Skip to content
Qantas investigates WhatsApp phishing reports targeting customers

Qantas investigates WhatsApp phishing reports targeting customers

Australianaviation.Au September 22, 2026

Australia’s national carrier is once again investigating a possible security breach after some of its customers were targeted by WhatsApp phishing messages.

The Flying Kangaroo and a Sydney hotel warn customers not to payment details following suspicious messages targeting Qantas Hotels customers. This content is available exclusively to Australian Aviation members. Login Become a Member To the rest of this article, please login. To unlock all Australian Aviation magazine content and again unlimited access to our daily news and features, become a member today! A monthly membership is only $5.99 or save with our annual plans. PRINT $49.95 for 1 year Become a Member See benefits Australian Aviation quarterly print & digital magazines Access to In Focus reports every month on our website PRINT + DIGITAL $99.95 for 1 year Become a Member $179.95 for 2 years Become a Member See benefits Unlimited access to all Australian Aviation digital content Access to the Australian Aviation app Australian Aviation quarterly print & digital magazines Access to In Focus reports every month on our website Access to our Behind the Lens photo galleries and other exclusive content Daily news updates via our email bulletin DIGITAL $5.99 Monthly Become a Member $59.95 Annual Become a Member See benefits Unlimited access to all Australian Aviation digital content Access to the Australian Aviation app Australian Aviation quarterly print & digital magazines Access to In Focus reports every month on our website Access to our Behind the Lens photo galleries and other exclusive content Daily news updates via our email bulletin View more offers and details

Australian Aviation quarterly print & digital magazines

Access to In Focus reports every month on our website

Unlimited access to all Australian Aviation digital content

Access to the Australian Aviation app

Australian Aviation quarterly print & digital magazines

Access to In Focus reports every month on our website

Access to our Behind the Lens photo galleries and other exclusive content

Daily news updates via our email bulletin

Unlimited access to all Australian Aviation digital content

Access to the Australian Aviation app

Australian Aviation quarterly print & digital magazines

Access to In Focus reports every month on our website

Access to our Behind the Lens photo galleries and other exclusive content

Daily news updates via our email bulletin

“We’re investigating reports of phishing attempts targeting some Qantas Hotels customers.

“If you receive a suspicious WhatsApp message claiming to be from a hotel, you should ignore the message. Qantas Hotels and our accommodation partners will never ask you to verify your booking or provide personal details via WhatsApp.

“If you are concerned your booking, we encourage you to check Qantas.com or the Qantas app.”

Qantas said it never requests passwords from customers and that customers should not provide personal information outside official airline channels.

Capella Hotels and Resorts has also noted the phishing messages, which have come to the attention of Capella Sydney. Several of its guests have received “suspicious” messages via WhatsApp.

Capella Sydney is aware of reports from guests who have received suspicious WhatsApp messages requesting payment and credit card details in relation to their reservations,” a hotel spokesman told the ABC late last week.

“We can confirm that the messages did not originate from Capella Sydney.”

Australian Aviation sister publication Cyber Daily asked Qantas if any new information had come to light since the AFR broke the news last week, but was provided with the same commentary.

Capella Sydney also said it had no further updates to provide.

The WhatsApp incidents come after more than five million Qantas customers had their data compromised by a Scattered Lapsus$ Hunters social engineering campaign in 2025. No threat actor has been identified in relation to the current phishing messages.

Extracted Entities

Attack Types (1)

Countries (1)

Domains (1)

Platforms (2)