# Going the Extra Mile: Travel Rewards Turn into Underground Currency


Cybercriminals have discovered a lucrative monetization avenue hidden in plain sight: the loyalty programs that travelers accumulate through everyday purchases and flights. Rather than targeting intellectual property or financial accounts, threat actors are increasingly compromising airline and hotel loyalty accounts to harvest accumulated miles and points—then converting them into discounted travel packages sold through underground marketplaces.


This emerging threat vector represents a shift in attacker economics. While traditional data breaches focus on extracting payment card information or personal identifiable information for fraud, the loyalty account compromise pipeline converts digital rewards directly into tangible travel commodities that bypass traditional financial tracking mechanisms.


## How the Monetization Pipeline Works


The attack chain begins where most cyber compromises do: credential theft. Threat actors obtain login credentials for airline and hotel loyalty accounts through phishing campaigns, credential stuffing attacks targeting weak password reuse, or data breaches that expose authentication materials. Once inside a loyalty account, the attacker faces a straightforward objective: extract accumulated miles or points before the account holder detects the intrusion.


The harvested rewards bypass traditional anti-fraud detection because they operate within legitimate loyalty program systems. An attacker with valid account access can redeem miles for flights, hotel stays, car rentals, and ancillary travel services without triggering the fraud alerts that normally flag unauthorized payment card transactions. From the loyalty program's perspective, the redemption appears as standard account activity.


Once the travel bookings are secured, the underground economy takes over. Threat actors list these reservations—often still in the original account holder's name—on dark web marketplaces and private channels. Buyers purchase flights and hotel stays at steep discounts, typically 30–60% below retail value. The attacker profits from the differential between the free rewards and the discounted sale price, while the buyer obtains genuine travel accommodations at bargain rates.


## The Scale of the Threat


According to threat intelligence research, loyalty account compromise has become systematic rather than opportunistic. Flare, a threat intelligence platform specializing in underground market monitoring, documented how cybercriminal collectives treat airline miles and hotel points as tradable commodities equivalent to currency. The volume suggests this has evolved beyond isolated incidents into organized, profit-driven operations.


The accessibility of loyalty accounts makes them attractive targets for criminal organizations of varying sophistication levels. Unlike financial fraud, which requires evading transaction monitoring systems and card issuer security protocols, loyalty account compromise requires only basic credential theft capabilities—well within reach of even novice threat actors. This low barrier to entry has democratized the attack, enabling diverse criminal groups to participate in the same supply chain.


Key risk factors that make loyalty accounts vulnerable:


  • Weak or reused passwords across multiple platforms
  • Insufficient multi-factor authentication adoption on loyalty accounts
  • Limited anomaly detection on redemption activities
  • Account recovery processes that don't require step-up verification
  • Lack of notification for large redemptions or account changes

  • ## Why Loyalty Programs Are Attractive Targets


    From an attacker economics perspective, loyalty account compromise offers advantages over traditional data theft. The rewards have established market value—an airline mile is worth approximately 1–2 cents on the open market, depending on the airline and redemption flexibility. A compromised account with 50,000 accumulated miles represents $500–1,000 in immediate liquidatable value.


    Critically, these transactions occur within the legitimate payment infrastructure controlled by the loyalty program operator. There are no chargebacks, payment card network disputes, or banking fraud investigators involved. The threat actor converts stolen rewards into cash-equivalent value without ever touching the financial system. From law enforcement's perspective, this creates jurisdictional complexity: a U.S.-based loyalty program compromise may be sold to buyers in Europe or Asia, cutting across multiple legal systems and regulatory boundaries.


    The underground markets where these stolen reservations are sold operate with their own reputation and escrow systems. Buyers can verify authenticity by checking the booking confirmation numbers and dates. Sellers maintain ratings based on delivery reliability. The market has professionalized around this commodity in ways that mirror legitimate travel resale platforms like Kayak or Hopper, except with no identity verification, no legitimate operator oversight, and no recourse for participants when disputes arise.


    ## Defensive Countermeasures


    Organizations operating loyalty programs and individual travelers can implement layered defensive strategies:


    For loyalty program operators:

  • Deploy behavioral anomaly detection on account activity, particularly unusual redemption patterns
  • Require step-up authentication (email confirmation, SMS verification, or push notification) before processing large redemptions
  • Implement velocity limits on redemptions within short time windows
  • Monitor for account access from new geographic locations
  • Maintain detailed audit logs of all loyalty account transactions for forensic investigation
  • Conduct regular threat intelligence gathering on underground markets specializing in travel commodities

  • For travelers and account holders:

  • Use unique, strong passwords for each loyalty program account
  • Enable multi-factor authentication on all loyalty accounts, prioritizing those with significant accumulated balances
  • Monitor account statements monthly for unauthorized activity
  • Configure email notifications for all redemption activities
  • Periodically review connected payment methods and contact information
  • Report unauthorized access immediately to both the loyalty program and relevant financial institutions

  • ## Broader Implications for Cybersecurity


    The emergence of loyalty account compromise as a significant threat vector illustrates how attacker monetization strategies evolve to circumvent existing security controls. As payment card fraud becomes increasingly difficult due to improved EMV technology and fraud detection, threat actors redirect their focus toward alternative assets with established market value but weaker defensive postures.


    This pattern—moving from difficult targets to softer alternatives—suggests that other reward-based systems, digital gift cards, and account credit balances may face similar pressure. Any digital asset with redemption value outside traditional banking infrastructure represents potential target expansion.


    ## HackWire Analysis


    The loyalty account compromise threat succeeds not because of advanced hacking techniques but because it exploits the gap between how tightly financial accounts are secured and how casually most people approach loyalty program credentials. A password breached from an obscure data leak becomes dramatically more valuable when applied across password reuse patterns to access a loyalty account holding thousands in accumulated rewards value.


    Organizations and consumers have trained themselves to view loyalty programs as low-stakes conveniences rather than financial assets requiring equivalent protection. The underground market evidence suggests threat actors have correctly identified this psychological misalignment as exploitable. Until loyalty program operators implement fraud detection comparable to financial institutions and individual account holders begin treating these credentials with financial seriousness, stolen miles will remain a reliable underground currency.