Thieves Skipped Your Credit Card and Went Straight for Your Airline Miles — editorial illustration

read receipts

Thieves Skipped Your Credit Card and Went Straight for Your Airline Miles

The balance you check twice a year is the one criminals check every day — and cashing it out rarely trips a single alarm.

·3 min read

A hacked American Airlines AAdvantage account with a healthy mileage balance sells on fraud forums for a fraction of what those miles are worth, and that discount is the whole scam. Miles feel like Monopoly money to you. To someone who steals them, they're inventory.

Here's the uncomfortable math. Your credit card has a fraud department that texts you when a charge looks weird, a chargeback process, and a legal cap on your liability. Your loyalty account has almost none of that. When someone drains 200,000 Hilton points into a booking or transfers your miles to a partner program, no bank calls. The airline doesn't freeze the account the way Chase freezes a card. The theft looks exactly like normal customer behavior, because redeeming points is normal customer behavior.

That gap is why "confirm your rewards account" is having a moment in your inbox.

Why the least-guarded balance is the most wanted one

Stolen loyalty accounts trade briskly on underground markets, and researchers have documented the pricing. Comparitech's ongoing dark-web index has tracked hacked accounts across categories, with rewards and airline logins going for a few dollars up to a few dozen depending on balance. Cheap to buy, easy to launder into flights, hotel nights, gift cards, or resale points that get moved through third-party brokers before anyone notices.

The scale is not theoretical. The FTC logged more than 330,000 phishing-related fraud reports in a single recent year, and "reactivate your account" lures are a workhorse of that category precisely because they don't need to look like a bank. A note about expiring miles or a "suspicious login on your rewards profile" gets clicked by people who'd never click a fake wire transfer. You're relaxed about points. That relaxation is the exploit.

And airlines have been slow. It took years — and a run of account takeovers — before major U.S. carriers pushed multi-factor authentication and put friction on partner transfers. Delta, United, and American all now offer or require stronger login protections, but a lot of accounts still sit behind a password you reused in 2016.

The tells, because there always are tells

A real loyalty email almost never asks you to "verify" by clicking through to a login page. When one lands, do three boring things:

  • Check the actual sender, not the display name. "American Airlines" in bold means nothing; the address behind it does. A message that fails SPF, DKIM, or DMARC alignment — the three checks that prove a domain really sent a mail — is a forgery no matter how clean the logo looks. This is exactly the layer xmail reads before you ever see the message.
  • Never log in from the email. Open a new tab, type the airline's address yourself, and check your balance there. If the "urgent" problem doesn't exist on the real site, it doesn't exist.
  • Turn on MFA and lock transfers. The single most valuable thing you can do is make your miles un-moveable without a second factor.

The thing worth sitting with: you've been trained for a decade to guard the card and ignore the points. The people phishing you know that better than you do. They're not after the number in your wallet. They're after the number you forgot you had.

FTC phishing fraud reports in a single year

Sources

  1. FTC Consumer Sentinel — Phishing and imposter fraud report volumes
  2. Comparitech — Dark-web pricing index for hacked accounts including rewards logins
  3. American Airlines AAdvantage — AAdvantage account and security options

← All articles

Thieves Skipped Your Credit Card and Went Straight for Your Airline Miles · xmail