Effectively, it lastly occurred — I fell sufferer to considered one of my loyalty program accounts being hacked, particularly my Southwest Fast Rewards account. On Dec. 3, I acquired an e-mail from Southwest at 9:30 p.m. EST confirming my lodge reservation at Hampton Inn & Suites Kalamazoo-Oshtemo for a check-in date of Dec. 4 and a checkout date of Dec. 5.
The e-mail acknowledged that 17,100 Southwest factors had been deducted from my account to ebook this lodge. Based on TPG’s December 2024 valuations, that is about $240 in worth. Initially, I believed this is perhaps a phishing e-mail rip-off attempting to coax me into clicking on the hyperlinks offered to steal info. Instantly, I logged into my Southwest account to verify if the factors had been deducted.
Sadly, sure, this hacker had used my hard-earned reward factors to ebook a lodge keep.
Listed here are the steps I took to get my factors again and how one can attempt to stop hackers from stealing your factors and miles.
Associated: How you can shield your self towards rewards program knowledge breaches
What I did when my Southwest Fast Rewards account was hacked
After realizing that somebody had accessed my Fast Rewards account, I instantly modified my password to stop further factors from getting used. Subsequent, I known as Southwest to tell the airline that my account had been hacked and that my factors had been used fraudulently.
As a result of it was late at night time, the Southwest consultant knowledgeable me that this was a Fast Rewards problem — she might solely help with flights and never lodge reservations — so I would want to name the cellphone line for the loyalty program within the morning when it reopened.
Nonetheless, the Southwest rep advised me to name the lodge on to allow them to know that this reservation was made as a result of my account had been hacked. Although it will not assist me get my factors again instantly into my account, it was value leaving a paper path of the steps taken to indicate that this was fraud.
Once I known as the lodge straight, the entrance desk worker was extraordinarily apologetic. Although she couldn’t cancel the reservation on her finish, she left an in depth notice for her supervisor to provide me a name within the morning so he might attempt to resolve the problem.
Day by day E-newsletter
Reward your inbox with the TPG Day by day publication
Be a part of over 700,000 readers for breaking information, in-depth guides and unique offers from TPG’s consultants
Associated: How you can establish and forestall bank card fraud
Although nothing additional may very well be finished that night time to get my Southwest factors again, I spent the subsequent few hours ensuring my loyalty program passwords had been up to date. Whereas some airways and lodge packages have employed two-step authentication, others, equivalent to Southwest, haven’t but adopted swimsuit.
To offer myself peace of thoughts, I made a decision to alter all of my passwords to attempt to mitigate the danger of my different accounts being hacked and my rewards being stolen utilizing my info.
The subsequent morning, I known as Southwest Fast Rewards and gave the lady an in depth description of what had occurred, explaining that I had instantly contacted Southwest, knowledgeable the airline of the account hack, known as the lodge and adjusted my account password. The rep advised me that she could be submitting a report and that somebody from Southwest would observe up with me by way of e-mail concerning my factors. She famous a number of occasions that it was factor I had found the hack instantly, as some individuals do not realize for months that they’ve rewards lacking from their account.
After I used to be finished talking with the Southwest rep, the lodge supervisor gave me a name to let me know that he had acquired the reserving notice and he could be canceling the reservation on his finish. As a result of this reservation was booked with factors by way of a 3rd social gathering, he couldn’t give me again my rewards, however once more, it confirmed Southwest {that a} paper path was being left to assist my case.
Southwest did give me my factors again, however …
On Dec. 4, I acquired an e-mail from a Southwest Fast Rewards rep telling me that the airline takes “the safety of our members’ Fast Rewards accounts significantly, and we shield our members from fraudulent exercise by fortifying your knowledge towards a breach.” The e-mail states that Southwest “requires members to enter a password previous to accessing any of their account info,” and so they encourage the usage of a “sturdy password.”
The e-mail additionally cites Southwest’s phrases and situations, noting that the airline is “not answerable for unauthorized entry to a member’s account and won’t change stolen factors or awards.”
Nonetheless, as a “gesture of goodwill and one-time exception,” Southwest determined to refund me the 17,100 factors.
Except for being a Fast Rewards member, I additionally maintain the Southwest Fast Rewards® Plus Credit score Card. I am undecided if this truth was taken into consideration when my case was being reviewed.
Whereas I’m grateful that Southwest returned my reward factors, I am unable to assist however acknowledge that we stay in a digital age through which hackers and scammers work endlessly to entry individuals’s private account info. Even huge companies have fallen sufferer to those hacks. For Southwest to rely solely on one password and never an extra step to authenticate the person appears a bit behind the occasions.
We reached out to Southwest with my expertise, and a spokesperson despatched us the next assertion:
Southwest is dedicated to defending our Clients’ accounts with complete cyber safety controls. We’ll proceed to reinforce our core know-how and have carried out a spread of proactive and responsive safety measures throughout our platforms.
It is value noting that Southwest is not alone right here, as a number of different airways — together with American and Frontier — haven’t got two-factor authentication choices for securing your loyalty account balances.
So, how am I attempting to guard my accounts within the wake of this hack?
Associated: Understanding 3D bank card safety and the way it might have an effect on your journeys to different international locations
Steps to guard your loyalty accounts to safeguard your factors and miles
Although these further steps aren’t assured to guard your private info and loyalty accounts, they positive will not harm.
Change and replace your passwords
Whether or not you have been hacked or not, updating your password repeatedly is a good suggestion, particularly if you have not finished so in a very long time. Moreover, be sure that to have totally different passwords for every of your accounts. You probably have one password (or a really related one) for each account, hackers might simply entry all of them.
Arrange two-step authentication (when potential)
These days, many airline and lodge loyalty packages supply two-step authentication to assist safe your account. This system will usually require an extra code, which might be despatched by way of e-mail, textual content or by way of an authentication app equivalent to Google Authenticator.
Get e-mail and/or textual content alerts
Although nobody likes to be inundated with a bunch of emails and/or texts, it is a good suggestion to verify your communication preferences are up to date. Most packages will contact you when a reserving is made, your factors and miles are used or even when your contact info/profile has been up to date. It will allow you to establish fraud early — which might make it simpler to resolve.
As a result of Southwest instantly notified me about my reserving — and since I am somebody who regularly checks my emails on my cellphone — I might contact the correct events straight away, change my account password and resolve the problem.
Associated: My AAdvantage account was hacked: Here is what occurred and how one can shield your self
Backside line
A hacker just lately redeemed greater than 17,000 of my Southwest Fast Rewards factors, although I used to be in a position to rapidly take steps to get them again. Sadly, I’m not the primary — and will not be the final — factors and miles fanatic to fall sufferer to an account hack. Earlier this yr, TPG managing editor Clint Henderson had virtually 400,000 American Airways AAdvantage miles stolen from his account. Fortunately, he too obtained them again.
However as fraudsters proceed to get extra intelligent of their hacking strategies, it is best to be diligent and pay shut consideration to your private accounts. Although Southwest refunded me my factors, in keeping with their phrases, this was not assured and substitute of stolen factors is seemingly solely authorised on a case-by-case foundation. Subsequently, to make sure you do not utterly lose out in your hard-earned rewards, take further steps to safe your accounts.