Loyalty Points and Airline Miles Fraud: The Accounts Thieves Love
Your airline miles are money. So are your hotel points, your supermarket rewards, your coffee shop balance, and the credit card points you have been carefully hoarding for a business-class seat. Criminals worked this out long before most account holders did.
Loyalty accounts are close to a perfect target: they hold real transferable value, almost nobody checks them, they rarely have two-factor authentication, and when the theft is discovered months later the trail is cold. This guide explains how the theft works and how to make your accounts a bad target.
Why Loyalty Accounts Are Such Easy Targets
They hold value but feel like nothing
A hundred thousand airline miles can be worth well over a thousand dollars. People who would notice a missing $1,000 from a bank account will not notice missing miles for a year.
Nobody monitors them
You check your bank app weekly. When did you last open your supermarket rewards account? Attackers rely on that gap. Some drain accounts slowly to avoid triggering anything.
Security is usually weak
Many loyalty programmes still use a membership number and a short numeric PIN. Two-factor authentication is often unavailable or off by default. Password requirements are frequently weaker than a bank would allow.
Points are easy to launder
Miles can be transferred to another member, spent on gift cards, converted to merchandise, or used to book a flight or hotel that gets resold. Once redeemed, recovery is difficult.
Your membership number is not a secret
It is printed on boarding passes, luggage tags, and booking confirmations. People photograph boarding passes and post them online constantly. That number plus a weak PIN is often the whole login.
How the Theft Actually Happens
- Credential stuffing. The dominant method. Your email and password leaked from an unrelated breach years ago, and automated tools try that pair against hundreds of loyalty sites. If you reused the password, they are in.
- Phishing. "Your 50,000 miles expire in 48 hours — log in to keep them." The urgency is fake and the login page is a copy.
- Fake reward and survey offers. "Complete this survey for 5,000 bonus points." The survey harvests credentials and personal data.
- Boarding pass exposure. A photographed boarding pass reveals your name, membership number, and booking reference — enough to access some itineraries and, on weaker programmes, the account.
- Call centre social engineering. An attacker with your name, date of birth, and membership number talks an agent into a password reset.
- Points-selling marketplaces. Grey-market brokers buy points with no meaningful checks on where they came from, which is what makes the theft profitable.
- Malware and infostealers. Browser-saved passwords are a standard target, and loyalty logins sit right next to banking ones.
Warning Signs
- Your balance is lower than you remember, or a redemption you did not make appears in the history.
- A booking confirmation for a trip you did not book, often to somewhere you have never been.
- A notification that your email, address, or phone on the account was changed. Act on this immediately — it is usually the first step in a takeover.
- You stop receiving programme emails, because the address on file was changed.
- A "points transfer" confirmation to a member you do not know.
- Login alerts from an unfamiliar country.
- Your tier status drops unexpectedly, or a reward you were saving for is suddenly unaffordable.
- Password reset emails you did not request from any loyalty programme.
How to Protect Your Points
1. Use a unique password on every loyalty account
This single change defeats credential stuffing, which is how most of these accounts fall. Generate a long random password per programme and store it in a password manager. If you have reused one password across your airline, hotel, and supermarket accounts, fix that today.
2. Turn on two-factor authentication wherever it exists
Coverage is improving. Check the security settings of each programme you actually use. Prefer an authenticator app over SMS, but SMS is far better than nothing here.
3. Set a strong PIN and change the default
Where the programme uses a numeric PIN, avoid your birth year, the last four digits of your phone, or 1234. Store it in your password manager rather than reusing one across programmes.
4. Check your balances quarterly
Put a recurring reminder in your calendar. Ten minutes, four times a year, covering your airline, hotel, and any card points. Early detection is the difference between a reversal and a loss.
5. Turn on every notification the programme offers
Email or push alerts for logins, redemptions, transfers, and profile changes. This is free and it is your fastest warning.
6. Never post your boarding pass
Not the photo, not the barcode, not the luggage tag. The barcode in particular encodes more than people realise. Shred paper boarding passes rather than leaving them in the seat pocket.
7. Consolidate and close
Every dormant loyalty account is an unmonitored liability. Close programmes you no longer use, and combine duplicate accounts within the same programme.
8. Do not chase bonus point offers from strangers
Unsolicited emails, DMs, and adverts offering bonus miles are almost always harvesting credentials. Go to the programme's own app or website and check whether the promotion exists there.
9. Be careful with third-party point aggregators
Apps that show all your balances in one place need your credentials for every programme. Some are reputable; some are not; all of them centralise the risk. If you use one, make sure it supports read-only access and has its own two-factor.
10. Spend rather than hoard
A large balance is a large target. It also loses value quietly to devaluations and expiry. If you have been saving points for years, consider using them.
11. Lock down the email address behind them
Every one of these accounts resets through your inbox. That address needs a unique password and strong two-factor before anything else on this list matters.
If Your Points Have Been Stolen
- Call the programme immediately — phone, not email. Ask them to freeze the account and flag fraudulent redemptions. Speed matters: unflown bookings can sometimes be cancelled and the points returned.
- Change the password and check every profile field — email, phone, postal address, and any added authorised users or linked accounts. Attackers change the contact details so you stop receiving alerts.
- Ask for the account history in writing, showing the unauthorised activity and the login records.
- Change the password on your email account too, and revoke active sessions. If the takeover started there, fixing only the loyalty account solves nothing.
- Identify every other account with that password. If the cause was credential stuffing, other services are exposed as well.
- Escalate if they refuse to restore. Most major programmes will reinstate stolen points once fraud is established, but the first agent may say no. Ask for the fraud or loyalty security team, put it in writing, and keep a record of every contact.
- Report it. To the FTC in the US, Action Fraud in the UK, or your national consumer protection body. If a credit card was linked, notify the issuer as well.
- Check the linked card. Some programmes store a payment card for topping up points — treat it as compromised and get it reissued.
- Ignore anyone offering to recover your points for a fee. That is the follow-up scam.
The Bottom Line
Loyalty points are treated as a game by the people who earn them and as currency by the people who steal them. The gap between those two views is the whole vulnerability.
You do not need to do much. Give every loyalty account a unique password, switch on two-factor and alerts where they exist, stop photographing your boarding pass, and open the balances once a quarter.
That is maybe forty minutes of work in total, and it protects something that took you years of flights and shopping to accumulate.
Comments
Post a Comment