A question for the more tech-savvy: Unless and until BA implement 2-factor verification for log-in, can having 2-factor verification on one's email account at least be some help here? Most of the schemes posters are describing seem to involve also accessing the user's email account. I'm assuming this would be harder for folks, like me, who have set up 2-factor on our gmail or other service.
Anyway, after the stories I've seen posting here, I've now taken to regularly checking my points balance -- which at least is quick to do via the app -- to have a shot at catching shenanigans earlier.