On Monday, Qantas said it was investigating WhatsApp messages sent to Qantas Hotels customers. The messages ask the recipient to verify a booking and provide payment details. Capella Sydney, one of the hotels involved, confirmed the messages did not come from it. Other accommodation partners are affected. No threat actor has been identified, and neither Qantas nor the hotel has said how the senders knew who had a booking.
That last part is the whole story. A message that knows your name, your hotel and your dates is not a lottery ticket. It is the product of a list.
Where the list came from is unknown, and to the recipient it does not matter
It could be a hotel booking system. It could be a partner's partner. It could be data from last year's Qantas breach, in which more than five million customers' details were taken through , resurfacing in a new campaign. Or none of those. The companies involved are investigating, and until they say, anyone claiming to know is guessing.
What a customer experiences is the same either way. A message on a channel they use every day, from a name they recognise, about a thing that is true. The urgency is real because the booking is real. The only thing wrong with it is the request at the end.
We wrote last month about breach data being bundled and resold, one victim's records joined with another's so the buyer gets a fuller picture. This is what that looks like on the receiving end. The breach notification arrives, the credit monitoring is offered, the story ends. Then, months or years later, the phone buzzes.
The tell has changed
For years the advice was to look for bad spelling and odd grammar. That advice is dead. These messages are clean. The tell now is the channel and the ask.
Qantas put it in one sentence: "Qantas Hotels and our accommodation partners will never ask you to verify your booking or provide personal details via WhatsApp." That is the right shape for a statement, and every organisation that holds customer data should be able to make one like it before anything goes wrong. We will contact you here. We will never ask for that. Anything else is not us.
If your business cannot finish those sentences, your customers cannot check a message against them, and your staff cannot either.
What to do with it
For customers: ignore the message. If you have a booking and you are worried, open the app or the website you booked with and look. Do not use a link, a number or a reply button that arrived in the message.
For businesses: write the "we will never" statement and put it where customers see it, on the booking confirmation and the website, not in a press release after the fact. Decide which channels you use for customer contact and stop using the others, because every channel you might plausibly use is one an attacker can plausibly imitate. And brief the front desk, because the first sign of a campaign like this is a guest ringing to ask whether the message is real, and the answer needs to be immediate.
For staff, the same logic applies inside the building. The finance team gets the "urgent invoice" from a supplier whose mailbox was taken in someone else's breach. The message is on the right thread, references the right job, and asks for a changed bank account. The defence is a rule that survives a convincing message: payment details change by phone call to a known number, never by reply. That rule is the core of the awareness training that works, and the reason most of it does not is that it teaches people to spot fakes instead of giving them a rule.
Phishing-resistant sign-in is the other half. A hardware key or a passkey will not authenticate to a fake page, however convincing the message that led there. We wrote about why we now sell them on Tuesday, and the reasoning applies to a hotel front desk as much as to a finance team.
Is the Qantas Hotels WhatsApp campaign linked to the 2025 Qantas breach?
Nobody has said so. Qantas, Capella Sydney and their partners are investigating, and no threat actor has been identified.
What should I do if I already replied?
If you gave card details, call your bank on the number on the back of the card and ask for the card to be blocked. If you gave a password, change it on the real site and anywhere else you used it.



