I had this happen several years ago (no points were redeemed) but out of an abundance of caution I added a PIN code to my account. It's not 100% foolproof, as you could still book stays via the web, but you can't do transfers to other programs or purchase products with points. I have to call and provide the PIN for those types of transactions.