Not sure where else to post this but figured this might help someone...
I typically use a VPN. A couple weeks ago, I booked a flight reward successfully. Very shortly after this, Aeroplan had emailed me asking me if I logged in from the US (I am Canadian). First time I've ever seen this kind of email from Aeroplan. The email was informative only ("If yes, you can safely ignore this message" type). Time stamps matched when I logged in to book my flight reward, so I ignored it.
Few hours after that, another email: "Your AEROPLAN account has been disabled due to suspicious activity detected by Air Canada. To access your account please click on the link below or visit Aircanada.com to reset your password."

Go figure.
Funnily enough, in the same email, they
recommend I "Use Two Factor Authentication". Ahhhh... youdontsay.jpg
Fast forward to present timeline, no activity on my Aeroplan account. I login and try to book another flight reward and on the fare review page, there was a message at the top (paraphrased): please contact Aeroplan to provide additional verification to book flight rewards.

. The error only displays on a desktop browser, my attempts to book on the mobile app just returned some generic error (along the lines of "we're unable to book your reward at this time" with no specificity). Additionally IIRC, the error only came up when trying to book flights involving partner metal. Flights on AC metal didnt' seem to come up with any errors on mobile or web.
Finally found the time to call in. The agent asked me a bunch of questions relating to my account when I told her I had a security block (account activity, address, etc.). After passing the verification, she had to "talk to the compliance department" to unblock my account. 10 minutes later, she returned to say it was done - and that I had to change my password as it was a requirement for the unblock (press X for doubt but whatever, not a huge deal).
Password changed, still couldn't book anything (same error on the fare review page), had some back and forth, tried another browser session for the second time and ... lo and behold, it worked, no more error message on the fare review page.
My conclusion from all this: it doesn't take very much to get your account in the crosshairs from the fraud and compliance department. 50k, I regularly fly both revenue and on points, have a premium cobranded CC.