ddos
TheGarudaEye Targets Qatar Airways Holidays Over Board of Peace Funding
> By Clara | Sep 02, 2026 | 7 min read
Regional hacktivist collective TheGarudaEye Targets Qatar Airways Holidays Over Board of Peace Funding in an operational dispatch circulated Tuesday, September 1, 2026, claiming a targeted Layer 7 stresser attack disrupted online travel package booking services on the airline’s leisure subsidiary portal (qatarairwaysholidays.com).

In the material shared, TheGarudaEye displayed the site showing a “Temporarily Unavailable” message, along with notes indicating the server had failed to respond for more than an hour at the time of checking. The outage was recorded at 07:16 local time on September 1, 2026. As supporting evidence, the group included a link to a report from the third party monitoring service check-host.cc, commonly used to verify a domain’s availability from multiple network checkpoints around the world.
What Reportedly Happened
Based on the material distributed by TheGarudaEye, the operation’s primary targets were two entities: Qatar Airways as the parent carrier, and Qatar Airways Holidays as the travel package and vacation services division operating through the domain qatarairwaysholidays.com. The group stated that they had successfully rendered the Qatar Airways Holidays site inaccessible.
The circulated screenshots also featured a world map with green and red markers, a visual style commonly used by hacktivist groups and security researchers alike to depict network status or the geographic distribution of targets. Additional images showed financial data graphics described as business losses resulting from digital operational disruption, though the methodology behind those figures was not explained in detail in the material that was shared.
The “Temporarily Unavailable” page displayed on qatarairwaysholidays.com is a standard message that typically appears when a server experiences excessive traffic load, configuration issues, or a temporary service outage. The pattern and narrative used are consistent with the hallmarks of a Distributed Denial of Service attack, commonly known as DDoS, a technique that floods a target server with a massive volume of simultaneous requests until the system can no longer serve legitimate users.
Who Was Affected
The parties most directly affected by this incident are users and prospective customers attempting to access booking services through the Qatar Airways Holidays website. The site’s unavailability could potentially disrupt ticket bookings, vacation packages, and other reservation services typically offered through the platform.

As part of the Qatar Airways corporate group, a disruption at a subsidiary like this also carries reputational implications for the wider business group, given that Qatar Airways is recognized as one of the world’s five star airlines with a substantial international customer base. As of this writing, no official statement has been published by either Qatar Airways or Qatar Airways Holidays regarding the disruption to their website.
Technical Details Circulated
On the technical side, the material distributed by TheGarudaEye included screenshots showing streams of randomized green characters against a dark background, a visual style commonly used within hacking communities to depict script execution or simulated network activity. However, no in depth technical specifics were made publicly available by the group, such as the exact attack method used, traffic volume measured in gigabits per second, or a list of IP addresses involved in the operation.
The primary piece of evidence they included was a link to a check-host.cc report with a unique identification code, a service used to verify whether a domain is reachable from various monitoring server locations worldwide. This method is commonly used by hacktivist groups as a form of visual proof to demonstrate the success of their operations to their audience and followers on social media.
Background on TheGarudaEye
TheGarudaEye presents itself as a hacktivist group that openly voices support for Palestine through various hashtags such as #FreePalestine and #WeAreRevolution. In the message accompanying the evidence of the attack, the group wrote a narrative highlighting what they described as funding from an entity called the “Board of Peace,” which according to their statement was flowing to Israel.

It should be noted that the narrative regarding fund flows and these allegations represents a one sided statement from TheGarudaEye itself, presented as part of the political motive behind the hacking operation they carried out, rather than an independent investigative finding from any financial institution or human rights organization. In a separate post, TheGarudaEye also displayed a list of countries they referred to as their “Target List,” including Qatar, Saudi Arabia, Turkey, the United Arab Emirates, the United States, and a number of other nations, with checkmark statuses next to each country name indicating the progress of their operations against that particular country.
The attack on Qatar Airways Holidays was also marked with dedicated operation hashtags, namely #OpQatar and #OpBoP, indicating that this incident is part of a broader and ongoing series of cyber operations rather than a standalone action. The group also included acknowledgments to those they described as their allies and supporters, though the identities of these individuals or groups were not disclosed publicly.
At the end of the post, TheGarudaEye also promoted a private community accessible through a link on their social media profile, a pattern commonly employed by hacktivist groups to expand their follower base and strengthen their operation’s visibility within the broader hacking community.
Potential Impact on the Aviation and Tourism Industry
This incident underscores the ongoing vulnerability faced by the aviation and tourism sectors to politically motivated cyber threats. This sector’s characteristics make it particularly susceptible to DDoS attacks, given the high reliance on digital platform availability for ticket booking, online check in, and web based customer service processes.

Should the disruption last for a significant duration as described in this report, potential consequences could include lost transaction opportunities during the outage period, diminished customer confidence in the reliability of the company’s digital platform, and additional strain on internal technical teams working to restore services as quickly as possible. On a broader scale, incidents like this could also prompt other companies across the Middle East and Asia to reassess the resilience of their digital infrastructure against similar threats, particularly amid growing activity from hacktivist groups targeting entities with certain geopolitical affiliations.
This trend of geopolitically motivated attacks also shows that private sector entities, including airlines and their subsidiaries, are increasingly becoming targets even when they are not directly involved in the government policies or diplomatic issues driving the attacking group’s narrative.
Response and Mitigation Efforts
As of publication, no official statement has been found from Qatar Airways, Qatar Airways Holidays, or Qatar’s national cybersecurity authority regarding the current status of qatarairwaysholidays.com or any recovery measures underway. Users planning to access Qatar Airways Holidays services are advised to monitor the company’s official channels, such as verified social media accounts or the main Qatar Airways website, as alternative sources of information during the recovery process.
For other companies in the aviation and tourism sector, this incident can serve as an opportunity to strengthen defenses against DDoS attacks, including through the deployment of cloud based traffic mitigation services, real time network anomaly monitoring, the development of robust cyber incident response plans, and close collaboration with third party cybersecurity providers to detect attack patterns at an early stage.
Conclusion
The incident affecting Qatar Airways Holidays serves as a reminder that the cyber threat landscape across the Middle East and surrounding regions continues to evolve, with motives increasingly intertwined with geopolitical issues and regional conflicts. Groups like TheGarudaEye demonstrate how hacktivism today extends beyond government institutions and increasingly reaches into private sector businesses perceived as symbolically connected to the causes they champion.
CyberAsia.io will continue to monitor further developments regarding the recovery status of the Qatar Airways Holidays website, as well as any potential official response from the parties involved, and will update this report should new relevant information become available.
Disclaimer: CyberAsia is an independent Cyber Threat Intelligence (CTI) research organization. The information provided in this report is derived from public intelligence gathering, dark web monitoring, and threat actor claims. It is published strictly for educational purposes, defensive analysis, and public awareness. CyberAsia does not endorse, verify, or facilitate any cyberattacks or illegal activities.
> INTELLIGENCE_NOTICE
The report above detailing TheGarudaEye Targets Qatar Airways Holidays Over Board of Peace Funding is part of the CyberAsia public archive. For organizations requiring real-time attack telemetry, check-host latency records, and edge firewall mitigation strategies for ddos incidents, please refer to our Secure Drop or contact the research desk.