Person using a laptop

Staying Cyber Safe

What you need to know

The cyber safety of Qantas Frequent Flyers is a priority for us. We take active, quality measures to help our members keep safe online and also encourage our members to do what's possible to protect their account and personal information, as well as Qantas Points. The guide below will help you identify threats and protect yourself online.

What’s phishing?

'Phishing' is when scammers try to trick you into sharing information that can be valuable to them, including passwords, PINs, personal information and credit card details.

Phishing emails are the most common for Frequent Flyers, but you might also be targeted with a fake SMS, social media post or even a voice call. Phishing emails might use your name and try to appear authentic by replicating Qantas logos, company information and other familiar materials.

Our top tips for checking your account

The cyber safety checklist

When it comes to staying safe online, the more of these habits you keep, the better.

tip icon

Use strong passwords and PINs

Don't share or write down passwords, and change them frequently. Remember, your Frequent Flyer points are valuable and should be treated like cash. Create unique passwords for each site - avoid easy-to-guess PINs like 1234, birthdays, telephones and postcodes.

lock

Setup Two-Factor Authentication (2FA)

Set up 2FA and auto-lock after periods of inactivity. Log out of accounts and close browser windows when finished.

web icon

Be careful of what you share online

Avoid posting your personal information and booking details on social media, including sharing pictures publicly of your ticket or boarding pass.

software update

Keep your computer's security software up to date

Turn on automatic updates for software across your  personal devices to  help protect your devices from vulnerabilities which could be used to access your device and steal your personal information.

What to do when you have:

Lock icon

Locked out of your Qantas Frequent Flyer account?

Call the Frequent Flyer Service Centre immediately on +61 2 9433 2329 (Worldwide).

Frequently asked questions

Why do I receive a verification code when accessing my Qantas account now? Is this 2FA?
To log in, you usually need to enter your Qantas membership number, last name and PIN. To help members keep their Qantas accounts safe, we've introduced an extra level of security (also known as two-factor authentication or 2FA). When you log into your account, you'll be sent an SMS or email with a verification code to help make sure it's really you. You can also get verification codes using a third-party Authenticator app instead of waiting for texts or emails. 

Where will my 2FA verification code be sent? How long is it valid for?
The verification code will be sent to the mobile phone number or email address you have registered in your Qantas account profile, so your personal details need to be kept up-to-date. (As you log in, you'll be reminded of the registered phone number - with a few digits masked for security.) Once you receive your verification code, you have 10 minutes to enter it into the login window. If the time expires, just reload the page to generate a new code.

You can also get verification codes using a third-party Authenticator app instead of waiting for texts or emails. To set this up go to 'My profile', navigate to 'Personal information', select 'Authenticator App' and follow the prompts.

If I receive a 2FA verification code but I’m not trying to log into my account, do I need to report it?
You should contact the Frequent Flyer Service Centre on 13 11 31. There could be several reasons this happens and not necessarily fraud related or due to an attempted hack. A member of the team will check the account for unusual or unauthorised activity and help make sure the account is secure and set up any additional 2FA options. They will also report this for further investigation. 

I entered my 2FA verification code incorrectly - what now?
If you enter the code once incorrectly, you'll be given two more attempts. After this you'll be taken through a series of security questions allowing you to log in. You'll need to answer the question about your mother's maiden name plus at least two other questions correctly. Then press 'verify' to log in.

I can't access my 2FA verification code - what do I do?
You may not be able to receive a 2FA verification code because, for example, you haven't got your phone with you or recently changed your number. No problem - just select the option to 'verify another way' shown in the login window. You'll be taken through a series of security questions allowing you to log in.