← Back to Gadget Pulse US

Another Loyalty Program Hack Just Handed Strangers Your Rewards Points

Persona #3 ยท Vol: 0

If you woke up this week to an email saying your account was "part of a security incident," congratulations โ€” you're now a card-carrying member of America's fastest-growing club.

This time it's a major hotel loyalty program, and the attackers apparently walked off with names, contact info, and enough account details to make your points disappear faster than free breakfast at a conference hotel.

Here's the part that should bug you more than the breach itself: loyalty accounts are basically unsecured bank accounts that nobody guards.

You've got years of points sitting there, redeemable for flights and rooms, and the password protecting them is probably the same one you used on a forum in 2011.

Criminals buy leaked credential lists from older breaches, then run them against airline, hotel, and retail rewards portals until something unlocks.

Once inside, they drain points into gift cards or transfer them to mule accounts before you even notice the balance is gone.

By the time customer service picks up, your status tier is toast.

What makes this round feel different is the timing.

Travel demand is up, points are worth more than they've been in years, and companies keep bolting on "enhanced security" that amounts to a text message you'll ignore.

Two-factor authentication helps, but only if you actually turn it on and don't approve every push notification like it's a candy crush life.

Change the password on every rewards account you own, and stop reusing the one from your old gym login.

Turn on two-factor everywhere it's offered, even if it's annoying.

Check your points balances monthly the way you'd check a credit card statement, because nobody else is watching them for you.

And if you get one of those vague breach notices, read the fine print.

Companies love burying the useful details โ€” like whether passwords were exposed or just email addresses โ€” somewhere below a paragraph about their "commitment to privacy." That commitment apparently doesn't include telling you plainly what got taken.

The uncomfortable truth is that loyalty programs were built for convenience, not security, and retrofitting them is expensive.

Until regulators or lawsuits force the issue, expect more of these notices landing in your inbox with a cheerful subject line and a link to a FAQ page nobody will read.

Our take: treat every rewards account like cash in a sock drawer, because that's effectively what it is.

The companies clearly aren't losing sleep over it, so you might as well be the one person in your family who actually enables two-factor authentication.

Final Thoughts

It won't make you popular at Thanksgiving, but it might save your points.

Continue Reading