{"id":4683,"date":"2026-09-02T07:08:01","date_gmt":"2026-09-02T07:08:01","guid":{"rendered":"https:\/\/cyberasia.io\/?p=4683"},"modified":"2026-09-05T08:01:01","modified_gmt":"2026-09-05T08:01:01","slug":"thegarudaeye-targets-qatar-airways-holidays-over-board-of-peace-funding","status":"publish","type":"post","link":"https:\/\/cyberasia.io\/article\/ddos\/thegarudaeye-targets-qatar-airways-holidays-over-board-of-peace-funding\/","title":{"rendered":"TheGarudaEye Targets Qatar Airways Holidays Over Board of Peace Funding"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Regional hacktivist collective <span style=\"color: #fb923c;border-radius: 4px;padding: 2px 7px;font-weight: 600\">TheGarudaEye Targets Qatar Airways Holidays Over Board of Peace Funding<\/span> in an operational dispatch circulated Tuesday, September 1, 2026, claiming a targeted Layer 7 stresser attack disrupted online travel package booking services on the airline&#8217;s leisure subsidiary portal (<span style=\"color: #38bdf8;border-radius: 4px;padding: 2px 7px;font-weight: 600\">qatarairwaysholidays.com<\/span>).<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" width=\"819\" height=\"1024\" src=\"https:\/\/cyberasia.io\/people\/wp-content\/uploads\/2026\/09\/IMG_20260902_132040_718-819x1024.jpg\" alt=\"\" class=\"wp-image-4685\" \/ loading=\"eager\" fetchpriority=\"high\" srcset=\"https:\/\/cyberasia.io\/people\/wp-content\/uploads\/2026\/09\/IMG_20260902_132040_718-819x1024.jpg 819w, https:\/\/cyberasia.io\/people\/wp-content\/uploads\/2026\/09\/IMG_20260902_132040_718-240x300.jpg 240w, https:\/\/cyberasia.io\/people\/wp-content\/uploads\/2026\/09\/IMG_20260902_132040_718-768x960.jpg 768w, https:\/\/cyberasia.io\/people\/wp-content\/uploads\/2026\/09\/IMG_20260902_132040_718.jpg 1024w\" sizes=\"(max-width: 819px) 100vw, 819px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">In the material shared, <strong>TheGarudaEye<\/strong> displayed the site showing a &#8220;<strong><mark class=\"has-inline-color has-vivid-red-color\">Temporarily Unavailable<\/mark><\/strong>&#8221; message, along with notes indicating the server had failed to respond for more than an hour at the time of checking. The outage was recorded at 07:16 local time on September 1, 2026. As supporting evidence, the group included a link to a report from the third party monitoring service <strong><mark class=\"has-inline-color has-vivid-green-cyan-color\">check-host.cc<\/mark><\/strong>, commonly used to verify a domain&#8217;s availability from multiple network checkpoints around the world.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><mark class=\"has-inline-color has-luminous-vivid-amber-color\">What Reportedly Happened<\/mark><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Based on the material distributed by <strong>TheGarudaEye<\/strong>, the operation&#8217;s primary targets were two entities: Qatar Airways as the parent carrier, and Qatar Airways Holidays as the travel package and vacation services division operating through the domain qatarairwaysholidays.com. The group stated that they had successfully rendered the Qatar Airways Holidays site inaccessible.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The circulated screenshots also featured a world map with green and red markers, a visual style commonly used by hacktivist groups and security researchers alike to depict network status or the geographic distribution of targets. Additional images showed financial data graphics described as business losses resulting from digital operational disruption, though the methodology behind those figures was not explained in detail in the material that was shared.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The &#8220;<strong><mark class=\"has-inline-color has-vivid-red-color\">Temporarily Unavailable<\/mark><\/strong>&#8221; page displayed on <strong><mark class=\"has-inline-color has-vivid-cyan-blue-color\">qatarairwaysholidays.com<\/mark><\/strong> is a standard message that typically appears when a server experiences excessive traffic load, configuration issues, or a temporary service outage. The pattern and narrative used are consistent with the hallmarks of a <strong><mark class=\"has-inline-color has-vivid-red-color\">Distributed Denial of Service attack,<\/mark><\/strong> commonly known as DDoS, a technique that floods a target server with a massive volume of simultaneous requests until the system can no longer serve legitimate users.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><mark class=\"has-inline-color has-luminous-vivid-amber-color\">Who Was Affected<\/mark><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The parties most directly affected by this incident are users and prospective customers attempting to access booking services through the <strong><mark class=\"has-inline-color has-vivid-green-cyan-color\">Qatar Airways Holidays<\/mark><\/strong> website. The site&#8217;s unavailability could potentially disrupt ticket bookings, vacation packages, and other reservation services typically offered through the platform.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" width=\"819\" height=\"1024\" src=\"https:\/\/cyberasia.io\/people\/wp-content\/uploads\/2026\/09\/IMG_20260902_132043_136-819x1024.jpg\" alt=\"\" class=\"wp-image-4687\" \/ loading=\"lazy\" srcset=\"https:\/\/cyberasia.io\/people\/wp-content\/uploads\/2026\/09\/IMG_20260902_132043_136-819x1024.jpg 819w, https:\/\/cyberasia.io\/people\/wp-content\/uploads\/2026\/09\/IMG_20260902_132043_136-240x300.jpg 240w, https:\/\/cyberasia.io\/people\/wp-content\/uploads\/2026\/09\/IMG_20260902_132043_136-768x960.jpg 768w, https:\/\/cyberasia.io\/people\/wp-content\/uploads\/2026\/09\/IMG_20260902_132043_136.jpg 1024w\" sizes=\"auto, (max-width: 819px) 100vw, 819px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">As part of the Qatar Airways corporate group, a disruption at a subsidiary like this also carries reputational implications for the wider business group, given that Qatar Airways is recognized as one of the world&#8217;s five star airlines with a substantial international customer base. As of this writing, no official statement has been published by either Qatar Airways or Qatar Airways Holidays regarding the disruption to their website.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><mark class=\"has-inline-color has-luminous-vivid-amber-color\">Technical Details Circulated<\/mark><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">On the technical side, the material distributed by <strong><mark class=\"has-inline-color has-luminous-vivid-orange-color\">TheGarudaEye<\/mark><\/strong> included screenshots showing streams of randomized green characters against a dark background, a visual style commonly used within hacking communities to depict script execution or simulated network activity. However, no in depth technical specifics were made publicly available by the group, such as the exact attack method used, traffic volume measured in gigabits per second, or a list of IP addresses involved in the operation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The primary piece of evidence they included was a link to a <strong><mark class=\"has-inline-color has-vivid-cyan-blue-color\">check-host.cc<\/mark><\/strong> report with a unique identification code, a service used to verify whether a domain is reachable from various monitoring server locations worldwide. This method is commonly used by hacktivist groups as a form of visual proof to demonstrate the success of their operations to their audience and followers on social media.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><mark class=\"has-inline-color has-luminous-vivid-amber-color\">Background on TheGarudaEye<\/mark><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">TheGarudaEye presents itself as a hacktivist group that openly voices support for Palestine through various hashtags such as #FreePalestine and #WeAreRevolution. In the message accompanying the evidence of the attack, the group wrote a narrative highlighting what they described as funding from an entity called the &#8220;Board of Peace,&#8221; which according to their statement was flowing to Israel.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" width=\"1024\" height=\"576\" src=\"https:\/\/cyberasia.io\/people\/wp-content\/uploads\/2026\/09\/TheGarudaEye-1024x576.jpg\" alt=\"\" class=\"wp-image-4689\" \/ loading=\"lazy\" srcset=\"https:\/\/cyberasia.io\/people\/wp-content\/uploads\/2026\/09\/TheGarudaEye-1024x576.jpg 1024w, https:\/\/cyberasia.io\/people\/wp-content\/uploads\/2026\/09\/TheGarudaEye-300x169.jpg 300w, https:\/\/cyberasia.io\/people\/wp-content\/uploads\/2026\/09\/TheGarudaEye-768x432.jpg 768w, https:\/\/cyberasia.io\/people\/wp-content\/uploads\/2026\/09\/TheGarudaEye.jpg 1280w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">It should be noted that the narrative regarding fund flows and these allegations represents a one sided statement from <strong><mark class=\"has-inline-color has-luminous-vivid-orange-color\">TheGarudaEye<\/mark><\/strong> itself, presented as part of the political motive behind the hacking operation they carried out, rather than an independent investigative finding from any financial institution or human rights organization. In a separate post, TheGarudaEye also displayed a list of countries they referred to as their &#8220;<strong><mark class=\"has-inline-color has-vivid-red-color\">Target List<\/mark><\/strong>,&#8221; including Qatar, Saudi Arabia, Turkey, the United Arab Emirates, the United States, and a number of other nations, with checkmark statuses next to each country name indicating the progress of their operations against that particular country.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The attack on Qatar Airways Holidays was also marked with dedicated operation hashtags, namely <strong><mark class=\"has-inline-color has-vivid-cyan-blue-color\">#OpQatar<\/mark><\/strong> and <strong><mark class=\"has-inline-color has-vivid-cyan-blue-color\">#OpBoP<\/mark><\/strong>, indicating that this incident is part of a broader and ongoing series of cyber operations rather than a standalone action. The group also included acknowledgments to those they described as their allies and supporters, though the identities of these individuals or groups were not disclosed publicly.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">At the end of the post, <strong>TheGarudaEye<\/strong> also promoted a private community accessible through a link on their social media profile, a pattern commonly employed by hacktivist groups to expand their follower base and strengthen their operation&#8217;s visibility within the broader hacking community.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><mark class=\"has-inline-color has-luminous-vivid-amber-color\">Potential Impact on the Aviation and Tourism Industry<\/mark><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">This incident underscores the ongoing vulnerability faced by the aviation and tourism sectors to politically motivated cyber threats. This sector&#8217;s characteristics make it particularly susceptible to <strong><mark class=\"has-inline-color has-vivid-red-color\">DDoS attacks<\/mark><\/strong>, given the high reliance on digital platform availability for ticket booking, online check in, and web based customer service processes.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" width=\"819\" height=\"1024\" src=\"https:\/\/cyberasia.io\/people\/wp-content\/uploads\/2026\/09\/IMG_20260902_132044_884-819x1024.jpg\" alt=\"\" class=\"wp-image-4691\" \/ loading=\"lazy\" srcset=\"https:\/\/cyberasia.io\/people\/wp-content\/uploads\/2026\/09\/IMG_20260902_132044_884-819x1024.jpg 819w, https:\/\/cyberasia.io\/people\/wp-content\/uploads\/2026\/09\/IMG_20260902_132044_884-240x300.jpg 240w, https:\/\/cyberasia.io\/people\/wp-content\/uploads\/2026\/09\/IMG_20260902_132044_884-768x960.jpg 768w, https:\/\/cyberasia.io\/people\/wp-content\/uploads\/2026\/09\/IMG_20260902_132044_884.jpg 1024w\" sizes=\"auto, (max-width: 819px) 100vw, 819px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Should the disruption last for a significant duration as described in this report, potential consequences could include lost transaction opportunities during the outage period, diminished customer confidence in the reliability of the company&#8217;s digital platform, and additional strain on internal technical teams working to restore services as quickly as possible. On a broader scale, incidents like this could also prompt other companies across the <strong><mark class=\"has-inline-color has-vivid-green-cyan-color\">Middle East and Asia<\/mark><\/strong> to reassess the resilience of their digital infrastructure against similar threats, particularly amid growing activity from hacktivist groups targeting entities with certain geopolitical affiliations.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This trend of geopolitically motivated attacks also shows that private sector entities, including airlines and their subsidiaries, are increasingly becoming targets even when they are not directly involved in the government policies or diplomatic issues driving the attacking group&#8217;s narrative.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><mark class=\"has-inline-color has-luminous-vivid-amber-color\">Response and Mitigation Efforts<\/mark><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">As of publication, no official statement has been found from Qatar Airways, Qatar Airways Holidays, or Qatar&#8217;s national cybersecurity authority regarding the current status of qatarairwaysholidays.com or any recovery measures underway. Users planning to access <strong><mark class=\"has-inline-color has-luminous-vivid-orange-color\">Qatar Airways Holidays<\/mark><\/strong> services are advised to monitor the company&#8217;s official channels, such as verified social media accounts or the main Qatar Airways website, as alternative sources of information during the recovery process.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For other companies in the aviation and tourism sector, this incident can serve as an opportunity to strengthen defenses against <strong><mark class=\"has-inline-color has-vivid-red-color\">DDoS attacks<\/mark><\/strong>, including through the deployment of cloud based traffic mitigation services, real time network anomaly monitoring, the development of robust cyber incident response plans, and close collaboration with third party cybersecurity providers to detect attack patterns at an early stage.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><mark class=\"has-inline-color has-luminous-vivid-amber-color\">Conclusion<\/mark><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The incident affecting <strong><mark class=\"has-inline-color has-vivid-green-cyan-color\">Qatar Airways Holidays<\/mark><\/strong> serves as a reminder that the cyber threat landscape across the Middle East and surrounding regions continues to evolve, with motives increasingly intertwined with <strong><mark class=\"has-inline-color has-luminous-vivid-orange-color\">geopolitical issues and regional conflicts<\/mark><\/strong>. Groups like <strong><mark class=\"has-inline-color has-vivid-cyan-blue-color\">TheGarudaEye<\/mark><\/strong> demonstrate how hacktivism today extends beyond government institutions and increasingly reaches into private sector businesses perceived as symbolically connected to the causes they champion.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>CyberAsia.io<\/strong> will continue to monitor further developments regarding the recovery status of the Qatar Airways Holidays website, as well as any potential official response from the parties involved, and will update this report should new relevant information become available.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\" \/>\n\n\n\n<p class=\"wp-block-paragraph\"><em><strong><mark class=\"has-inline-color has-vivid-red-color\">Disclaimer:<\/mark><\/strong> CyberAsia is an independent Cyber Threat Intelligence (CTI) research organization. The information provided in this report is derived from public intelligence gathering, dark web monitoring, and threat actor claims. It is published strictly for educational purposes, defensive analysis, and public awareness. CyberAsia does not endorse, verify, or facilitate any cyberattacks or illegal activities.<\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n","protected":false},"excerpt":{"rendered":"<p>Regional hacktivist collective TheGarudaEye Targets Qatar Airways Holidays Over Board of Peace Funding in an operational dispatch claiming a targeted Layer 7 stresser attack disrupted online travel package booking services.<\/p>\n","protected":false},"author":3,"featured_media":4684,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[1656,2400,521,29,203,773,14,70,12,1664,2402,2399,2401,2407,2398,2403,1649,1654,1655,868,1046,1173,1666,2405,1259,2404,1049,1178,1245,1247,2406,1160,1241,1169],"threat_actors":[411],"class_list":["post-4683","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ddos","tag-berita-keamanan-siber","tag-board-of-peace","tag-cyber-asia","tag-cyber-attack","tag-cyberasia","tag-cybersecurity-news","tag-ddos-attack","tag-hacker-news","tag-hacktivism","tag-keselamatan-siber","tag-middle-east-cybersecurity","tag-opqatar","tag-peretasan-qatar","tag-qatar","tag-qatar-airways-holidays","tag-qatar-cyber-attack","tag-serangan-ddos","tag-serangan-hacker","tag-serangan-siber","tag-thegarudaeye","tag-1046","tag-1173","tag-1666","tag-2405","tag-1259","tag-2404","tag-1049","tag-1178","tag-1245","tag-1247","tag-2406","tag-1160","tag-1241","tag-1169","threat_actor-the-garuda-eye"],"_links":{"self":[{"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/posts\/4683","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/comments?post=4683"}],"version-history":[{"count":7,"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/posts\/4683\/revisions"}],"predecessor-version":[{"id":4781,"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/posts\/4683\/revisions\/4781"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/media\/4684"}],"wp:attachment":[{"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/media?parent=4683"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/categories?post=4683"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/tags?post=4683"},{"taxonomy":"threat_actor","embeddable":true,"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/threat_actors?post=4683"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}