Loyalty Points Fraud Funds Cybercriminal 'Holidays'
Cybercriminals are increasingly targeting loyalty points programs, turning accumulated rewards into cash for flights, hotel stays, and other illicit gains.

Cybercriminals are shifting their focus from traditional data theft to a more lucrative and often overlooked avenue: loyalty points programs. These programs, offered by airlines, hotels, retailers, and even fast-food chains, represent a significant pool of 'currency' that is less protected than financial accounts, making it an attractive target for fraudsters.
As highlighted in a recent episode of the Lock and Code podcast featuring Kim Sutherland, Global Head of Fraud and Identity at LexisNexis Risk Solutions, the value stored in loyalty points can be substantial. Sutherland explained that while most loyalty points are valued at approximately one cent each, premium programs can yield more. For instance, 100,000 airline miles can translate to $1,000 in value, providing a direct financial incentive for attackers.
The primary reason for this shift is consumer negligence. Unlike bank accounts or credit cards, individuals often pay less attention to their loyalty program balances and activity. This lack of vigilance allows cybercriminals to exploit accounts with stolen credentials or through other means, redeeming points for high-value goods and services without immediate detection. Sutherland noted that some users are unaware of how to access their points or even that they are accumulating them, further aiding the fraudsters.
Instances of this fraud are already surfacing. One Chicago teacher discovered that 240,000 of his airline points had been stolen only after receiving a confirmation email for their use. In another case, an individual's airline miles were used to book rental cars in different cities, demonstrating the ease with which these points can be converted into tangible assets or services.
While the article doesn't detail specific technical methods used to compromise these accounts, it implies that credential stuffing and phishing are likely vectors, given the general nature of loyalty program access. The ease with which these points can be redeemed for travel and other goods makes them a direct substitute for cash in many scenarios, bypassing the need to launder stolen financial data.
Companies are aware of this growing threat and are implementing measures to protect customer accounts. However, the onus also falls on consumers to be more diligent. Sutherland advises users to regularly monitor their loyalty program accounts, enable any available security features such as two-factor authentication, and be wary of phishing attempts that might target their loyalty program credentials.
The trend underscores a broader evolution in cybercrime, where attackers are seeking out less conventional but equally valuable digital assets. As loyalty programs become more integrated into consumer spending habits, their attractiveness as a target for fraud is only expected to grow, potentially funding everything from illicit online activities to the very 'holidays' of cybercriminals.