FlyerTalk Forums - View Single Post - Account hacked, points spent
View Single Post
Old Oct 18, 2017, 3:34 pm
  #151  
FlyerTalker688786
Suspended
 
Join Date: Jul 2007
Posts: 4,477
Originally Posted by serpens
Since I can sign in using an email address or a member number, how does a new email address help secure the account? I might use the email address, but the hacker can just use the old member number.
In many hacking cases, the hacking of member account is linked to the hacking of email address. That is why victim was not able to see emails informing their change of action (e.g. pin reset or email address change).

However it is not saying that it is the same case of IHG. There is no concrete proof yet.

Yet, I must address that membership number is not enough for a hacker to get hold of your account. A PIN number and other information like email address, telephone number or full postal address is a must when you contact IHG to book award rooms. Change your email address to a complete new one would help IHG to flag its system and identify a potential hacker as the hacker is unlikely to learn your new email address so quickly. And an experience IHG customer service agent would be able to identify red flags for known compromised accounts.

IHG had not upgraded its PIN system yet. However, the customer service agents are very experienced by now on hacked account.

If your account is hacked and if you wish to keep your old number, you MUST provide a new email address that is totally different from the one you used before. This is no guarantee you would not be hacked again, but it would help IHG to add another layer of filter on your account.

Remember, the people who is selling your points or take advantages of your balance is not hackers themselves. Hackers profit from selling batches of information that contains names, membership numbers, emails, telephone numbers and addresses. The fraudsters bought these information and then took over the balance of your account. The fraudsters are not technologically advanced as the hackers so they could not and would not bother to try again once they notice you have changed your PIN and email address. If you have not changed to a new email address, the likelihood of them obtaining your email password is greater. Changing to a new email address do not stop them trying, but it does add additional layer of security.
FlyerTalker688786 is offline