• Home
  • News
  • Coins2Day 500
  • Tech
  • Finance
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
TechCybersecurity

Crooks Cash in Stolen Rewards Points for Flights and Hotels

By
Jeff John Roberts
Jeff John Roberts
Editor, Finance and Crypto
Down Arrow Button Icon
By
Jeff John Roberts
Jeff John Roberts
Editor, Finance and Crypto
Down Arrow Button Icon
November 27, 2017, 1:27 PM ET

It’s nice to take a free trip using credit card rewards. Unfortunately, criminal gangs feel the same way and are stealing other people’s rewards points—including those for British Airways and booking site Orbitz—in order to resell them on the Internet.

The rewards scam, which began in Russia but has since spread to English and Spanish speaking markets, represents yet another frontier for cyber criminals to make money by hacking consumer accounts.

According to Flashpoint, a service that monitors activity on the so-called dark web, the crooks are running full-blown travel agencies that let consumers purchase flights or hotel and car packages at a steep discount.

In a blog post describing the scams, Flashpoint also notes that users are encouraged to make reservations in their own names, and that some sites even have community groups where people post vacation photos.

Get Data Sheet, Coins2Day’s technology newsletter.

According to another source familiar with the dark web, which lets people conduct illegal transactions anonymously, there are numerous types of rewards points for sale. Other familiar brands include Southwest Airlines and Canada-based Aeroplan.

In response to a question from Coins2Day about why the companies don’t put a stop to this, Flashpoint said that some brands use software to detect unusual booking patterns. The problem, however, can be hard to detect since many consumers don’t pay close attention to the balances in their various rewards programs, which means thefts can go undetected for long periods of time.

Southwest provided the following statement:

“Southwest has a team that monitors the use of Rapid Rewards points online to ensure Customers are adhering to our polices. We address any misuse identified and implement safeguards to minimize unauthorized activity.”

The other companies did not immediately respond to a request for comment.

According to Flashpoint, the rise of hackers stealing rewards points has been facilitated by the use of “brute force” software, which allows the user to guess a large number of passwords in a short amount of time:

After obtaining a user’s password through brute forcing, cybercriminals can potentially access any rewards points associated with the compromised accounts. A symbiotic relationship exists between the expanding presence of these tools and the marketplace for compromised credentials.

In order to prevent hackers stealing their rewards programs, Flashpoint advises using long and complex passwords since those are harder to guess.

This story was updated at 7:45pm ET with Southwest statement.

About the Author
By Jeff John RobertsEditor, Finance and Crypto
LinkedIn iconTwitter icon

Jeff John Roberts is the Finance and Crypto editor at Coins2Day, overseeing coverage of the blockchain and how technology is changing finance.

See full bioRight Arrow Button Icon
Rankings
  • 100 Best Companies
  • Coins2Day 500
  • Global 500
  • Coins2Day 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Leadership
  • Success
  • Tech
  • Asia
  • Europe
  • Environment
  • Coins2Day Crypto
  • Health
  • Retail
  • Lifestyle
  • Politics
  • Newsletters
  • Magazine
  • Features
  • Commentary
  • Mpw
  • CEO Initiative
  • Conferences
  • Personal Finance
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Coins2Day Brand Studio
  • Coins2Day Analytics
  • Coins2Day Conferences
  • Business Development
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Coins2Day
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map

© 2025 Coins2Day Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Coins2Day Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.