Minimize your digital risk by detecting data loss, securing your online brand, and reducing your attack surface.
A powerful, easy-to-use search engine that combines structured technical data with content from the open, deep, and dark web.
Digital Risk Protection
Read our new practical guide to reducing digital risk.
New report recognizes Digital Shadows for strongest current offering, strategy, and market presence of 14 vendors profiled
Read Full Report
Reward program fraud has been rising in recent years across the aviation industry as well as the entire transportation sector. Some experts theorize that because Europay, Mastercard and Visa (EMV) chip technology has made physical credit card fraud more difficult, it has instead led to the global rise of reward point theft.
A major airline recently needed further expertise in identifying which cyber threats to prioritize, where to monitor for leaked intellectual property, and how to access hard-to-reach areas like the dark web without adding staff to their IT and security team. What they found was more than 300 compromised reward accounts posted for sale online.
Loyalty points are almost like cash, used not only for airline travel and rental cars but also for merchandise, gift cards, and live entertainment. Although reward accounts contain sensitive data like name, address, credit card, and even password numbers, they can be overlooked and even forgotten by customers over time. Account owners may not always be vigilant in monitoring accounts for suspicious activity – an easy win in cybercriminals’ minds.
Figure 1: Wall Street marketplace – user offering flight discounts
Password hygiene can also be lax, with reward account passwords shared across family members or reused by customers across several accounts. The many data breaches that have previously occurred likely mean that customer email addresses and passwords are already posted for sale online. Reward program thefts and prosecutions have rarely been publicized by airlines, although that is changing as seen by the notable prosecution of a college student recently for award point theft as a more public deterrent.
Cybercriminals use a variety of techniques to compromise and monetize stolen reward accounts. They can resell the account owner’s fully-vetted identity, or sell the reward points themselves. There are hundreds of criminal locations across the open, deep, and dark web that offer user account credentials for hotel and airline points.
Figure 2: Screenshot from Digital Shadows SearchLight™ – Forum post offering airline loyalty points and accounts
Here are some ways reward fraud occurs:
Want to see how this airline found the 300+ compromised reward accounts posted for sale online? See how Digital Shadows SearchLight™ enables organizations to mitigate this type of risk: Test Drive SearchLight™ Free Here.
To learn more about identifying which cyber threats to prioritize, where to monitor for leaked intellectual property, and how to access hard-to-reach areas like the dark web, subscribe to our newsletter here.