Skip to main content
Skip to content
Pricing
Try a live demo, it's freeBook a DemoSign InStart free

Security notice: 9 August 2026

A fraudulent trial account used our campaign feature to send Qantas-impersonation scam emails. No customer data was accessed. Here is exactly what happened.

Published 9 August 2026. Updated 18 August 2026 with a second, related incident.

Security notice: 9 August 2026

Published: 9 August 2026 Status: Closed. Both offender accounts terminated. Bulk sending on our shared identity is permanently withdrawn. Last updated: 18 August 2026. A second, related incident by SMS, and the controls now in place, are covered in the update below.


If you received a warning email from us today

It is genuine. We emailed everyone who received the scam message to warn them. Our warning came from bishal@onebookplus.com.au, contains no links, and asks you for nothing.

The scam email you should delete has the subject "Your Qantas credit is ready to claim" and appears to come from "E-QANTAS Rewards". It is not from Qantas. Do not open the link in it.

What happened

Early on Sunday 9 August 2026, someone created a free trial account on OneBookPlus, uploaded a stolen mailing list, and used our email campaign feature to send Qantas-impersonation phishing before we detected and stopped it.

146 messages reached inboxes. The offender's account was banned within two hours of the send, and bulk campaign sending was suspended across the entire platform shortly after.

What was not affected

No customer data was accessed, disclosed or lost. The offender created their own account and could only ever see their own data. No OneBookPlus customer's invoices, contacts, bookings or financial records were touched. There was no compromise of our systems, our credentials or our mail provider.

This is not a notifiable data breach under the Privacy Act 1988, and no notification to the OAIC is required.

Why it reached inboxes

Our campaign feature built the email sender name from the tenant's own business name, without validating it. The offender named their business "E-QANTAS Rewards", so that is what recipients saw, sent from our authenticated domain with valid SPF, DKIM and DMARC.

That is our fault. Spam filters had no reason to stop it.

What we did

  • Banned the account, destroyed its session, and deactivated the tenant
  • Suspended bulk campaign sending platform-wide
  • Reported both scam URLs to Google Safe Browsing, Microsoft and Netcraft
  • Lodged takedown requests with both domain registrars
  • Self-reported to our email provider
  • Notified the security teams of every organisation whose staff received the message
  • Individually warned all 146 recipients
  • Lodged reports with ReportCyber, which referred the matter to Victoria Police, and with ACCC Scamwatch

What we are changing

Written on 9 August. What was actually built went further, see the update below.

  1. Sender name validation. Business names that impersonate banks, government bodies, airlines or major brands can no longer be used as an email sender name.
  2. Campaigns off free trials. Trial accounts get a hard recipient cap; bulk sending requires a paid plan.
  3. Bulk import limits. Contact imports are rate limited and capped.
  4. Detection. Automated alerting on high-volume activity from new accounts. We found this incident by noticing it, which is not good enough.

Bulk campaign sending stays suspended until these are in place.


Update, 18 August 2026

A second incident, by text message

On 15 August 2026 a different account used bulk SMS the same way: 8 text messages to 5 Australian mobile numbers, advertising a fake marketplace listing and asking recipients to make contact off-platform. They went out under the shared OneBookPlus sender ID, so our name appeared on a scam on someone's phone.

Again, no customer data was accessed. The offender created their own account and could only ever see their own data. No other business's contacts, invoices or records were touched.

We texted a correction to every recipient on 16 August. The actor had signed up three times using disposable email domains, re-registering within hours of each block. All three accounts were terminated on 16 August.

Why the 9 August plan was the wrong answer

What we wrote above was mostly filters: validate the sender name, cap the volume, watch for spikes. A filter is a guess about intent, and it fails on exactly the send that matters.

The real problem was that we were lending our identity. A campaign sent from our shared domain, or a text sent under our shared sender ID, carries our reputation, and one abusive send damages invoice delivery for every other business on the platform.

What we actually did

Bulk sending on the OneBookPlus identity is withdrawn. Not filtered, withdrawn. It is off by default and cannot be re-enabled by accident.

Bulk messages now go out only from the sender's own verified identity.

  • Email campaigns require the business's own domain, DNS-verified. The mail goes out as them, on their reputation.
  • Bulk SMS requires the business's own sender name, lodged with the ACMA register.

A scammer cannot borrow a domain they had to prove they own. The reputation risk sits with whoever took it on, which is both fair and the only arrangement that actually holds.

Transactional messages were never restricted and still are not. Booking confirmations, reminders, receipts and invoice links send exactly as before. Those are the messages a customer is already expecting because they just did business with the sender. Blocking them would have punished every honest business for someone else's abuse.

The gate fails closed and cannot be reopened by accident. It is enforced on the server, not by hiding a button, and a send is refused if the check cannot be completed. Declaring whether a message is transactional or bulk is now a required parameter in our code, so a newly built messaging feature cannot be created ungated without its author making that decision deliberately. All 86 existing send paths were reviewed and classified.

Signup is harder to abuse. Disposable email domains are rejected when the account is created, against a list of more than 8,000 refreshed weekly, and aliases of an existing Gmail account can no longer be used to open unlimited free accounts.

What we will not claim

A blocklist raises the cost of coming back; it does not stop a determined person. Of the three domains this actor used, public blocklists carried two. What has changed is not that abuse has become impossible. It is that abuse can no longer be committed using our name.

Questions

Email bishal@onebookplus.com.au. If you received the scam message and want to know exactly what was sent to you, ask and we will tell you.

To report a security issue, see our responsible disclosure policy.

Questions about this notice

I received an email from OneBookPlus warning me about a Qantas scam. Is it genuine?
Yes. On 9 August 2026 OneBookPlus emailed every person who received the scam message, from bishal@onebookplus.com.au, to warn them. That warning email contains no links and asks for nothing. If you received it, it is genuine. The original scam email, with the subject "Your Qantas credit is ready to claim", is not from Qantas and should be deleted.
Was OneBookPlus customer data accessed in this incident?
No. No OneBookPlus customer data was accessed, disclosed or lost. The offender created their own trial account and could only ever see their own data. This was not a breach of OneBookPlus systems and is not a notifiable data breach under the Privacy Act 1988.
How did scam emails pass spam filters if they came from OneBookPlus?
The messages were genuinely sent through the OneBookPlus mail system by an account abusing the platform, so they carried valid SPF, DKIM and DMARC authentication. Recipient spam filters had no signal to reject them. The underlying cause was that a tenant's business name was used as the email sender name without validation, which allowed the offender to present as a well-known brand.
What has OneBookPlus changed to prevent this?
Bulk sending on the shared OneBookPlus identity has been withdrawn permanently. Email campaigns now require the business's own DNS-verified domain, and bulk SMS requires their own ACMA-registered sender name, so a bulk message always goes out on the sender's own reputation rather than ours. The gate is enforced on the server and fails closed. Transactional messages such as booking confirmations, reminders and invoices were never restricted. Disposable email domains are also now rejected at signup. See the 18 August 2026 update on this page for the full detail, including a second, related incident by SMS on 15 August 2026.