Go Back  FlyerTalk Forums > Miles&Points > Hotels and Places to Stay > Hilton | Hilton Honors
Reload this Page >

Consolidated "Hilton Honors Account Hacked" thread

Community
Wiki Posts
Search

Consolidated "Hilton Honors Account Hacked" thread

Thread Tools
 
Search this Thread
 
Old Feb 21, 2017, 3:17 am
  #271  
 
Join Date: Jan 2017
Programs: HH - Gold, BA - Blue
Posts: 188
Originally Posted by ceebee100
Loss prevention has closed your account for good and refuse to even consider reopening it. Maybe someone else has an idea that may help you.
To be fair, going off another recent thread here about loss prevention that isn't the be all and end all of the game.

You could consider going above loss prevention to the top and seeing what the bosses can do about it.
Orange.Man is offline  
Old Feb 21, 2017, 5:16 am
  #272  
 
Join Date: Feb 2013
Location: DCA
Posts: 7,769
Originally Posted by ceebee100
Sorry about your loss of points, but the first question that you will be asked by others is why did it take you almost 6 weeks to contact them after you received an email notification that your email address has been changed knowing that you did not make such a change? If you had immediately contacted them and said that you didn't make the change, things would probably have worked out much better for you in the end.
Exactly, and this isn't garden-variety victim-blaming. It would take a pretty large feat of good will for them to believe that you weren't complicit in the matter, given that you didn't pursue any recourse when the event actually happened, even after they gave you notice - which you acknowledge receiving.
arlflyer is offline  
Old Feb 21, 2017, 6:59 am
  #273  
FlyerTalk Evangelist
 
Join Date: Jun 2000
Location: Sunny SYDNEY!
Programs: UA Million Miler. (1.9M) Virgin Platinum. HH Diamond + SPG Gold
Posts: 32,330
New member, no location shown, strange and pretty implausible story.

Let me run it thru www.snopes.com!
ozstamps is offline  
Old Feb 21, 2017, 9:02 am
  #274  
Suspended
 
Join Date: Nov 1999
Posts: 24,153
Originally Posted by ceebee100
Sorry about your loss of points, but the first question that you will be asked by others is why did it take you almost 6 weeks to contact them after you received an email notification that your email address has been changed knowing that you did not make such a change? If you had immediately contacted them and said that you didn't make the change, things would probably have worked out much better for you in the end.
As it stands now, I don't see any other recourse for you. Loss prevention has closed your account for good and refuse to even consider reopening it. Maybe someone else has an idea that may help you.
+1 , the not contacting them after getting their email will be the knife in the OPs back. The OP can try going up the ladder but if the pts were earned from the CCs and not stays then I doubt HH will be willing to do anything If the OP had Diamond or Gold from stays then maybe a bone will thrown their way. Too much info not supplied to make a qualified guess
craz is offline  
Old Feb 21, 2017, 9:18 pm
  #275  
 
Join Date: Jul 2016
Posts: 4
Originally Posted by ceebee100
Sorry about your loss of points, but the first question that you will be asked by others is why did it take you almost 6 weeks to contact them after you received an email notification that your email address has been changed knowing that you did not make such a change? If you had immediately contacted them and said that you didn't make the change, things would probably have worked out much better for you in the end.
As it stands now, I don't see any other recourse for you. Loss prevention has closed your account for good and refuse to even consider reopening it. Maybe someone else has an idea that may help you.

I didn't found out about the email until I found an email notification in December. It wasn't that I discovered the email in October and did nothing about for 6 weeks.

Lost Prevention should have all the logs and activities of the account. Couldn't the Lost Prevention look at the activity and make a reasonable judgment that the account was hacked?

Originally Posted by ozstamps
New member, no location shown, strange and pretty implausible story.

Let me run it thru www.snopes.com!
Sorry, but this comment contributes nothing. But I understand you're skeptical because of my profile. Some people would just create new profile to create story or troll.

Last edited by Canarsie; Aug 7, 2017 at 10:58 am Reason: Consolidation.
jcao is offline  
Old Feb 22, 2017, 6:34 am
  #276  
FlyerTalk Evangelist
 
Join Date: Aug 2011
Location: Barcelona, London, on a plane
Programs: BA Silver, TK E+, AA PP, Hyatt Globalist, Marriott LT Plat, Hilton Diamond
Posts: 13,033
Originally Posted by jcao

Lost Prevention should have all the logs and activities of the account. Couldn't the Lost Prevention look at the activity and make a reasonable judgment that the account was hacked?
What do you expect log-in activity to say? Log-ins from different parts of the world? Many Honors members travel frequently and legitimately use VPNs, same as the criminals. They probably also get millions of brute force log-in requests daily, so digging through that to find one Honors member is unlikely to be productive.

You also don't mention whether you are a long-time member with lots of stays over the years, or whether you only accumulated points through recent credit card churning and didn't even get around to spending the points on yourself. All of these things help paint a picture of whether you are a regular guest who just got hacked, or whether you are somebody who Honors doesn't mind having as an ex-member.

And, for what it's worth, Flyertalk tends to be much more sympathetic towards frequent, long-time posters as opposed to people whose first post is a complaint against a company. There are dozens of sign-ups whose first and only post is to rant about something.
craigthemif is offline  
Old Feb 22, 2017, 7:51 am
  #277  
 
Join Date: Feb 2014
Posts: 921
Originally Posted by jcao
I didn't found out about the email until I found an email notification in December. It wasn't that I discovered the email in October and did nothing about for 6 weeks.

Lost Prevention should have all the logs and activities of the account. Couldn't the Lost Prevention look at the activity and make a reasonable judgment that the account was hacked?
How do you know what the hacker did to access your profile? If your login and security info is easy to guess, they could've simply gotten into your account after one or two attempts. That sort of activity wouldn't indicate anything unusual.

If you didn't log in for several weeks, yet the other person logged in several times from the same system/phone/IP address, it would make it appear that YOUR login was the one that is unusual, and you could be the hacker!
jeffandnicole is offline  
Old Jun 26, 2017, 3:34 pm
  #278  
 
Join Date: Jul 2011
Posts: 8
Exclamation HHonors Account Hacked and Miles Stolen

Woke up this morning to an email that I had transferred all but 9,000 of my points to someone else's HHonors account. They must have gotten my username / password somehow. I am pretty on the ball when it comes to online security so I'm a bit concerned. Diamond desk rep said it would take 7-10 business days to get the points back.
nedyah700 is offline  
Old Jun 27, 2017, 5:21 am
  #279  
 
Join Date: Jul 2015
Programs: HH Diamond, HGVC, WN RR, National Exec, Avis Preferred
Posts: 1,055
Originally Posted by nedyah700
Woke up this morning to an email that I had transferred all but 9,000 of my points to someone else's HHonors account. They must have gotten my username / password somehow. I am pretty on the ball when it comes to online security so I'm a bit concerned. Diamond desk rep said it would take 7-10 business days to get the points back.
It could also be a case of someone at Hilton fat fingering an HH# for a legitimate transfer for another customer. A couple of weeks ago I was on the phone with a rep for my credit union trying to set up an online id for an account I have with my mother. I gave her the login I wanted to use and she set it up, gave me a temp password and when I went to create a permanent password someone else's phone number came up in the profile. I questioned what the phone number was and she realized that she had set up the id on someone else's account. It's crazy that I was that close to logging into someone else's bank account.
birdiedouble is offline  
Old Jun 27, 2017, 6:05 am
  #280  
 
Join Date: Jun 2005
Location: DTW/FNT
Programs: Delta (nee NW), Hilton Diamond. IHG (PT)
Posts: 4,823
Originally Posted by ozstamps
New member, no location shown, strange and pretty implausible story.

Let me run it thru www.snopes.com!
I agree -- particularly because 150k points are only good for something like 3 to 5 free nights.

Bob H
BobH is offline  
Old Jun 27, 2017, 4:22 pm
  #281  
 
Join Date: Jul 2000
Location: The Villages, Florida
Posts: 1,334
Hacked - points withdrawn

I am so frustrated. Knew you guys would understand. Over 100k points withdrawn in three transactions in one day. They changed my email and phone number under profile. I now have a case number, but they won't have any answers for several days. I discovered it when I logged in to book a stay at the beach.
fscher is offline  
Old Jun 27, 2017, 7:36 pm
  #282  
 
Join Date: Apr 2017
Posts: 8
Sorry to hear about your experience, particularly with an expectation to book.

One point to consider to minimize the chances of this happening again is to ensure the machines you use to log into your account have up to date internet security suites (typically anti-virus plus anti-malware plus extras). In addition, also consider the "strength" of your password - is it something that is fairly easy to figure out from the perspective of a hacker with bad intentions? Finally, always be wary of someone trying to trick you into giving up your credentials by spoofing a fake Hilton email or website.
nullchain is offline  
Old Jun 28, 2017, 7:09 am
  #283  
 
Join Date: Feb 2014
Posts: 921
Originally Posted by fscher
I am so frustrated. Knew you guys would understand. Over 100k points withdrawn in three transactions in one day. They changed my email and phone number under profile. I now have a case number, but they won't have any answers for several days. I discovered it when I logged in to book a stay at the beach.
BTW, loved the signature fscher! Did you see the news report the other day regarding the meth lab and golf cart chop shop ring that was broken up at the Villages? Those retirees know how to live it up down there!! Haha
jeffandnicole is offline  
Old Jul 9, 2017, 6:20 am
  #284  
 
Join Date: Mar 2011
Location: PHL
Programs: US; AA; UA; Hilton Gold; Club Carlson Gold; IHG Platinum;
Posts: 388
Woke up yesterday morning to find a message that my HHonors email was changed at 2AM. Logged in to my account and, surely enough, my points balance decreased by 233,000 but no new activities were listed yet. Called customer service and they opened up 2 tickets (apparently there were 2 separate points.com transfers). I was told that someone will get in touch with me within 2-3 days. We'll see what happens.

It's strange that my password has not been changed and not all available points have been transferred out. I am wondering if this might be an inside job.
Kpoxa is offline  
Old Jul 21, 2017, 8:38 am
  #285  
 
Join Date: Dec 2016
Posts: 246
Originally Posted by Kpoxa
Woke up yesterday morning to find a message that my HHonors email was changed at 2AM. Logged in to my account and, surely enough, my points balance decreased by 233,000 but no new activities were listed yet. Called customer service and they opened up 2 tickets (apparently there were 2 separate points.com transfers). I was told that someone will get in touch with me within 2-3 days. We'll see what happens.

It's strange that my password has not been changed and not all available points have been transferred out. I am wondering if this might be an inside job.
Your password is not needed to gain access to your Honors account and the points in it. Anybody we can call, give your name, plus two of: your phone number; your email or your honors account can do what they want with your account.

The bad guys are doing their happy dance at the prospect that soon Honors points will be able to be used for anything on amazon.com and there do not appear to be any plans to make security on Honors accounts any more robust.
retiredfromhilton is offline  


Contact Us - Manage Preferences - Archive - Advertising - Cookie Policy - Privacy Statement - Terms of Service -

This site is owned, operated, and maintained by MH Sub I, LLC dba Internet Brands. Copyright © 2024 MH Sub I, LLC dba Internet Brands. All rights reserved. Designated trademarks are the property of their respective owners.