Skip to content
Information Technology, Internet

Monash expert: Qantas mobile app glitch exposes customer information

Monash University 2 mins read

A Monash University expert is available to comment on reports of Qantas customers having access to other passengers' information on their mobile app, and what needs to be done to protect against such incidents in the future. 

 

Dr Muhammed Esgin, Department of Software Systems & Cybersecurity, Faculty of Information Technology

Contact details: +61 450 501 248 or [email protected]  

  • Cybersecurity
  • Privacy-enhancing technologies
  • Blockchain technologies
  • Quantum-safe cryptography

The following can be attributed to Dr Esgin:

“It is too early to tell what exactly caused the issue. However, it is certainly a privacy concern given (unauthorised) people are able to see personal information about other Qantas passengers. 

 

“Many companies store customer information in a database and mobile applications need to first authenticate a customer to make sure that it is really the right person being granted access. Then typically the app is allowed to retrieve information from the database about that particular user only and not others, unless permission is granted. The issue seems to be that somehow the app is retrieving private information about other users.

 

“To prevent such issues, there needs to be proper authentication, authorisation and access control in place. That means we need to make sure that it is really the right person, accessing the right information and nothing beyond what is permitted.

 

“Unfortunately, these kinds of personal information exposure can be exploited by cybercriminals. It is difficult to measure the extent of the exploitation at this point as we may not be able to fully understand how much sensitive information has been exposed. However, a common strategy of cybercriminals is to use such sensitive information and situations like this to scam users, for example by pretending to be calling/texting/emailing from Qantas or using the sensitive information leaked to present a more convincing scenario to their victims.

 

“We certainly need better training around cybersecurity and its best practices. The software systems we rely on today are quite complex and minor changes may lead to significant issues. Therefore, we need cybersecurity trained people implementing changes carefully whenever needed under stringent protocols to ensure that inadvertent privacy breaches do not arise.”

 

For any other topics on which you may be seeking expert comment, contact the Monash University Media Unit on +61 3 9903 4840 or [email protected]. For more Monash media stories visit our news & events site

More from this category

  • Information Technology
  • 23/04/2025
  • 23:11
Axibo Inc.

Waterloo Startup Axibo AI Secures $12M to Pioneer ‘Made in Canada’ Humanoids

Made‑in‑Canada Robotics, Engineered in Waterloo, Designed for the World WATERLOO, ONTARIO / ACCESS Newswire / April 23, 2025 / Axibo Inc., a Waterloo-based robotics innovator celebrated for its groundbreaking 4D volumetric capture technologies and serving customers like Netflix and Apple, today announced a $12 million funding round. This investment includes $11 million from prominent external investors and an additional $1 million from Axibo's founders Anoop Gadhrri, Sohaib Al-Emara, and Reiner Schmidt, whose passion for robotics began back in 2019 with their university's first autonomous vehicle. The funding launches Axibo's ambitious new division dedicated to advanced humanoid robotics.Axibo FoundersWith a track…

  • Information Technology
  • 22/04/2025
  • 18:10
HERE Europe B.V.

HERE partners with ECARX to launch Next-Generation, In-Car Navigation at Auto Shanghai 2025

The collaboration leverages HERE’s next-generation navigation platform, and ECARX’s full-stack capabilities to deliver an industry-leading navigation solution for leading Chinese automakers. By integrating HERE SDK and compliant location data across 200+ countries, the solution significantly shortens development cycles for international vehicle platforms. A production-ready solution, along with a demo, will debut at Auto Shanghai 2025.Shanghai, Auto Shanghai 2025 – HERE Technologies, the leading location data and technology platform, today announced its strategic partnership with ECARX, global mobility technology company ECARX (Nasdaq: ECX), on co-developing a new-generation navigation system with multi-scenario adaptability, integrating the HERE SDK navigation platform with ECARX's full-stack…

  • Information Technology
  • 22/04/2025
  • 10:41
American Wave Machines, Inc.

PerfectSwell(R) Zion To Start Construction

Generation 6 Technology Set for Southern Utah SOLANA BEACH, CA / ACCESS Newswire / April 17, 2025 / American Wave Machines, the global leader in world-class surf pool destinations, announces a new project, PerfectSwell® Zion, a mixed-use development in Washington, Utah, the outdoor activity hub adjacent to Zion National Park. AWM is partnering with Desert Lakes LLC on the project. The commercial surf park anchors a luxury residential community called Zion Shores offering waterfront single family homes and beachfront townhouses. PerfectSwell® Zion will be open to the public with Zion Shores residents enjoying unique perks and surf priority. PerfectSwell® Zion…

Media Outreach made fast, easy, simple.

Feature your press release on Medianet's News Hub every time you distribute with Medianet. Pay per release or save with a subscription.