Qantas passengers’ personal details exposed as airline app logs users into wrong account

Potentially thousands of Qantas customers have had their personal details made public via the airline’s app, with some frequent flyers able to view strangers’ account details and possibly make changes to other users’ bookings. Clare Gemmell from Sydney said that she and four colleagues encountered the problem shortly after 8.30 on Wednesday morning. “My colleague logged in and said ‘I think the Qantas app has been hacked because it’s not my account when I log in’.” When Gemmell logged into the app, she was greeted with a message saying “Hi Ben”. The app told her Ben had more than 250,000 points and an upcoming international flight. “Another colleague of mine said it looked like she was able to cancel somebody’s flight ticket,” she said. “You could see boarding passes for other people, one of my colleagues could see a flight going to Melbourne and it looked like you could interact and actually affect the booking.” Sign up for Guardian Australia’s free morning and afternoon email newsletters for your daily news roundup The app has more than 115,000 ratings and reviews in the Apple store, where it has a star rating of 4.8. Gemmell, who works in customer data technology, said...

Read more