault makes breaches irrelevant by design. Just days before Australia’s national airline…

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

Mark Fermor Director & Co-Founder, Firevault 

5 min read 

Share 

[](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Fqantas-hit-by-cyberattack-after-fbi-alert-but-the-real-failure-was-what-remained-online)[](https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Fqantas-hit-by-cyberattack-after-fbi-alert-but-the-real-failure-was-what-remained-online&text=Qantas%20Cyberattack%20After%20FBI%20Alert%2C%20What%20Stayed%20Online%0A%0AWhy%20data%20availability%20became%20aviation%E2%80%99s%20weakest%20link%2C%20and%20how%20Firevault%20makes%20breaches%20irrelevant%20by%20design.%20Just%20days%20before%20Australia%E2%80%99s%20national%20airline%E2%80%A6)[](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Fnews%2Fqantas-hit-by-cyberattack-after-fbi-alert-but-the-real-failure-was-what-remained-online)[](mailto:?subject=Qantas%20Cyberattack%20After%20FBI%20Alert%2C%20What%20Stayed%20Online&body=Why%20data%20availability%20became%20aviation%E2%80%99s%20weakest%20link%2C%20and%20how%20Firevault%20makes%20breaches%20irrelevant%20by%20design.%20Just%20days%20before%20Australia%E2%80%99s%20national%20airline%E2%80%A6%0A%0Ahttps%3A%2F%2Ffire-vault.com%2Fnews%2Fqantas-hit-by-cyberattack-after-fbi-alert-but-the-real-failure-was-what-remained-online)

![A commercial aircraft at an airport gate at dusk with red warning lights on the terminal](/__l5e/assets-v1/63e4c0b8-2b4d-4117-b973-7ea9deba5b14/qantas-cyberattack-fbi-1771248361477-2x.jpg)

A commercial aircraft at an airport gate at dusk with red warning lights on the terminal

Why it matters

## What this means for organisations holding critical data

Why data availability became aviation’s weakest link, and how Firevault makes breaches irrelevant by design. Just days before Australia’s national airline…

In this analysis

1.  01 [When Data Is Always Available, I…](#section-0)
2.  02 [A Familiar Adversary Exploiting …](#section-1)
3.  03 [What Should Never Have Been Online](#section-2)
4.  04 [Firevault: What Disconnection Ma…](#section-3)
5.  05 [A Strategic Rethink for Aviation…](#section-4)
6.  06 [What This Breach Should Change, …](#section-5)

**On this page**[When Data Is Always Available, I…](#section-0)[A Familiar Adversary Exploiting …](#section-1)[What Should Never Have Been Online](#section-2)[Firevault: What Disconnection Ma…](#section-3)[A Strategic Rethink for Aviation…](#section-4)[What This Breach Should Change, …](#section-5)

### **Why data availability became aviation’s weakest link, and how Firevault makes breaches irrelevant by design.**

Just days before Australia’s national airline [Qantas](https://www.qantas.com/gb/en.html) was breached, the FBI issued a formal alert warning of an imminent campaign by [Scattered Spider](https://en.wikipedia.org/wiki/Scattered_Spider), a cybercriminal group known for infiltrating major infrastructure and aviation brands. The warning was clear. The target profile was known. But still, the breach came.

Qantas disclosed that internal systems were disrupted in an attack that bore all the hallmarks of Scattered Spider’s well-practised method: SIM-swapping, social engineering, and credential hijacking. Booking platforms were affected. Internal comms systems went offline. Investigation protocols were triggered. And while Qantas maintains that no customer data has yet been confirmed compromised, the silence in the days ahead will speak volumes.

The incident reveals something larger than a single breach: a persistent design flaw in how aviation, and many other critical industries, treat their most sensitive data. The assumption that everything needs to stay online. All the time.

## When Data Is Always Available, It’s Always Vulnerable

Qantas was not targeted because it was weak. It was targeted because it was **connected**.

Like many modern airlines, Qantas operates a sprawling web of platforms that handle flight data, customer ID, financial operations, supplier contracts, employee records, and more, all in real time. This infrastructure is efficient, but it’s also fragile. Because when you expose everything for speed, you expose everything to risk.

According to the **2025 Accenture Aviation Cyber Risk Review**:

-   92% of aviation firms store high-risk data (e.g., ID records, HR cases, contracts) on network-accessible systems
-   68% have no physical or offline data segmentation strategy in place
-   Only 11% use vaulting or air-gapped controls for sensitive compliance files

The design problem isn’t new. But what’s changed is that threat actors now know how, and where, to take advantage of it.

> “The Qantas breach wasn’t a failure of tools. It was a failure of containment. The data was left online, waiting to be found.”  
> , _Mark Fermor, Co-Founder, Firevault_

## A Familiar Adversary Exploiting Familiar Weaknesses

Scattered Spider (also known as UNC3944 or Muddled Libra) has become infamous for targeting English-speaking enterprises with sprawling digital environments. Their focus is high-stakes data. Their method is credential-based access. Their success comes from one thing: **availability**.

In previous breaches, including those at MGM, Caesars, and multiple U.S. telecoms, they didn’t bypass firewalls. They bypassed the process. The same appears to be true in the Qantas case.

By the time the FBI issued its alert, it was already too late.

## What Should Never Have Been Online

What makes this breach more damaging is the likelihood that highly sensitive documents were exposed not because of negligence, but because **they were kept on systems designed to stay live**.

These may include:

-   Crew and employee identity files
-   Passport and payment data tied to frequent flyer accounts
-   Internal HR records, investigations, and disciplinary documents
-   Legal correspondence and board-level strategy papers
-   Audit logs, supplier pricing, and compliance disclosures

These documents **do not need persistent access**. Yet in many airlines, they’re stored on network-connected drives or cloud-based systems, where they’re discoverable, even by adversaries with a single compromised credential.

> “If a document can cost you your reputation, your regulatory status, or your share price, it should not live online.”  
> , _Firevault, Q2 2025_

## Firevault: What Disconnection Makes Possible

This is the precise use case Firevault was built for. Not to detect breaches, or encrypt what is already exposed, but to **remove high-impact data from exposure altogether**.

**Firevault is an offline vaulting platform,** offline by design, to secure sensitive files in a physically offline custody environment. No IP address. No remote sync. No user-driven error paths.

What goes into a Firevault:

-   Legal and regulatory documents
-   Identity records (passports, staff credentials)
-   Executive strategies and risk plans
-   Internal investigations and HR cases
-   Whistleblower logs, board correspondence, and litigation files

These are not records that need to be touched daily. But they are the records that attackers target first.

> “Firevault doesn’t stop a breach. It makes the breach irrelevant by removing the prize.”  
> , _Mark Fermor, Firevault_

## A Strategic Rethink for Aviation and Critical Infrastructure

In light of this breach, aviation CISOs and executives must reconsider their foundational assumptions:

-   Does every file need to be available 24/7?
-   Are we creating exposure simply because no one has said “disconnect it”?
-   What happens if the breach isn’t stopped in time?
-   What if the goal isn’t detection, but disappearance?

Firevault doesn’t sit on your network. It sits **outside** it, reachable only by verified, permissioned users through physically secured channels. It turns the "always-on" threat model into a **“never-there” strategy**.

This isn’t theoretical. It’s now a proven differentiator.

## What This Breach Should Change, Immediately

For boards and CROs, this incident should mark a turning point. The cyber risk conversation is no longer just about phishing, patching, and posture. It’s about **presence**.

If attackers can reach the data, they will.  
If they can’t see it, they can’t touch it.

That’s the disconnection principle Firevault enforces. It’s simple:  
**If you wouldn’t leave it on a USB in a public café, don’t leave it online.**

## The Takeaway: Live Files Invite Live Threats

The Qantas breach was not caused by a bug or an employee mistake. It was caused by an architectural belief, that convenience, speed, and access were more important than custody and containment.

Firevault was built to challenge that belief.  
Because once the breach begins, **only the data you’ve removed from reach will survive intact**.

### References

1.  [The Guardian – Qantas Confirms Cyberattack](https://www.theguardian.com/australia-news/2025/jul/01/qantas-hit-by-cyberattack-amid-scattered-spider-threats)
2.  ABC News – FBI Warning Before Breach
3.  ZDNet – Scattered Spider Targeting Tier 1 Brands
4.  Accenture – 2025 Aviation Cyber Resilience Review
5.  Cybersecurity Dive – Offline Vaulting Market Emerges

**Firevault: The data they can’t see is the data they can’t steal.**  
👉 [firevault.com](/)

About the author

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

### Mark Fermor

[](https://www.linkedin.com/in/mfermor)

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

The Firevault view**Offline Secure Storage® keeps a clean copy beyond the reach of an attacker.**[Why #OSS →](/why-oss)

Control systems and access**Cut the physical paths attackers and third parties depend on.**[Explore Control →](/solutions/control)

Get started**Get started, or talk to a member of the team.**[Get started →](/get-started)

How Firevault would handle this

## Controls an auditor can physically verify

Firevault gives you physical separation, named custody and evidenced access, so compliance claims about isolation and control are things you can show, not just assert.

[Get started](/get-started)[Talk to the team](/demo)

**Custody**Named, access-controlled hardware in a Firevault Bunker 

**Evidence**Access windows and retrieval events are recorded 

**Separation**Physical isolation that satisfies offline copy requirements 

**Jurisdiction**Stored where your regulatory position requires 

Related Reading

## You may also find these useful

[

![Firevault Awarded Cyber Essentials and Cyber Essentials Plus Certification](/__l5e/assets-v1/446b675b-b48b-4b8e-ba01-b97ad3abf97d/firevault-cyber-essentials-plus-certified-2x.jpg)

News 

### Firevault Awarded Cyber Essentials and Cyber Essentials Plus Certification

Firevault has been awarded Cyber Essentials and Cyber Essentials Plus certification, the UK Government-backed scheme run by the NCSC, following an independent technical audit of its systems and controls.

26 Jul 2026 2 min 







](/news/firevault-cyber-essentials-plus-certified)[

![Russian hackers steal UK government logins: why offline vaults change the equation](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/news%2Frussian-hackers-uk-government-logins.jpg)

News 

### Russian hackers steal UK government logins: why offline vaults change the equation

The Telegraph reports that Russian-linked hackers have harvested UK government login credentials and traded them on dark-web forums. The incident is a reminder that credentials, however well protected in the cloud, remain the single point of failure that offline data vaults are designed to remove.

7 Jul 2026 4 min 







](/news/russian-hackers-steal-uk-government-logins-offline-vaults)[

![Great Marlow School partially closed after cyber attack](/news/great-marlow-school-cyber-hero.jpg)

News 

### Great Marlow School partially closed after cyber attack

A malware incident has shut down ICT systems at Great Marlow School in Buckinghamshire, cancelling lessons and silencing parent communications. Here is what it tells us.

14 Jun 2026 4 min 







](/news/great-marlow-school-cyber-attack-partial-closure)[

![School Ransomware: Files Must Live Offline](/__l5e/assets-v1/5dcdf155-e287-48e8-bf9b-82b9837b80d0/school-ransomware-safeguarding-2x.jpg)

News 

### School Ransomware: Files Must Live Offline

St Anne's Catholic School in Southampton was shut for four days after ransomware hit its network. It is not the first school to be targeted. From nurseries to councils, sensitive safeguarding data remains dangerously exposed on connected systems.

27 Mar 2026 7 min 







](/news/st-annes-southampton-ransomware-safeguarding-files-physically-offline)[

![TfL Hack: 10 Million Records Stolen](/__l5e/assets-v1/77ff397a-d530-4aee-88e3-5098513ae34e/tfl-hack-10-million-scattered-spider-2x.jpg)

News 

### TfL Hack: 10 Million Records Stolen

Transport for London has confirmed that around 10 million customer records were stolen during the 2024 Scattered Spider cyber attack, making it one of the largest data breaches in British history. The revelation raises urgent questions about transparency, regulatory accountability and the case for offline secure storage.

11 Mar 2026 5 min 







](/news/tfl-hack-10-million-records-stolen-scattered-spider)[

![Firevault: 2025 Tech Trailblazers Shortlist](/__l5e/assets-v1/c2acabab-9ada-4969-9d69-b18478181083/firevault-shortlisted-trailblazers-v2-1771248067838-2x.jpg)

News 

### Firevault: 2025 Tech Trailblazers Shortlist

We’re proud to announce that Firevault Limited has been shortlisted for the 2025 Tech Trailblazers Awards, recognised in the Firestarter category. For a young…

29 Nov 2025 6 min 







](/news/firevault-shortlisted-for-the-2025-tech-trailblazers-firestarter-award)

## Suggested Reading

-   [What is Offline Secure Storage The foundation of physical disconnection ](/offline-secure-storage/what-is-oss)
-   [Why Offline Secure Storage The case for physical control ](/why-oss)
-   [Ransomware Defence Hold gold copies offline ](/oss-for-ransomware-recovery)
-   [Control Physical path control for IT and OT ](/solutions/control)
-   [Knowledge Vault All articles, guides and whitepapers ](/learn/knowledge)
-   [Book a Demo See Firevault in action ](/demo)

[Back to Knowledge Vault](/learn/knowledge)