toot.wales is one of the many independent Mastodon servers you can use to participate in the fediverse.
We are the Open Social network for Wales and the Welsh, at home and abroad! Y rhwydwaith cymdeithasol annibynnol i Gymru, wedi'i bweru gan Mastodon!

Administered by:

Server stats:

615
active users

#qantas

3 posts2 participants0 posts today

(exclusive):

ShinyHunters sent Google an extortion demand; Shiny comments on current activities

In a long chat yesterday, Shiny touched on Google, France, Australia and the Qantas injunction, and the NSA's alleged attempts at voice analysis:

databreaches.net/2025/08/08/sh

#ShinyHunters #ScatteredSpider #Salesforce #Google #LVMH #Qantas

@campuscodi @lawrenceabrams @zackwhittaker @euroinfosec @kevincollier

Here's the latest on the Qantas hack.

Oddly enough - and I shit you not - I legit woke up in the middle of the night last night and had a random thought that maybe we're looking at the wrong hacking collective for this one.

So yeah, honestly, this rings pretty true.

#qantas #cybersecurity #databreach

cyberdaily.au/security/12447-q

Cyber Daily · Qantas hack: ShinyHunters collective may be behind Aussie airline data breachBy David Hollingworth

@amvinfe has a post about how injunctions and superinjunctions are being used to protect entities but work against having an informed public, especially when it comes to cybersecurity.

The recent #Qantas injunction is a useful example of how an injunction won't solve the problem it is sought to allegedly solve, and it only leaves the public in the dark. If @troyhunt were to be sent the data from Qantas, he could not add it to his database for HaveIBeenPwned because he is Australian and HIBP is an Australian entity. So millions of Qantas customers will not be able to check to see if their information has shown up on the dark web as a result of the Qantas breach because of the injunction that was justified as being needed to protect them.

The topic of injunctions and superinjunctions is very near and dear to @amvinfe's heart -- and mine -- as we both got hit with a #superinjunction earlier this year.

His post:

Legal Silence: Injunctions Against the Press in Cybersecurity

suspectfile.com/legal-silence-

I've just called #Qantas, which is an unusual step for me. Another email which identified all the information I had in the system which has been compromised, and the sentence, "I'd like to reassure you that our investigation has reaffirmed that no credit card details, personal financial information or passport details were stored in this system and therefore have not been accessed."

I felt I needed to give feedback that they have missed the point. I can change my credit card number. I can't change my date of birth.

It shows in part how the system was breached. A complete misunderstanding of what's important to keep secure.