The text is not handing you points. It is asking for a login, a one-time code, or a card.
A message lands that looks like Qantas Frequent Flyer. Your points are about to expire. Your account is locked. A prize is sitting there if you tap now. The page that opens has the red kangaroo and a box for your membership number, last name, and PIN. If you type those in, or if you type the code that then hits your real phone, you have just given the account to someone who is not Qantas Airways.
Qantas is a real airline. The Frequent Flyer program is real. The official site is qantas.com, and the program also lives at frequentflyer.qantas.com. The costume is the message, not the carrier.

Overview
The trap is simple. Scammers impersonate Qantas Frequent Flyer so you treat the next tap like a chore you already trust. They want one of three things. They want the login: membership number, last name, and PIN. They want the one-time code that Qantas sends when a real login starts. Or they want a card, or a “fee,” that supposedly releases points, a refund, or a prize.
Once they have the login, they can drain points, change the email, and reuse the same details on other sites. Once they have the code, they can finish a login you did not start.
Qantas has said this out loud. On its official cyber safety and latest scams page, the airline tells customers it does not contact people to ask for PINs, passwords, or one-time passwords by text or email. It also tells members to treat unsolicited calls, SMS, and emails that claim to be Qantas with caution. That is the airline talking about people wearing its name. It is not a warning that Qantas itself is fake.
Scamwatch, run by Australia’s National Anti-Scam Centre, posted a Qantas impersonation alert on 9 February 2026. The alert says scammers use Qantas logos and branding, then push a link to claim a refund, claim a gift, or redeem points that are about to expire. Click the link and you land on a site built to steal whatever you type. Scamwatch says Qantas has been warning about this class of scam since it was first identified in August 2025.
You do not need to be a member to get the text. People who think their details were in a data breach are at more risk, but anyone with a phone can be on the list.

This is not a new costume. In July 2023 the Australian Competition and Consumer Commission warned that a text-and-email loyalty scam was already hitting customers of Qantas Frequent Flyer, Telstra, and Coles. In the four months before that alert, Scamwatch had 209 reports.
ACCC Deputy Chair Catriona Lowe said the vast majority named those three programs, and that any loyalty scheme could be next. The script then is the same script now. Your points are about to expire, a link follows, and sometimes the page asks for a credit card so you can “use” the points.
The scammers take the points. They also take the login and the personal details for identity fraud.
Qantas’s own latest-scams list, updated through 2026, names the same family in different clothes. Fake Qantas Points SMS. Bonus points that need “confirmation.” Refunds that could not be processed. Account protection emails. Suspicious sign-in alerts. Gift coupons. Mystery boxes. A settlement after a trip disruption. Card frozen texts. Qantas Pay and Qantas Money lockouts. None of those messages are the airline asking you to save it. They are people who need you to panic for thirty seconds.
The real program is still the real program. Qantas help says you log in from qantas.com or the Frequent Flyer pages with your last name, Frequent Flyer number, and PIN. The airline then sends a verification code to the mobile or email on the account, or you use an authenticator or a passkey. On its passkeys page, Qantas says a passkey only works on the official website and app.
If you wander onto a fake page, the passkey will not authenticate. That is one reason a lookalike site is so hungry for a typed PIN and a typed code. The fake page cannot use your passkey. It needs you to type.
If you already tapped the link, keep the text. Do not type anything else on that page. The rest of this piece is the costume, the ask, and what to do if the login or the card already went out.
How The Scam Works
The fake points text
The most common costume is a clock on your points. Qantas logged a jump in this SMS in April 2026. The sender shows as Qantas or Qantas Points. The subject on some of them is Award Points Expire. One example Qantas published reads, “Your QANTAS plus rewads points will be expired soon,” and then points at a lookalike page on the qantascredit-home.my domain. Another subject Qantas published is “Qantas Frequent Flyer: Your 30,152 Award Points Expire.”
The spelling is sloppy on purpose or by habit. Rewads. Its gone. A number that looks personal. A domain that is not qantas.com. The feeling is the same as a boarding pass you are about to miss. You have flown with the airline, or you have a card in a wallet, or you simply know the name. The text treats that familiarity as a deadline.
Some of those texts tell you to reply Y, then close and reopen the message so a link “activates.” Qantas says that instruction is there to get you to engage.
The Canberra Times, writing on 9 February 2026, the same day as the Scamwatch alert, printed another live line: “Qantas: Your 12,846 Rewards points will expire at 03 February 2026.GO get your gift before they’re gone!” Recipients were told to reply Y or to copy the link into a browser, a way around the filters that block a raw tap.
A Qantas spokesperson told the paper those messages often send people to sites that closely resemble official login pages.
The ACCC’s 2023 warning already described the next screen. You “log in.” You may be asked for a credit card so you can use the points. Then the points move, and so do your details. Lowe’s comment at the time still fits. People under cost-of-living pressure are easier to rush. A balance that “expires tonight” feels like money falling out of a pocket. It is not. It is a form.
Qantas has also logged older cousins of the same text. In June 2025 it warned about SMS that said “Click the link” for uncollected Qantas Points, and about Qantas Marketplace texts that told people to open a link and redeem points before they expire. Same ask. Different stamp on the envelope. If the only new fact in the message is a short link, the message is not a statement. Your real balance sits behind a login you open yourself.
The prize, the gift, the cash-out
If the points clock does not land, a prize will. Scamwatch lists “claim a gift” next to the refund and the expiring-points links. Qantas’s own older-scam list has the same bait across several years.
In May 2025 Qantas published subject lines such as “$99.5 AUD Gift Coupon is waiting!”, “Claim Your Exclusive $99.50 AUD Gift Today!”, and “Your Exclusive vouchers still unredeemed.” In June 2025 it warned about a mystery-box win SMS that asked people to click and schedule a delivery.
In August 2025 the subjects included “Convert to Cash Now,” “Important Information about Expired Travel Credit,” “Loyalty Reward,” “Take action now and Claim your refund,” and “The details of your reward.” In October 2025 a perk SMS congratulated people on a “New MVP W.P.”
The Canberra Times described luxury prizes in the 2026 wave: iPhones, Dyson appliances, Coles vouchers, sitting next to the expiring-points threat. You were not in a draw. The gift is a door. A $99.50 coupon in a subject line is a number Qantas itself quoted from a fake email, not a voucher sitting in your account. If you did not enter a contest, there is nothing to schedule.
Qantas says promotional points are credited automatically. They will never require you to “confirm” or “claim” them through an external link. That sentence is on the airline’s July 2026 bonus-points warning. If a message needs you to claim, confirm, convert, or schedule a prize you did not enter, it is not the program doing you a favour. Real offers, when they exist, are on the site or in the app you opened on purpose.
The lock, the login alert, the protect-your-account email
Fear works as well as greed. Qantas logged a Frequent Flyer suspicious sign-in scam in October 2025. The subjects include “Loyal Traveller Unexpected Login” and “Alert: Login Attempt Unrecognized – Qantas Frequent Flyer.” The email wants a click so you can “verify” a sign-in you never made. A real unexpected login is something you check inside the account, not on a page that arrived with the accusation.
In February 2026 Qantas warned about account-protection emails, often with the subject “Avoid Service Interruption,” that push people to update account and card details. In May 2026 it warned about Qantas Pay emails that say the profile is deactivated, the card is locked, and the points are suspended, with a button to Unlock Qcard.
The same month, Qantas Money emails asked people to complete a profile or verify a card, sent from addresses that are not Qantas, including a mssqatar.com example the airline published. In June 2026 a Qantas Money deletion email, sent from a wufoo.com address Qantas published, said the account would be deleted and funds frozen unless a “mandatory update” was finished by 1 July.
Card-frozen texts showed up in May 2026 too. “Your card has been temporarily suspended.” “Your card has been frozen.” Qantas says some of those scam texts have appeared in the same thread as a real Qantas message. That is a nasty trick. The thread looks familiar. The new line is not from the airline. A frozen card is a bank conversation or an in-app check, not a callback printed under a genuine earlier SMS.
Qantas’s own spotting guide names the urgency language: “action required,” “your account will be locked,” “claim your prize now.” Those phrases are there to shorten the gap between the ping and the tap. The lock is not on your membership. It is on your attention.
The page that is not the login
The Qantas Frequent Flyer login is not a mystery. Qantas help says you sign in from the qantas.com home page, from the Frequent Flyer home page, or from My account, with last name, Frequent Flyer number, and PIN. Then a verification code goes to the mobile on the file. That is the real door. You type the address. You do not borrow it from a text.
The fake door copies the colours and the fields. Qantas’s June 2026 refund-phishing write-up is blunt about what the page harvests: Frequent Flyer membership number, last name, PIN, and credit card details. The emails used subjects like “Update regarding your recent refund” and a Verify and Claim Refund button. The airline published non-Qantas sending domains for that wave, including capdata-osmozium.com, drcoindreau.com, and novatools.com.
Qantas published an example of a fake webpage that asks you to verify the account and confirm a payment method. That is the login trap with a refund costume over it.
July 2026 added a bonus-points email that says an allocation is pending. Subjects look like “Your Bonus Points Allocation Is Pending” plus a reference number. The display name can read Qantas-Digital-Services even when the mailbox is doing other work. The button says View My Points. The destination is a form. Qantas’s line on that wave is the same as the points-SMS line.
Check the balance in the official app or by logging into the Frequent Flyer account yourself. Do not confirm a bonus through mail.
The same month, Qantas warned about fake Travel Protection settlement pages. Those pages dress up as an approved payout after a trip disruption. The airline published examples of what the fakes put on the screen, including a $2,240.00 figure and reference formats such as QTP-2026-449182 and QF-INS-27501. Those numbers are the costume. They will change from message to message.
Qantas says it will never ask you to accept a settlement through an unsolicited link before you have lodged or discussed a claim. If you never opened a claim, there is nothing to review.
Travel Weekly reported one lookalike that used qantaspoins.com, a missing letter, and a sender prefix of +63. Qantas tells members to treat domains that do not end in qantas.com or qantas.com.au as reportable. It names qantas.net and qantas.biz as examples that are not the airline. A display name can say Qantas while the mailbox is support at a qantas-secure.com lookalike, or a string of extra letters. The airline’s rule is short.
Check the address the mail was sent from, not the name on the envelope. Real Qantas mail ends in qantas.com. A mailbox at loyalty.qantas.com is an example Qantas itself gives. The Frequent Flyer safe senders list also names email.qantas.com and e.qantas.com.
Australia now requires branded SMS sender IDs to be registered through the Australian Communications and Media Authority. Qantas says genuine messages can show as Qantas, QANTAS, or QantasMoney. If the phone labels the sender Unverified, treat it as a warning, not as a boarding pass. A registered name is not magic either. Qantas still tells you to match a text against the latest-scams list and to skip the link. The name on the bubble is one check.
The official app is the check that matters.

Qantas’s member account security page is the place it tells Frequent Flyers how phishing actually looks. Poor grammar. Suspicious links. Urgent or enticing language. Altered sender names. Extra numbers in an address. The page also says Qantas will never ask you to email details of your bank account, credit card, PIN, or passwords. That is the airline drawing a line under its own costume. A form that wants those things is not a service centre.
What they actually want
The page is a costume. The ask is specific.
They want the login. Membership number, last name, PIN. With those, a stranger can open the real account and look at the points, the email, the phone, and any card on the profile. From there, points can move into gift cards, flights, or partner redemptions. The Canberra Times, citing an EY report from December 2025, described loyalty points as a “shadow currency” that criminal networks convert and resell. A quiet account is a good target.
If you do not look at the balance for a month, a drain can sit there.
They want the one-time code. Qantas sends that code because a login just started. If a text says enter the code we just sent you, after you typed your PIN on a page you reached from SMS, you may be finishing a login the scammer started on the real site. The code is not a customer-service PIN. It is a key. Qantas says it will not ask for that key by text or email.
Scamwatch repeats the same line. If a person, a form, or a chat window wants the digits that just arrived, stop. Let the code expire. Ten minutes is a short wait. A drained account is not.
They want a fee or a card. The ACCC already described the credit-card step on fake loyalty pages in 2023. The 2026 refund and settlement costumes ask for payment details to process or release money or points. Qantas says it will not ask you to confirm a credit card through unsolicited channels, and it will not ask you to pay for a flight change through an unexpected callback.
In May 2026 it also warned that fake Qantas phone numbers are being planted in search results and social posts. If you call one of those, you reach a person who wants a payment. Use the numbers on qantas.com. Do not use the first result that looks helpful.
None of this makes Qantas the problem. The airline publishes the patterns, takes reports, and tells you to use the app or type qantas.com yourself. The person who needs your code is the person who cannot log in without you. The kangaroo on the fake page is paint. The membership is still yours until you type.
What To Do If You Have Fallen Victim to This Scam
Do not be embarrassed. Scamwatch says that first, and it is right. These messages use a brand millions of people already open without thinking. The costume works because the airline is real.
If you only received the text or the email, do not tap the link, do not reply Y, and do not call a number that arrived with the message. Open the official Qantas app, or type qantas.com yourself, and look at the account there. If the points are still yours and nothing looks off, delete the message after you have reported it.
Qantas asks you to send the original email, the URLs, and screenshots to Scamwatch when you can, then delete the message. If it is a social post, report the post on that platform too.
If you tapped and then stopped, close the tab. Do not type the membership number to “see if the page is real.” It is not. Change the PIN from a page you opened yourself. Turn on or confirm two-factor authentication from the profile, under Personal Information, the way Qantas describes on its member account security page. If you can, set a passkey so a lookalike site cannot complete a login with a stolen PIN alone.
If you typed the membership number, last name, and PIN, treat the account as open to someone else. Change the PIN immediately from the official site or app. Check the email and mobile on the profile. If those have moved, the recovery path is already compromised. Call the Qantas Frequent Flyer Service Centre on 13 11 31 inside Australia, or +61 2 9433 2329 outside Australia.
Those are the numbers Qantas prints on the cyber safety page for a compromised Frequent Flyer account. Qantas’s cyber incident help page also publishes a dedicated support line on 1800 971 541, or +61 2 8028 0534 from overseas.
If you typed a one-time code, assume a real login may have completed. Do the PIN change and the Service Centre call the same day. Ask them to review recent access and to lock what they can. Check whether points moved, whether a family transfer was requested, whether a store or partner redemption went through. Points can leave quietly. If a new device or a new email is on the file, say that first.
If you entered a card, or paid something to release points or a settlement, call the bank or card issuer first and say the details went to a phishing page. Then do the Qantas calls. Watch the account for charges that use the same costume: a travel claim, a points unlock, a small test amount. Do not wait for a statement to roll around.
The $2,240.00 figure Qantas quoted from a fake settlement page is an example of what a costume can print. Your own bank record is the one that matters.
If personal details went out, Scamwatch points Australian and New Zealand residents to IDCARE on 1800 595 160. Qantas’s cyber safety page also tells people to contact IDCARE when personal information may have been stolen or misused. That is identity help, not a second login page.
Report the message to Scamwatch. If you are outside Australia, use your local fraud agency. Qantas’s cyber safety page is the place to match the costume against the latest named waves. Do not use a phone number from a search ad or from the text itself. Qantas says to take contact details from qantas.com, and to end a call that does not feel right and ring back on a number you sourced yourself.
The May 2026 fake-number warning exists because people who “just Googled Qantas” have already reached a desk that is not the airline.
Change the PIN on any other account where you reused it. Loyalty logins leak into email and banking when people recycle a four-digit habit. If the same PIN opens a bank app, change that too, from the bank’s own site or phone number on the back of the card.
Keep the original text or email. A screenshot of the sender, the full address bar, and the time helps Scamwatch and helps the airline. Then delete the message so you do not tap it a week later when you are tired. If a second text arrives that says the first one was a mistake, treat that as the same costume. Qantas will not chase you down a thread to finish a login.
The Bottom Line
Qantas Frequent Flyer is not the scam. The text is. The email is. The page that needs your PIN after a warning you did not ask for is.
The airline’s line is the one to keep. It will not ask for your PIN, your password, or a one-time code by SMS or email. Promotional points do not need a claim tap from a stranger’s link. A settlement you never lodged does not need an Accept button in your inbox. A prize you did not enter is not sitting on a short link.
A lock you heard about in a message is not a lock you fix by typing.
If the message is about points, a lock, a refund, or a gift, open the official app or type qantas.com. If the account is fine, you lost a minute. If it is not, you still have the Service Centre numbers the airline published, the bank, IDCARE, and Scamwatch.
The people who wrote that SMS need you to be late. They need the code while it is still warm. They need a fee that releases something you already own. You can let the clock on the text run out. The points do not live in the message.