# Going the Extra Mile: Travel Rewards Turn into Underground Currency
Cybercriminals have discovered a lucrative monetization avenue hidden in plain sight: the loyalty programs that travelers accumulate through everyday purchases and flights. Rather than targeting intellectual property or financial accounts, threat actors are increasingly compromising airline and hotel loyalty accounts to harvest accumulated miles and points—then converting them into discounted travel packages sold through underground marketplaces.
This emerging threat vector represents a shift in attacker economics. While traditional data breaches focus on extracting payment card information or personal identifiable information for fraud, the loyalty account compromise pipeline converts digital rewards directly into tangible travel commodities that bypass traditional financial tracking mechanisms.
## How the Monetization Pipeline Works
The attack chain begins where most cyber compromises do: credential theft. Threat actors obtain login credentials for airline and hotel loyalty accounts through phishing campaigns, credential stuffing attacks targeting weak password reuse, or data breaches that expose authentication materials. Once inside a loyalty account, the attacker faces a straightforward objective: extract accumulated miles or points before the account holder detects the intrusion.
The harvested rewards bypass traditional anti-fraud detection because they operate within legitimate loyalty program systems. An attacker with valid account access can redeem miles for flights, hotel stays, car rentals, and ancillary travel services without triggering the fraud alerts that normally flag unauthorized payment card transactions. From the loyalty program's perspective, the redemption appears as standard account activity.
Once the travel bookings are secured, the underground economy takes over. Threat actors list these reservations—often still in the original account holder's name—on dark web marketplaces and private channels. Buyers purchase flights and hotel stays at steep discounts, typically 30–60% below retail value. The attacker profits from the differential between the free rewards and the discounted sale price, while the buyer obtains genuine travel accommodations at bargain rates.
## The Scale of the Threat
According to threat intelligence research, loyalty account compromise has become systematic rather than opportunistic. Flare, a threat intelligence platform specializing in underground market monitoring, documented how cybercriminal collectives treat airline miles and hotel points as tradable commodities equivalent to currency. The volume suggests this has evolved beyond isolated incidents into organized, profit-driven operations.
The accessibility of loyalty accounts makes them attractive targets for criminal organizations of varying sophistication levels. Unlike financial fraud, which requires evading transaction monitoring systems and card issuer security protocols, loyalty account compromise requires only basic credential theft capabilities—well within reach of even novice threat actors. This low barrier to entry has democratized the attack, enabling diverse criminal groups to participate in the same supply chain.
Key risk factors that make loyalty accounts vulnerable:
## Why Loyalty Programs Are Attractive Targets
From an attacker economics perspective, loyalty account compromise offers advantages over traditional data theft. The rewards have established market value—an airline mile is worth approximately 1–2 cents on the open market, depending on the airline and redemption flexibility. A compromised account with 50,000 accumulated miles represents $500–1,000 in immediate liquidatable value.
Critically, these transactions occur within the legitimate payment infrastructure controlled by the loyalty program operator. There are no chargebacks, payment card network disputes, or banking fraud investigators involved. The threat actor converts stolen rewards into cash-equivalent value without ever touching the financial system. From law enforcement's perspective, this creates jurisdictional complexity: a U.S.-based loyalty program compromise may be sold to buyers in Europe or Asia, cutting across multiple legal systems and regulatory boundaries.
The underground markets where these stolen reservations are sold operate with their own reputation and escrow systems. Buyers can verify authenticity by checking the booking confirmation numbers and dates. Sellers maintain ratings based on delivery reliability. The market has professionalized around this commodity in ways that mirror legitimate travel resale platforms like Kayak or Hopper, except with no identity verification, no legitimate operator oversight, and no recourse for participants when disputes arise.
## Defensive Countermeasures
Organizations operating loyalty programs and individual travelers can implement layered defensive strategies:
For loyalty program operators:
For travelers and account holders:
## Broader Implications for Cybersecurity
The emergence of loyalty account compromise as a significant threat vector illustrates how attacker monetization strategies evolve to circumvent existing security controls. As payment card fraud becomes increasingly difficult due to improved EMV technology and fraud detection, threat actors redirect their focus toward alternative assets with established market value but weaker defensive postures.
This pattern—moving from difficult targets to softer alternatives—suggests that other reward-based systems, digital gift cards, and account credit balances may face similar pressure. Any digital asset with redemption value outside traditional banking infrastructure represents potential target expansion.
## HackWire Analysis
The loyalty account compromise threat succeeds not because of advanced hacking techniques but because it exploits the gap between how tightly financial accounts are secured and how casually most people approach loyalty program credentials. A password breached from an obscure data leak becomes dramatically more valuable when applied across password reuse patterns to access a loyalty account holding thousands in accumulated rewards value.
Organizations and consumers have trained themselves to view loyalty programs as low-stakes conveniences rather than financial assets requiring equivalent protection. The underground market evidence suggests threat actors have correctly identified this psychological misalignment as exploitable. Until loyalty program operators implement fraud detection comparable to financial institutions and individual account holders begin treating these credentials with financial seriousness, stolen miles will remain a reliable underground currency.