Go Back  FlyerTalk Forums > Miles&Points > Airlines and Mileage Programs > British Airways | Executive Club
Reload this Page >

300,000 miles stolen from my Avios BA account

Community
Wiki Posts
Search

300,000 miles stolen from my Avios BA account

Thread Tools
 
Search this Thread
 
Old Jan 17, 2017, 10:01 am
  #16  
A FlyerTalk Posting Legend
 
Join Date: Aug 2006
Location: Argentina
Posts: 40,210
Russians at it again....does Trump have a hotel in Hungary?
HIDDY is offline  
Old Jan 17, 2017, 10:25 am
  #17  
 
Join Date: Oct 2004
Location: York
Programs: Falconflyer Gold
Posts: 485
Seems to me there is a lack of security safeguards here because if there was a booking on the account, surely this should have generated an email to the account holder as a booking confirmation. I appreciate the hacker could have changed the user's email address but that action should have also generated an email to the original email address.
yorweb is offline  
Old Jan 17, 2017, 10:51 am
  #18  
 
Join Date: Dec 2013
Programs: QRPC Platinum, KFEG
Posts: 999
I can't believe BA still haven't implemented two factor authentication yet.
AAtticus is online now  
Old Jan 17, 2017, 11:09 am
  #19  
 
Join Date: Jul 2008
Location: London
Programs: BA Blue, Hyatt, Marriot, HHonors
Posts: 378
Avoid having the same Username/Password Combination on different websites. As soon as one account is hacked, chances are many more will be.
Getafix is offline  
Old Jan 17, 2017, 11:10 am
  #20  
 
Join Date: Oct 2013
Location: Dubai
Programs: BAEC Gold
Posts: 396
Originally Posted by Concerto
I do hope this gets sorted out. Frequent traveller accounts seem to be particularly prone to this these days. I keep an eye on mine at least twice a week. Watch out for your IHG Rewards accounts too, with their silly 1980s four digit passwords.
My IHG got hacked on Boxing Day, had just over 500,000 points spent on iTunes vouchers. I got them all back last week and a new account, thankfully. Their password system is shocking, only 10,000 combinations.
jamesreid978 is offline  
Old Jan 17, 2017, 11:51 am
  #21  
 
Join Date: Jul 2009
Posts: 561
If you use a web-accessible email (e.g. gmail), I'd also strongly encourage you to set up two-factor authentication - more info at https://www.google.com/landing/2step/

If someone gets into your email they can very easily get information such as your exec card number (and other FT programmes), giving them a treasure trove of information to exploit. They can also easily perform password resets on these accounts and very quickly cover their tracks by deleting notifications.
markle is offline  
Old Jan 17, 2017, 12:12 pm
  #22  
Community Director Emerita
 
Join Date: Oct 2000
Location: Anywhere warm
Posts: 33,745
I'm so sorry to hear about this. What a shock.

I use AwardWallet and check my balances every day. It's an early warning system should any of my points accounts get hacked.
SanDiego1K is offline  
Old Jan 17, 2017, 12:25 pm
  #23  
 
Join Date: May 2014
Posts: 740
Originally Posted by AAtticus
I can't believe BA still haven't implemented two factor authentication yet.
I can believe it. They're not renowned for having cutting edge IT. They should have done this instead of the terrible web site refresh.
ppp909 is offline  
Old Jan 17, 2017, 12:47 pm
  #24  
 
Join Date: Feb 2015
Location: London
Programs: BAEC Silver, SPG Gold, Hilton Gold, Melia Gold, Shangri-La Jade, BA Amex PP, Iberia+, Nandos Card
Posts: 1,523
Originally Posted by markle
If someone gets into your email they can very easily get information such as your exec card number (and other FT programmes), giving them a treasure trove of information to exploit. They can also easily perform password resets on these accounts and very quickly cover their tracks by deleting notifications.
This happened to me - hackers got my Amex details and email address and casually deleted nine confirmation emails about PlayStations and Xboxes they had ordered from my inbox...

if there is an option for TFA on your email, it is worth the minor inconvenience. Do it.
obduro is offline  
Old Jan 17, 2017, 1:44 pm
  #25  
 
Join Date: Oct 2015
Location: London
Programs: BAEC Gold, Hotels.com Gold
Posts: 576
Originally Posted by AAtticus
I can't believe BA still haven't implemented two factor authentication yet.
This.
CloudGazer is offline  
Old Jan 17, 2017, 4:32 pm
  #26  
FlyerTalk Evangelist
 
Join Date: Feb 2002
Location: Montreux CH
Programs: FB Platinum, M&M FTL, BA Blue
Posts: 11,620
Originally Posted by corporate-wage-slave
I am glad I'm not alone in my views on that.
I think even a monkey would agree with you. My opinion about the internet, anyway, is that it's totally crap technology that a child of 3 could hack. We desperately need something new.
Concerto is offline  
Old Jan 17, 2017, 5:27 pm
  #27  
 
Join Date: Jul 2016
Location: London
Programs: BA LtG, Flying Blue Plat
Posts: 274
It has happened to me too before, I wouldn't say that my password was weak or used by me on other websites, it's just one of those things. I keep my Avios between BA/IB and the Avios website incase it happens again and I need a last minute redemption or priority award.
ShuttleRunner is offline  
Old Jan 17, 2017, 10:37 pm
  #28  
 
Join Date: Oct 2009
Location: ARN
Programs: SK EBG, BAEC Gold, LH FTL, FBP, CCG, HH Diamond
Posts: 1,533
Originally Posted by Flyiboy
Sorry to hear this.. It is scary. This is why I change my password once a month. It may sound a bit on the OCD side but it works for me...
Absolutely no need to do that. Just use strong passwords and change them maybe once a year.

Originally Posted by AAtticus
I can't believe BA still haven't implemented two factor authentication yet.
I agree. Is there any airline/hotel chain that has done this yet?
agehall is offline  
Old Jan 17, 2017, 11:09 pm
  #29  
Original Poster
 
Join Date: Dec 2001
Posts: 3,181
Originally Posted by HIDDY
Russians at it again....does Trump have a hotel in Hungary?
LOL well at least sounds East Europeanish to me. Some Hungarian chain hotel in some resort town I never heard of. It seems they use miles for hotel stays a lot; not for air travel.

The hotel only charges $47 a night. 300,000 miles must have bought them quite a few rooms or they spent a long time there. They must have invited the whole family; aunts, uncles, cousins, grandmas, grandpas.
Bretteee is offline  
Old Jan 18, 2017, 2:08 am
  #30  
 
Join Date: Sep 2011
Location: ADL
Programs: Qantas Platinum One, Hilton Honors Diamond, Oneworld Emerald
Posts: 32
Originally Posted by Concerto
Watch out for your IHG Rewards accounts too, with their silly 1980s four digit passwords.
Hello Qantas.
HolmbyHills is offline  


Contact Us - Manage Preferences - Archive - Advertising - Cookie Policy - Privacy Statement - Terms of Service -

This site is owned, operated, and maintained by MH Sub I, LLC dba Internet Brands. Copyright © 2024 MH Sub I, LLC dba Internet Brands. All rights reserved. Designated trademarks are the property of their respective owners.