Telstra has denied claims the same cyber extortion group currently holding Qantas to ransom have breached and stolen 100 gigabytes of its customer data and are holding it to ransom.
Notorious cybercriminal group Scattered LAPSUS$ Hunters last night updated its victim website to include Telstra, adding to the list of over 40 large companies it claims to have recently breached — which included Qantas, Disney, Toyota and Adidas
Samples of the allegedly stolen data appeared online, however it only included phone numbers, last names, first name initials and residential addresses.
Business News found the exact data listed in the allegedly stolen sample data set on website Reverse Australia, suggesting it was already publicly available.
And in a statement to Business News, a Telstra spokesperson said the claims of a breach were not substantiated.
"We're aware that a malicious actor has listed what it claims is Telstra data online and we have investigated," the spokesperson said.
"Based on our assessment, the data has been scraped from publicly available sources and does not originate from Telstra systems.
"No passwords, banking details or personal identification data a such as driver's licence or Medicare numbers are included."
It comes as the group approaches its October 10 deadline for the ransom of the personal data of over 5 million Qantas customers, breach in late-June.
Some 153 gigabytes of Qantas data was stolen in the June 28 breach, in which a group of cyber criminals used social engineering techniques to trick a third-party customers service platform operated by a call centre in the Philippines into granting access to its systems.
The data stolen comprised almost six million Qantas accounts, including full names, addresses, emails, phone numbers, dates of birth and frequent flyer numbers.
The group claims to have breached through Salesforce, although Salesforce has since blamed the Drift app, a third-party tool built by Salesloft that connects to Salesforce to automate customer service interactions.
Qantas was one of 39 large companies listed as having had data stolen as a result of the Salesforce breach, which also included Adidas, Toyota, Disney and Google.
The criminal group late-last week posted on a newly created breach website (currently defunct) to boast of its skills, warn Salesforce it must negotiate, and threaten the data would be released publicly on October 10.
"We highly advise you proceed into the right direction, your organisation can prevent the release of this data, regain control over the situation and all operations remain stable as always," the website said.
"We highly recommend a decision-maker to get involved as we are presenting a clear and mutually beneficial opportunity to resolve this matter."
"If Salesforce does not engage with us to resolve this, we will completely target each and every indiviual (sic) customers of theirs listed below, failure to comply will result in massive consequences.
"If we come to a resolution (with Salesforce) all individual extortions against your customers will be withdrawn from. Nobody else will have to pay us, if you pay, Salesforce."
A statement from Salesforce said the company was "aware of recent extortion attempts by threat actors".
"Our findings indicate these attempts relate to past or unsubstantiated incidents, and we remain engaged with affected customers to provide support," the statement said.
"At this time, there is no indication that the Salesforce platform has been compromised, nor is this activity related to any known vulnerability in our technology."
While the statement denies there had been an actual hack, it links to a March 2025 blog post on its own website detailing how companies can guard against social engineering-based cyber attacks - the very attack vector used in Scattered Lapsus$ Hunters' claimed breach.
In an email to customers, Salesforce said it refuses to negotiate or pay the group's extortion demands.
It comes after Qantas last week was granted a six-month non-publication order over the names of solicitors working for the company on the matter by NSW Supreme Court Justice Francois Kunc.
"In relation to the lawyers (a non-publication order) might be... justifiable on the basis that the perpetrators have some temporary ire against the legal advisors," he said.
"It is depressing as it is obvious to observe that their attention will move on."
Justice Kunc said the perpetrators of the attack seemed to be "beyond our reach" and said hacking activities like the Qantas breach presented a "serious societal problem".
"The threat represented to our community, to our commerce, by these actors is very real."
That followed Qantas obtaining an interim injunction in the NSW Supreme Court to prevent the stolen data being accessed, viewed, released, used, transmitted or published by anyone, including by third parties.
While injunctions like that stop the information being shared within Australia, it does little to stop its spread by threat actors involved.
In fact, Scattered Lapsus$ Hunters didn't just ignore the injunction; they published all the court files showing Qantas' application for the injunction on a now-deleted Telegram channel.
On a separate Telegram channel, still running, the group lashed out at Qantas for the court orders.
"Qantas, why are u (sic) lying to your citizens? All your injunction does is prevent media outlets/journalists," the statement said.
"YOUR data WILL be released and IT WILL be accessed."
