Skip to content
Information Technology, Internet

Monash expert: Qantas mobile app glitch exposes customer information

Monash University 2 mins read

A Monash University expert is available to comment on reports of Qantas customers having access to other passengers' information on their mobile app, and what needs to be done to protect against such incidents in the future. 

 

Dr Muhammed Esgin, Department of Software Systems & Cybersecurity, Faculty of Information Technology

Contact details: +61 450 501 248 or media@monash.edu  

  • Cybersecurity
  • Privacy-enhancing technologies
  • Blockchain technologies
  • Quantum-safe cryptography

The following can be attributed to Dr Esgin:

“It is too early to tell what exactly caused the issue. However, it is certainly a privacy concern given (unauthorised) people are able to see personal information about other Qantas passengers. 

 

“Many companies store customer information in a database and mobile applications need to first authenticate a customer to make sure that it is really the right person being granted access. Then typically the app is allowed to retrieve information from the database about that particular user only and not others, unless permission is granted. The issue seems to be that somehow the app is retrieving private information about other users.

 

“To prevent such issues, there needs to be proper authentication, authorisation and access control in place. That means we need to make sure that it is really the right person, accessing the right information and nothing beyond what is permitted.

 

“Unfortunately, these kinds of personal information exposure can be exploited by cybercriminals. It is difficult to measure the extent of the exploitation at this point as we may not be able to fully understand how much sensitive information has been exposed. However, a common strategy of cybercriminals is to use such sensitive information and situations like this to scam users, for example by pretending to be calling/texting/emailing from Qantas or using the sensitive information leaked to present a more convincing scenario to their victims.

 

“We certainly need better training around cybersecurity and its best practices. The software systems we rely on today are quite complex and minor changes may lead to significant issues. Therefore, we need cybersecurity trained people implementing changes carefully whenever needed under stringent protocols to ensure that inadvertent privacy breaches do not arise.”

 

For any other topics on which you may be seeking expert comment, contact the Monash University Media Unit on +61 3 9903 4840 or media@monash.edu. For more Monash media stories visit our news & events site

More from this category

  • Information Technology
  • 15/01/2025
  • 08:08
UNSW Sydney

This metaphorical cat is both dead and alive – and it will help quantum engineers detect computing errors

A team led by UNSW quantum engineers has created a “Schrödinger’s cat” – a famous quantum thought experiment – inside a silicon chip. UNSW…

  • Contains:
  • Information Technology
  • 14/01/2025
  • 01:11
Delinea

Delinea Hires CyberArk Veteran Chris Kelly as President, GTM to Continue Disrupting the Identity Market

Strategic Leadership Appointment Fuels Next Phase of Growth and Execution Following an Impressive 2024SAN FRANCISCO, Jan. 13, 2025 (GLOBE NEWSWIRE) -- Delinea, a pioneering provider of solutions for securing identities through centralized authorization, today announced the leadership appointment of Chris Kelly as President, Go-To-Market. With 20+ years of experience driving revenue growth and client experience, Kelly will oversee Delinea’s global sales, channel, solution engineering, and customer success teams as the company positions for accelerated growth.“Chris’ appointment comes on the heels of a remarkable year for Delinea,” said Art Gilliland, CEO of Delinea. “His extensive global leadership and operational expertise make…

  • Information Technology
  • 14/01/2025
  • 01:11
Mediaocean

New Mediaocean Report Reveals 2025 Advertising Trends: Generative AI and Automation Lead Marketing Evolution

Insights from nearly 700 marketing professionals underscore consumer and media tech shifts as advertisers prioritize digital channelsNEW YORK, Jan. 13, 2025 (GLOBE NEWSWIRE) -- Mediaocean, the foundational partner for omnichannel advertising, released the findings from its 2025 H1 Advertising Outlook Report, which reveals how marketers are navigating rapid technological advancements and shifting consumer behaviors. The report highlights key findings, including the rise of generative AI as the top consumer trend, marketers’ increased investments in automation, and the continued prioritization of digital channels like social media, digital display/video, and Connected TV (CTV).The 2025 Advertising Outlook Report was informed by a recent…

Media Outreach made fast, easy, simple.

Feature your press release on Medianet's News Hub every time you distribute with Medianet. Pay per release or save with a subscription.