Cybercriminals are increasingly targeting loyalty points programs, converting stolen points into real-world value for fraudulent purchases, including funding vacations. This emerging form of digital fraud leverages the fact that many consumers do not monitor their loyalty accounts with the same scrutiny applied to bank accounts.
Kim Sutherland, Global Head of Fraud and Identity at LexisNexis Risk Solutions, explained that loyalty points, often valued at about one cent per point, can represent significant sums. For instance, 100,000 airline points can be equivalent to $1,000 in the United States, with premium programs potentially offering even greater value.
The appeal for criminals lies in this direct monetary conversion and the relative lack of consumer vigilance. Unlike credit card numbers or personal identifying information, which require additional steps to monetize, loyalty points can be directly redeemed for goods and services, such as discounted hotel stays, flights, and rental cars.
Instances of this fraud include a Chicago teacher who discovered 240,000 airline points had been stolen only after receiving a confirmation email for their use. In another case, an individual's airline miles were fraudulently redeemed to book rental cars in New York and Memphis.
Sutherland highlighted that many individuals are unaware of the points they accumulate or how to access them, creating an opportunity for fraudsters who actively seek out these valuable assets. The theft of loyalty points allows criminals to fund various expenditures, essentially enabling them to take holidays at the expense of victims.






