Home/Incidents/FirstClass (FirstClass.com.au)

FirstClass (FirstClass.com.au)

3 Jun 2026 · NSW · Hospitality & Tourism
Data Breach HIGH ✓ Verified

What happened

A malicious threat actor operating under the alias "2019" leaked a database containing more than 53,300 customer account records belonging to Sydney-based luxury travel agency FirstClass.com.au on an underground hacking forum. The exfiltrated data was made available for download at no cost and compromised personal details including names, phone numbers, email addresses, IP addresses, account statuses, and preferred flight launch airports. Security reviews of the published samples indicated the bulk of populated records were restricted to core personal contact fields. The threat actor responsible has targeted an estimated 19 Australian organizations in early 2026.

Incident details

Organisation
FirstClass (FirstClass.com.au)
Date
3 Jun 2026
Attack type
Data Breach
Severity
HIGH
Sector
Hospitality & Tourism
State
NSW
Records affected
53,300 claimed
Threat actor
2019

Source

insurancebusinessmag.com ↗
← Back to all incidents