Australia’s national carrier is once again investigating a possible security breach after some of its customers were targeted by WhatsApp phishing messages.
“We’re investigating reports of phishing attempts targeting some Qantas Hotels customers.
“If you receive a suspicious WhatsApp message claiming to be from a hotel, you should ignore the message. Qantas Hotels and our accommodation partners will never ask you to verify your booking or provide personal details via WhatsApp.
“If you are concerned about your booking, we encourage you to check Qantas.com or the Qantas app.”
Qantas said it never requests passwords from customers and that customers should not provide personal information outside official airline channels.
Capella Hotels and Resorts has also noted the phishing messages, which have come to the attention of Capella Sydney. Several of its guests have received “suspicious” messages via WhatsApp.
“Capella Sydney is aware of reports from guests who have received suspicious WhatsApp messages requesting payment and credit card details in relation to their reservations,” a hotel spokesman told the ABC late last week.
“We can confirm that the messages did not originate from Capella Sydney.”
Cyber Daily asked Qantas if any new information had come to light since the AFR broke the news last week, but was provided with the same commentary.
Capella Sydney also said it had no further updates to provide.
The WhatsApp incidents come after more than five million Qantas customers had their data compromised by a Scattered Lapsus$ Hunters social engineering campaign in 2025. No threat actor has been identified in relation to the current phishing messages.
Want to see more stories from trusted news sources?Make Cyber Daily a preferred news source on Google.