Effectively, it lastly occurred — I fell sufferer to one in every of my loyalty program accounts being hacked, particularly my Southwest Fast Rewards account. On Dec. 3, I obtained an e mail from Southwest at 9:30 p.m. EST confirming my resort reservation at Hampton Inn & Suites Kalamazoo-Oshtemo for a check-in date of Dec. 4 and a checkout date of Dec. 5.
The e-mail acknowledged that 17,100 Southwest factors had been deducted from my account to e book this resort. In line with TPG’s December 2024 valuations, that is about $240 in worth. Initially, I assumed this could be a phishing e mail rip-off attempting to coax me into clicking on the hyperlinks offered to steal data. Instantly, I logged into my Southwest account to verify if the factors had been deducted.
Sadly, sure, this hacker had used my hard-earned reward factors to e book a resort keep.
Listed below are the steps I took to get my factors again and how one can attempt to forestall hackers from stealing your factors and miles.
Associated: How one can shield your self towards rewards program knowledge breaches
What I did when my Southwest Fast Rewards account was hacked
After realizing that somebody had accessed my Fast Rewards account, I instantly modified my password to stop extra factors from getting used. Subsequent, I known as Southwest to tell the airline that my account had been hacked and that my factors had been used fraudulently.
As a result of it was late at night time, the Southwest consultant knowledgeable me that this was a Fast Rewards difficulty — she may solely help with flights and never resort reservations — so I would wish to name the telephone line for the loyalty program within the morning when it reopened.
Nevertheless, the Southwest rep advised me to name the resort on to allow them to know that this reservation was made as a result of my account had been hacked. Although it could not assist me get my factors again instantly into my account, it was price leaving a paper path of the steps taken to indicate that this was fraud.
Once I known as the resort straight, the entrance desk worker was extraordinarily apologetic. Although she couldn’t cancel the reservation on her finish, she left an in depth observe for her supervisor to present me a name within the morning so he may attempt to resolve the difficulty.
Day by day Publication
Reward your inbox with the TPG Day by day e-newsletter
Be a part of over 700,000 readers for breaking information, in-depth guides and unique offers from TPG’s consultants
Associated: How one can determine and stop bank card fraud
Although nothing additional may very well be carried out that night time to get my Southwest factors again, I spent the following few hours ensuring my loyalty program passwords had been up to date. Whereas some airways and resort packages have employed two-step authentication, others, corresponding to Southwest, haven’t but adopted go well with.
To present myself peace of thoughts, I made a decision to alter all of my passwords to attempt to mitigate the chance of my different accounts being hacked and my rewards being stolen utilizing my data.
The subsequent morning, I known as Southwest Fast Rewards and gave the lady an in depth description of what had occurred, explaining that I had instantly contacted Southwest, knowledgeable the airline of the account hack, known as the resort and altered my account password. The rep advised me that she can be submitting a report and that somebody from Southwest would comply with up with me through e mail concerning my factors. She famous a number of instances that it was a superb factor I had found the hack instantly, as some folks do not understand for months that they’ve rewards lacking from their account.
After I used to be carried out talking with the Southwest rep, the resort supervisor gave me a name to let me know that he had obtained the reserving observe and he can be canceling the reservation on his finish. As a result of this reservation was booked with factors via a 3rd social gathering, he couldn’t give me again my rewards, however once more, it confirmed Southwest {that a} paper path was being left to assist my case.
Southwest did give me my factors again, however …
On Dec. 4, I obtained an e mail from a Southwest Fast Rewards rep telling me that the airline takes “the safety of our members’ Fast Rewards accounts critically, and we shield our members from fraudulent exercise by fortifying your knowledge towards a breach.” The e-mail states that Southwest “requires members to enter a password previous to accessing any of their account data,” and so they encourage using a “sturdy password.”
The e-mail additionally cites Southwest’s phrases and circumstances, noting that the airline is “not answerable for unauthorized entry to a member’s account and won’t change stolen factors or awards.”
Nevertheless, as a “gesture of goodwill and one-time exception,” Southwest determined to refund me the 17,100 factors.
Except for being a Fast Rewards member, I additionally maintain the Southwest Fast Rewards® Plus Credit score Card. I am unsure if this truth was taken under consideration when my case was being reviewed.
Whereas I’m grateful that Southwest returned my reward factors, I am unable to assist however acknowledge that we reside in a digital age wherein hackers and scammers work endlessly to entry folks’s private account data. Even massive companies have fallen sufferer to those hacks. For Southwest to rely solely on one password and never an extra step to authenticate the consumer appears a bit behind the instances.
We reached out to Southwest with my expertise, and a spokesperson despatched us the next assertion:
Southwest is dedicated to defending our Clients’ accounts with complete cyber safety controls. We are going to proceed to reinforce our core know-how and have carried out a spread of proactive and responsive safety measures throughout our platforms.
It is price noting that Southwest is not alone right here, as a number of different airways — together with American and Frontier — haven’t got two-factor authentication choices for securing your loyalty account balances.
So, how am I attempting to guard my accounts within the wake of this hack?
Steps to guard your loyalty accounts to safeguard your factors and miles
Although these extra steps aren’t assured to guard your private data and loyalty accounts, they positive will not harm.
Change and replace your passwords
Whether or not you have been hacked or not, updating your password recurrently is a good suggestion, particularly if you have not carried out so in a very long time. Moreover, be sure that to have totally different passwords for every of your accounts. When you have one password (or a really related one) for each account, hackers might simply entry all of them.
Arrange two-step authentication (when attainable)
These days, many airline and resort loyalty packages supply two-step authentication to assist safe your account. This system will usually require an extra code, which shall be despatched through e mail, textual content or via an authentication app corresponding to Google Authenticator.
Get e mail and/or textual content alerts
Although nobody likes to be inundated with a bunch of emails and/or texts, it is a good suggestion to verify your communication preferences are up to date. Most packages will contact you when a reserving is made, your factors and miles are used or even when your contact data/profile has been up to date. This can enable you determine fraud early — which might make it simpler to resolve.
As a result of Southwest instantly notified me about my reserving — and since I am somebody who often checks my emails on my telephone — I may contact the correct events straight away, change my account password and resolve the difficulty.
Associated: My AAdvantage account was hacked: Here is what occurred and how one can shield your self
Backside line
A hacker lately redeemed greater than 17,000 of my Southwest Fast Rewards factors, although I used to be in a position to shortly take steps to get them again. Sadly, I’m not the primary — and will not be the final — factors and miles fanatic to fall sufferer to an account hack. Earlier this yr, TPG managing editor Clint Henderson had virtually 400,000 American Airways AAdvantage miles stolen from his account. Fortunately, he too received them again.
However as fraudsters proceed to get extra intelligent of their hacking strategies, it is best to be diligent and pay shut consideration to your private accounts. Although Southwest refunded me my factors, in response to their phrases, this was not assured and alternative of stolen factors is seemingly solely authorised on a case-by-case foundation. Subsequently, to make sure you do not fully lose out in your hard-earned rewards, take extra steps to safe your accounts.