{"id":406730,"date":"2026-08-30T16:07:09","date_gmt":"2026-08-30T16:07:09","guid":{"rendered":"https:\/\/malwaretips.com\/blogs\/?p=406730"},"modified":"2026-08-30T16:07:09","modified_gmt":"2026-08-30T16:07:09","slug":"qantas-rewards-message-scam-investigation","status":"publish","type":"post","link":"https:\/\/malwaretips.com\/blogs\/qantas-rewards-message-scam-investigation\/","title":{"rendered":"Qantas Rewards Message Scam Exposed: Fake or Real? A Full Investigation"},"content":{"rendered":"<p>A message says thousands of Qantas Frequent Flyer points are about to expire. Another promises a refund, a gift, or a special reward that must be claimed before the clock runs out.<\/p><div id=\"mwtad2474619497\" class=\"mwtadhigh-1 mwtadentity-placement\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"7453445881\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>The offer feels personal because travel points have real value. The link, however, can lead to a carefully copied page built to steal much more than a few loyalty points.<\/p>\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" width=\"533\" height=\"511\" src=\"data:image\/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==\" class=\"wp-image-406726 lazyload\" alt=\"Fake Qantas text and email messages promising expiring reward points and a loyalty prize\" loading=\"lazy\" title=\"\" sizes=\"auto, (max-width: 533px) 100vw, 533px\" data-src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/qantas-rewards-phishing-message.png\" data-srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/qantas-rewards-phishing-message.png 533w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/qantas-rewards-phishing-message-300x288.png 300w\"><\/figure>\n<div id=\"mwtad302617956\" class=\"mwtadheader-1 mwtadentity-placement\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"2917133959\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Overview<\/h2>\n<h3>The Messages Borrow Trust From a Real Loyalty Program<\/h3>\n<p>Qantas is a familiar airline, and its Frequent Flyer program gives points a recognizable value. Scammers exploit that familiarity with messages about expiring balances, surprise refunds, unclaimed gifts, or account verification.<\/p><div id=\"mwtad4148150320\" class=\"mwtadp1 mwtadentity-placement\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"1471373341\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>The recipient does not need to be a Qantas customer. High-volume campaigns can reach people at random, while more targeted messages may use contact details or travel information exposed elsewhere.<\/p>\n<p>A convincing logo and an accurate description of the rewards program do not authenticate the message. Brand images, colors, and common account language can be copied in minutes.<\/p>\n<h3>The Link Leads to the Actual Scam<\/h3>\n<p>The SMS or email is only the invitation. The linked page may reproduce a Qantas sign-in screen, rewards catalogue, refund form, survey, or card verification step.<\/p><div id=\"mwtad416927938\" class=\"mwtadp2 mwtadentity-placement\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"6935453015\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>Anything entered can be captured by the operator. That may include a Frequent Flyer number, password, name, date of birth, address, card details, bank information, security answers, or one-time verification code.<\/p>\n<p>The attacker can then test the credentials on the real account, attempt card purchases, use the personal details in other fraud, or sell the collected information.<\/p>\n<h3>Urgency Prevents Independent Verification<\/h3>\n<p>Expiring points and limited rewards create a believable deadline. A victim who fears losing a valuable balance may follow the supplied link instead of opening the Qantas app independently.<\/p><div id=\"mwtad4132927962\" class=\"mwtadp3 mwtadentity-placement\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"5315249587\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>Scamwatch has confirmed active Qantas impersonation messages involving refunds, gifts, and expiring points. Qantas does not ask customers to send passwords, PINs, or one-time passwords by email or text.<\/p>\n<ul>\n<li>The message may promise points, a refund, a gift, or a travel reward.<\/li>\n<li>Official Qantas branding can be copied onto an unrelated page.<\/li>\n<li>The sender domain and linked domain may have no connection to Qantas.<\/li>\n<li>The fake page can collect account, identity, and payment information.<\/li>\n<li>Anyone can receive the message, even without a Qantas account.<\/li>\n<\/ul>\n<p>One observed text claimed that 12,846 rewards points would expire on January 31, 2026. It told the recipient to claim bonus points and even suggested copying the link into Safari if it did not open.<\/p>\n<div id=\"mwtad788387340\" class=\"mwtadp4 mwtadentity-placement\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"8735619847\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><p>The accompanying email used Qantas and Frequent Flyer branding but came from an unrelated sender domain. It promised a randomly selected $99.50 AUD gift coupon and asked the recipient to complete SMS verification.<\/p>\n<p>Those details are not harmless marketing. They are designed to move the victim from an unexpected message to a fake login, identity form, or payment page before the offer can be questioned.<\/p>\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" width=\"400\" height=\"773\" src=\"data:image\/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==\" class=\"wp-image-406727 lazyload\" alt=\"Fake Qantas Frequent Flyer reward email promising a .50 AUD gift coupon\" loading=\"lazy\" title=\"\" sizes=\"auto, (max-width: 400px) 100vw, 400px\" data-src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/qantas-frequent-flyer-reward-email.png\" data-srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/qantas-frequent-flyer-reward-email.png 400w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/qantas-frequent-flyer-reward-email-155x300.png 155w\"><\/figure>\n<div id=\"mwtad1450159532\" class=\"mwtadheader-2 mwtadentity-placement\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"9284335404\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>What the Fake Qantas Messages Are Trying to Collect<\/h2>\n<p>A fake rewards page often begins with a harmless-looking question or account field. Each additional screen asks for slightly more information, making the process feel like a normal redemption flow.<\/p>\n<div id=\"mwtad3655055754\" class=\"mwtadp5 mwtadentity-placement\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"9971336976\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><p>Login credentials can expose the Frequent Flyer account and any personal data stored there. Reused passwords may also provide access to email, shopping, and financial accounts.<\/p>\n<p>Card details allow attempted purchases. A one-time code can authorize a transaction or confirm a new device while the victim believes they are merely verifying a reward.<\/p>\n<p>Identity details remain useful after the fake page disappears. Names, addresses, birth dates, travel preferences, and loyalty numbers can support later impersonation calls or account-recovery fraud.<\/p>\n<div id=\"mwtad2403033307\" class=\"mwtadheader-3 mwtadentity-placement\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"5345090394\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Why the Reward and Refund Stories Feel Believable<\/h2>\n<p>Loyalty programs regularly send legitimate notices about points, promotions, and member offers. Scammers hide their message inside that normal flow and use a reward size that sounds attractive without appearing impossible.<\/p>\n<p>Travel also creates moments of uncertainty. A recent flight, delay, booking change, cancelled trip, or remembered points balance can make an unexpected refund message feel timely.<\/p>\n<p>The emotional hook changes according to the recipient. A reward creates excitement, an expiry notice creates fear of loss, and a refund suggests money is already owed. Every version pressures the reader to click first and verify later.<\/p>\n<div id=\"mwtad1161428634\" class=\"mwtadheader-4 mwtadentity-placement\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"5354318971\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Why a Frequent Flyer Account Is Valuable to Criminals<\/h2>\n<p>A loyalty account may not look as sensitive as a bank account, but it can contain spendable points, stored contact information, travel history, membership status, and links to family or business profiles.<\/p>\n<p>Points can sometimes be redeemed for travel, upgrades, products, vouchers, or transfers. A criminal who gains control may change contact details, make a redemption, or use the account as a stepping stone into another service.<\/p>\n<p>Travel information also has value for social engineering. Knowledge of a recent destination, membership tier, or booking can make a later call about a refund or schedule change feel personally relevant.<\/p>\n<p>The account password creates an additional risk when it has been reused. Attackers routinely test captured email and password combinations against other services, a process known as credential stuffing.<\/p>\n<p>This is why the response should not stop with the loyalty account. The victim must also secure the connected email and every important account that used the same or a closely related password.<\/p>\n<p>A points balance can be replaced in some circumstances, but identity and login information can keep circulating. Quick action reduces the opportunity for the operator to turn one fake reward into several different fraud attempts.<\/p>\n<div id=\"mwtad890573777\" class=\"mwtadheader-6-2 mwtadentity-placement\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"2830607691\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>How a Fake Verification Screen Can Defeat Bank Warnings<\/h2>\n<p>Modern phishing pages may work in real time. When the victim submits card information, the operator can immediately try it at a merchant or add it to another payment service.<\/p>\n<p>The genuine bank then sends a verification message. Because the victim is already expecting a code from the fake reward page, the security prompt can appear to confirm that everything is proceeding normally.<\/p>\n<p>Read the bank message carefully. It may name the actual merchant, amount, device, or action being authorized. That description matters more than the explanation shown on the rewards page.<\/p>\n<p>Never copy a one-time code into a page reached through an unsolicited message. Close the page, open the banking app independently, and contact the issuer if an unfamiliar authorization appears.<\/p>\n<p>A scammer may call seconds later and claim the code is required to reverse the suspicious charge. Real bank staff do not need the customer&#8217;s one-time password to cancel fraud.<\/p>\n<p>If a code was shared, tell the issuer exactly what happened. Saying only that the card may be compromised can miss the fact that an authentication step was actively approved.<\/p>\n<div id=\"mwtad4057641310\" class=\"mwtadheader-6 mwtadentity-placement\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3648031192\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>How the Qantas Rewards Message Scam Works<\/h2>\n<h3>Step 1: A Reward or Problem Appears Without Warning<\/h3>\n<p>The campaign begins with an SMS or email claiming that points will expire, a refund is waiting, a gift has been selected, or account benefits need confirmation.<\/p>\n<p>The message may include a precise points balance or redemption deadline. Exact numbers make the claim feel account-specific even when the same message has been sent widely.<\/p>\n<h3>Step 2: Qantas Branding Creates Familiarity<\/h3>\n<p>The sender copies the Qantas name, Frequent Flyer logo, red color palette, travel imagery, and familiar terms such as tier status, loyalty points, or member reward.<\/p>\n<p>Display names can hide the real email address, and a sender name shown as \u201cQantas\u201d can be chosen by anyone. The actual domain after the @ symbol is more useful than the label.<\/p>\n<h3>Step 3: The Link Opens a Lookalike Redemption Page<\/h3>\n<p>The destination may resemble qantas.com, but its registered domain is different. A long address can contain the word \u201cqantas\u201d while still belonging to an unrelated operator.<\/p>\n<p>Some messages encourage copying a failed link into another browser. That unusual instruction is meant to bypass link scanning, browser protections, or a block already placed on the domain.<\/p>\n<h3>Step 4: A Login Form Captures the Account Credentials<\/h3>\n<p>The fake site requests a Frequent Flyer number or email address and password. It may reject the first entry deliberately, prompting the victim to type the password again and confirming it was not a simple mistake.<\/p>\n<p>The real Qantas account is not being verified. The data is being sent to infrastructure controlled by the scammer or an associated phishing service.<\/p>\n<h3>Step 5: The Reward Requires Identity and Payment Details<\/h3>\n<p>After the login, the page may claim a small delivery charge, card validation, tax, or processing fee is needed. This is how a free reward becomes a payment-card theft attempt.<\/p>\n<p>The form can request the full card number, expiry date, security code, billing address, phone number, and date of birth. The small stated fee makes the request seem lower risk than it is.<\/p>\n<h3>Step 6: A Verification Code Authorizes the Fraud<\/h3>\n<p>If the criminal tests the card or account in real time, the bank or service may send a genuine one-time code. The phishing page immediately asks the victim to enter it.<\/p>\n<p>The code is not confirming the reward. It may approve a card transaction, password reset, new device, or account change initiated by the attacker.<\/p>\n<h3>Step 7: The Stolen Data Fuels More Scams<\/h3>\n<p>The page may display an error or fake confirmation after submission. Meanwhile, the operator can attempt account access, redeem points, make purchases, or combine the information with other leaked data.<\/p>\n<p>Later calls may claim to be from Qantas, a bank, or a fraud team. Because the caller knows details entered on the fake form, the follow-up can sound more credible than the original message.<\/p>\n<div id=\"mwtad383963607\" class=\"mwtadheader-7 mwtadentity-placement\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"2944237110\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Company, Address, and Fulfillment Checks<\/h2>\n<h3>The Qantas Logo Does Not Identify the Sender<\/h3>\n<p>Qantas is a real airline, but the message operator is not identified by copied branding. Expand the sender details and inspect the complete email address instead of trusting the visible display name.<\/p>\n<p>A legitimate company can also be impersonated through a compromised mailbox. Confirm the message inside the official Qantas app or account, not by replying to the sender.<\/p>\n<h3>The Web Address Can Expose the Impostor<\/h3>\n<p>Look for the registered domain immediately before the first single slash. A domain such as qantas-reward.example.com belongs to example.com, not Qantas.<\/p>\n<p>Extra words, hyphens, unusual country extensions, and URL shorteners deserve caution. Do not paste the link into another browser simply because the message says to do so.<\/p>\n<h3>Fake Support Often Stops Responding After Payment<\/h3>\n<p>A fraudulent page may list a generic email address or number that handles many unrelated brands. It can disappear as soon as banks, hosting companies, or domain providers begin receiving reports.<\/p>\n<p>Find Qantas contact information through the official app or by typing qantas.com. Do not use contact details printed inside the suspicious email or landing page.<\/p>\n<h3>A Claimed Reward Must Be Traceable Inside the Real Account<\/h3>\n<p>A genuine points balance, refund, or member offer should be visible through an independently opened Qantas account. A reward that exists only after following a message link cannot be verified.<\/p>\n<p>Check the stated campaign, redemption rules, delivery method, and account history. A random gift should not require unrelated card verification or disclosure of a one-time password.<\/p>\n<h2>Warning Signs in a Qantas Points or Refund Message<\/h2>\n<ul>\n<li>The offer is unexpected and expires within hours.<\/li>\n<li>The sender address is unrelated to qantas.com.<\/li>\n<li>The link uses a shortened or unfamiliar domain.<\/li>\n<li>The message asks you to copy a blocked link into another browser.<\/li>\n<li>A free reward requires card details or a small delivery fee.<\/li>\n<li>The page asks for a password, PIN, or one-time verification code.<\/li>\n<li>The offer does not appear inside the independently opened account.<\/li>\n<\/ul>\n<p>Scamwatch&#8217;s official alert confirms that the campaign can target people who are not Qantas customers. Receiving the message does not mean the sender knows your real points balance.<\/p>\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" width=\"1024\" height=\"576\" src=\"data:image\/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==\" class=\"wp-image-406728 lazyload\" alt=\"Australian Scamwatch alert page warning about Qantas impersonation scams\" loading=\"lazy\" title=\"\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" data-src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/scamwatch-qantas-impersonation-alert-1024x576.jpg\" data-srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/scamwatch-qantas-impersonation-alert-1024x576.jpg 1024w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/scamwatch-qantas-impersonation-alert-300x169.jpg 300w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/scamwatch-qantas-impersonation-alert.jpg 1265w\"><\/figure>\n<h2>What to Do if You Have Fallen Victim to This Scam<\/h2>\n<ol>\n<li><strong>Stop using the page immediately.<\/strong> Close it without entering another code or payment. Do not revisit the link to check whether it still works, and do not answer follow-up calls from supposed fraud agents.<\/li>\n<li><strong>Change the Qantas password through the official site.<\/strong> Open the app or type qantas.com yourself. Use a new, unique password and review the Frequent Flyer profile, recent redemptions, linked family accounts, and stored details.<\/li>\n<li><strong>Secure the connected email account.<\/strong> Change its password if it was reused or entered on the fake page. Review sign-ins, recovery options, forwarding rules, app passwords, and active sessions.<\/li>\n<li><strong>Call the bank or card issuer.<\/strong> If card details or a one-time code were submitted, ask the issuer to block the card, investigate pending transactions, and explain whether account monitoring or replacement is needed.<\/li>\n<li><strong>Contact Qantas through an official channel.<\/strong> Report the phishing message and ask the airline to check for unauthorized access, points transfers, profile changes, or reward redemptions.<\/li>\n<li><strong>Preserve the evidence.<\/strong> Save screenshots, the full email, sender address, message number, destination URL, payment record, and time of each event. Do not crop out information investigators may need.<\/li>\n<li><strong>Report identity exposure.<\/strong> Australians can report the scam to Scamwatch and contact IDCARE if personal information was supplied. Report unauthorized transactions to the relevant bank and loyalty program.<\/li>\n<li><strong>Scan the affected device.<\/strong> If you downloaded an attachment, extension, or app, run a full Malwarebytes scan. It can detect credential-stealing malware and unwanted software that a password change alone would not remove.<\/li>\n<li><strong>Reduce exposure to repeated scam pages.<\/strong> AdGuard can block many malicious ads, trackers, and known phishing destinations before they load. Continue checking unexpected rewards directly inside the official app.<\/li>\n<li><strong>Watch for follow-up impersonation.<\/strong> Criminals may call with the stolen details and pretend to be Qantas or your bank. End the call and contact the organization using a number you find independently.<\/li>\n<\/ol>\n<h2>Frequently Asked Questions<\/h2>\n<h3>Are Qantas reward and points-expiry messages always scams?<\/h3>\n<p>No. Qantas can send legitimate account communications. Treat an unexpected link as unverified and confirm the offer inside the official app or an independently opened qantas.com account.<\/p>\n<h3>Can the scam target someone without a Qantas account?<\/h3>\n<p>Yes. Scamwatch says anyone can receive these messages. Large campaigns do not need to know whether every phone number belongs to a Qantas customer.<\/p>\n<h3>Does Qantas ask for one-time passwords by text or email?<\/h3>\n<p>Qantas warns that it does not contact customers to request passwords, PINs, or one-time passwords by email or SMS. Never send a code back to an unsolicited sender.<\/p>\n<h3>What can scammers do with stolen Frequent Flyer credentials?<\/h3>\n<p>They may access profile information, attempt points redemptions, change account details, or use a reused password against other services. Report the exposure promptly.<\/p>\n<h3>Why does the fake page charge a small delivery fee?<\/h3>\n<p>A small fee makes the request feel reasonable and provides an excuse to collect the full card number, security code, billing address, and sometimes a bank verification code.<\/p>\n<h3>Can I safely inspect the link without entering information?<\/h3>\n<p>It is safer not to open it. A page can redirect, track the visit, display deceptive prompts, or attempt a download. Verify the claim through the official Qantas app instead.<\/p>\n<h2>The Bottom Line<\/h2>\n<p>The Qantas rewards message scam turns points, refunds, and gifts into a path toward credential, identity, and card theft. Its branding may look polished, but the account action exists only on a page chosen by the sender.<\/p>\n<p>Do not follow the message link. Open Qantas independently, verify the reward there, and never provide a password, PIN, or one-time code in response to an unexpected email or text.<\/p>\n<div id=\"mwtad3376284287\" class=\"mwtadfinal mwtadentity-placement\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3077074880\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>Qantas rewards scam messages promise expiring points, refunds, or gifts. Learn how the fake pages steal logins, card details, and verification codes.<\/p>\n","protected":false},"author":51,"featured_media":406726,"comment_status":"open","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[49],"tags":[],"class_list":["post-406730","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-scam-reports","masonry-post","generate-columns","tablet-grid-50","mobile-grid-100","grid-parent","grid-50","resize-featured-image"],"_links":{"self":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/406730","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/users\/51"}],"replies":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/comments?post=406730"}],"version-history":[{"count":1,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/406730\/revisions"}],"predecessor-version":[{"id":407362,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/406730\/revisions\/407362"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media\/406726"}],"wp:attachment":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media?parent=406730"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/categories?post=406730"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/tags?post=406730"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}