Loyalty points fraud is funding hacker holidays (Lock and Code S07E18)
Malwarebytes' Lock and Code podcast examines loyalty-points theft, with LexisNexis' Kim Sutherland explaining why stolen airline and hotel points are lucrative for fraudsters.
LexisNexis Risk Solutions' Kim Sutherland says loyalty currency is worth roughly one cent per point, making 100,000 airline points worth about $1,000 in the US. Cited incidents include a Chicago teacher who lost 240,000 airline points, discovered only via a confirmation email, and a man whose miles were used to book rental cars in New York and Memphis. The episode discusses how points theft happens and what companies and consumers can do.
- Loyalty points are worth roughly one cent each, making them effectively currency for fraudsters.
- Victims often miss theft because loyalty accounts get less attention than bank accounts.
- One Chicago teacher lost 240,000 airline points, spotted only through a confirmation email.
- Stolen miles were fraudulently used to book rental cars in New York and Memphis.
Full article463 words · extracted from malwarebytes.com · click to collapse
This week on the Lock and Code podcast…
Crooks are taking a holiday. They’re counting on you to fund it.
For decades, cybercriminals have stolen roughly the same types of data. Biographical and personal details—like Social Security numbers, birthdates, addresses, and phone numbers—can be stolen to commit identity fraud. Credit card numbers, expiration dates, and CVC codes can be stolen to make fraudulent purchases. Usernames and passwords can, in the wrong hands, let a cybercriminal impersonate someone, steal sensitive photographs to later use for extortion, or abuse a reputation.
All of these attack models seek to turn sensitive or important data into currency. But an emerging form of digital fraud is targeting data that, when used strategically, practically is currency: Loyalty points.
Loyalty points programs are run by nearly every type of consumer-facing business today, from hotels to airlines to grocery stores to donut shops. As repeat customers accrue these points, they can exchange them for discounted prices on future purchases, cutting the costs of hotel stays, flights, rental cars, and even entire vacations.
But the value stored within these loyalty points makes them a high target for cybercrime, said Kim Sutherland, Global Head of Fraud and Identity at LexisNexis® Risk Solutions.
“Most loyalty currency is worth about one cent per point, and then there are premium programs that can be worth more than that,” Sutherland said, explaining that 100,000 airlines points, for example, can be worth $1,000 in the US. “Why criminals care so much about this is because most of us are not paying attention to our loyalty programs the same way we would our bank account.”
But diligence is much needed here, Sutherland said, noting that one Chicago teacher only learned that 240,000 of his airlines points had been stolen because he received a basic confirmation email about their use. In another example, a man’s airline miles were stolen and fraudulently used to book rental cars in New York and Memphis.
Today, on the Lock and Code podcast with host David Ruiz, we speak with Sutherland about loyalty points theft— how it happens, what companies are doing to protect customers, and what people can do to stay safe.
“Some of us don’t even know how to access those points, right? Or we don’t even know we’re accumulating them, but the fraudsters do.”
Tune in today to listen to the full conversation.
Show notes and credits:
Intro Music: “Spellbound” by Kevin MacLeod (incompetech.com)
Licensed under Creative Commons: By Attribution 4.0 License
http://creativecommons.org/licenses/by/4.0/
Outro Music: “Good God” by Wowa (unminus.com)
Listen up—Malwarebytes doesn’t just talk cybersecurity, we provide it.
Protect yourself from online attacks that threaten your identity, your files, your system, and your financial well-being with our exclusive offer for Malwarebytes Premium for Lock and Code listeners.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.malwarebytes.com/blog/podcast/2026/09/loyalty-points-fraud-is-funding-hacker-holidays-lock-and-code-s07e18