IronSights
←All insights

threat intelligence

Scams that follow a data breach: what is circulating in Australia right now

The second campaign after a breach: messages that know your booking, your employer or your bank and ask for one more thing. What is circulating now, the four shapes it takes, and what to do whether you are receiving them or your customers are. Refreshed weekly.

Ryan BallootBy Ryan Balloot, Managing Director29 September 20266 min read
ByRyan Balloot29 September 20266 min read

A data breach is not over when the notification email arrives. For the people whose details were taken, it is the start of a second campaign: messages that know their name, their booking, their employer or their bank, and ask for one more thing. This page tracks what is circulating in Australia right now, explains the shapes those messages take, and says what to do about them, whether you are the person receiving the message or the business whose customers are.

The current section is refreshed with our Friday breach review. Current at 30 September 2026.

Circulating now

What people are receivingWho it targetsWhere it comes from
WhatsApp messages asking the recipient to verify a hotel booking and provide card details, using the real hotel name and dates.Qantas Hotels customers with a current or recent booking.Unknown. Qantas and the hotels involved are investigating; nobody has said how the senders knew who had a booking. Qantas has stated it will never ask for booking verification or personal details over WhatsApp.
Nothing confirmed yet, but expect it: contact that knows an employee's licence, passport or tax file number details.Staff of the businesses listed by ransomware groups in September, including Leisure Coast Kitchens (Kairos), Thorndale Foundation (Qilin) and the dealerships in the Auto-IT supplier compromise (Storm).The proof files those groups published were staff identity documents: licence scans, passport scans, a completed TFN declaration and bank details. That is the raw material for identity fraud and for targeted messages, and it tends to surface weeks to months after the listing.
Bundled breach data resold as combined identity packages, surfacing as unusually well-informed phishing long after the original incident.Anyone whose details were in an Australian breach in the past few years.Criminal marketplaces are combining records from many breaches into one searchable set, so a 2024 breach becomes an ingredient in a 2026 message.

A listing on a leak site is a claim, not a confirmation, and a scam message is not proof that a particular breach caused it. What the table records is which populations are currently being targeted and why.

The four shapes a post-breach scam takes

The breached organisation, impersonated

A message from the company that lost your data, or from a partner of it, asking you to verify, secure, re-confirm or update something. It works because everything in it is true except the request. The Qantas Hotels messages are this shape: the hotel is real, the booking is real, the dates are real, and the link is not.

The helpful third party

Compensation, a refund, credit monitoring, a class action, a government support payment for breach victims. The breach is in the news, the offer sounds like the sort of thing that follows a breach, and the form asks for a bank account or identity document to process it. There is no Australian government scheme that pays breach victims through a link in a message.

The account takeover

No message at all. The stolen password is tried against every other service the person uses, and where it works, the attacker is in. Bundled data makes this efficient, because the attacker can filter to Australian records, to one industry or to one email domain before trying anything. is the control that breaks this chain; a password in a bundle is worth very little against an account that requires a second factor.

The supplier, from inside their own mailbox

For businesses, the most expensive shape. A supplier's mailbox is compromised in a breach nobody told you about, and the next invoice arrives from the real address with new bank details. The National Anti-Scam Centre put payment redirection losses at $166.8 million for 2025. The defence is a phone call to a known number before any bank detail change, every time, with no exceptions for urgency.

If you received one of these

Do not use anything that arrived in the message: not the link, not the phone number, not the reply button. Open the app or website you already use and look there. If the message claims to be from a company you deal with, ring the number on your card or their website and ask. If it knows things about you that only a breach would explain, assume the rest of the record is out there too: change reused passwords, turn on multi-factor authentication everywhere it is offered, and consider a credit ban or credit report check through the credit reporting bodies.

Report it. Scamwatch takes scam reports, ReportCyber takes cybercrime reports, and if money has moved, your bank first. Reports are the only way the numbers on this page get counted.

If it is your customers or staff receiving them

Write the sentence before you need it. Qantas's statement fits in one line: we will never ask you to verify a booking or provide personal details via WhatsApp. Every organisation that holds customer data should be able to finish the same three sentences, and put them on the confirmation email and the website rather than in a press release afterwards: we will contact you here, we will never ask for that, anything else is not us.

Brief the front desk and the inbox. The first sign of a campaign is a customer ringing to ask whether a message is real, and the answer has to be immediate and consistent. Then decide which channels you use for customer contact and stop using the others, because every channel you might plausibly use is one an attacker can plausibly imitate.

If the data came from you, the scam wave is part of the incident. The Notifiable Data Breaches assessment, the 72-hour Cyber Security Act report if a ransom is paid, and the customer communication all run on their own clocks; our cyber obligations hub has the deadlines, and our data extortion response page covers the case where the attacker is publishing rather than encrypting.

Why the wave arrives late

A breach used to be an event with an end date. Now the data is an ingredient. Sellers combine records from many breaches into composite packages, so a customer list with only email addresses becomes a usable identity package once it is joined to a set with dates of birth, another with phone numbers and another with passwords. The message that finally arrives knows more than any single breach exposed. We set this out in your data is now sold in bundles, and the Qantas Hotels campaign is what it looks like on the receiving end.

Frequently asked questions

Are there scams going around after recent Australian data breaches?

Yes. At the end of September 2026 the confirmed campaign is WhatsApp booking-verification messages to Qantas Hotels customers. Staff of businesses listed by groups in September should expect contact that uses the identity documents those groups published. Both are in the table above, which is refreshed weekly.

How do scammers know my booking or my employer?

From a list. A message that knows your name, your hotel and your dates is the product of data taken from somewhere, whether the organisation you dealt with, one of its suppliers, or an older breach recombined with newer ones. The source is often never confirmed, and to the person receiving the message it does not change what to do.

Will the company that was breached contact me by text or WhatsApp?

Assume not unless they have told you in advance that they will. The safe habit is to treat any contact that asks for details or a click as unverified, and to check through the app or website you already use.

Should I pay for dark web removal?

No. There is no remediation for data that has already been copied; it cannot be recalled, and anyone offering to remove it from the dark web is selling something that does not exist. Spend the money on multi-factor authentication and a password manager instead.

Where do I report a scam in Australia?

Scamwatch for scams, ReportCyber for cybercrime, IDCARE for identity theft support, and your bank immediately if money has moved.

If your organisation is the source

A wave of scams against your customers usually means the incident is larger than the notification suggested. If you are dealing with that now, 1300 004 766 is answered 24 hours a day, and our incident response team handles the investigation, the obligations and the customer communication together.

Incident response

If this happens to you, the first hour decides the rest.

Our incident response team is available 24/7 on 1300 004 766. We contain the incident, work out what was taken, and handle the reporting clocks you are now on.