Go Back  FlyerTalk Forums > Miles&Points > Hotels and Places to Stay > Hilton | Hilton Honors
Reload this Page >

HHonors Points Stolen Through Amazon.com

Community
Wiki Posts
Search

HHonors Points Stolen Through Amazon.com

Thread Tools
 
Search this Thread
 
Old Aug 4, 2019, 8:15 am
  #121  
Hilton Contributor Badge
 
Join Date: Sep 2015
Location: flyover country
Posts: 2,435
Originally Posted by Westcoaster
I noticed that the wording on the setup screen said "Choose how you'd like to receive verification codes, and we'll send you one whenever we need to confirm your identity...." (bolding mine.) So the question becomes under what circumstances do they send the code?
The ability to enroll in 2FA appeared on my last login, so I signed up. Immediately, Hilton asked for the code that it sent. It seemed odd that Hilton would want to confirm my identity while I'm logged in. Perhaps Hilton wanted to confirm that I could receive the code, but at that point, I couldn't see how to back out if I couldn't get the code.

And another thing. I needed to type six digits into six boxes, one at a time. Compare this to the procedure at Chase: Chase sends a code, I copy and paste it, and I'm done. No mistyping a number, no fuss. It's as if Hilton went out of the way to be user-hostile—although that seems to be the philosophy of its revamped web site.
serpens is offline  
Old Aug 4, 2019, 2:36 pm
  #122  
 
Join Date: Aug 2002
Location: NYC
Posts: 335
Originally Posted by Westcoaster
Good question. This 2FA isn't behaving like the 2FA systems used by my financial institutions, email, etc. I keep going back to the wording I quoted before:

"Choose how you'd like to receive verification codes, and we'll send you one whenever we need to confirm your identity...."

They haven't told us their criteria for using the code. It would be nice to hear from someone who has been asked for the code to verify that it does indeed get triggered by something.
I have tried without success to trigger 2FA:
  • 4 internet service providers
  • 3 devices (with cleaned browser caches)
  • 2 foreign countries via VPN (Netherlands and Hong Kong)
The only time 2FA has appeared was during setup.
Westcoaster likes this.
Petdog is offline  
Old Aug 4, 2019, 6:52 pm
  #123  
 
Join Date: Feb 2006
Posts: 1,065
Originally Posted by Petdog
I have tried without success to trigger 2FA:
  • 4 internet service providers
  • 3 devices (with cleaned browser caches)
  • 2 foreign countries via VPN (Netherlands and Hong Kong)
The only time 2FA has appeared was during setup.
Try this:

1. Login to your account
2. Under MY PROFILE, you should see PERSONAL INFORMATION. Click it
3. You should see ENHANCED SECURITY and the ability to add 2 Factor Authentication

Good Luck.
diesteldorf is offline  
Old Aug 4, 2019, 7:42 pm
  #124  
 
Join Date: May 2005
Posts: 4,872
You misread the post. 2FA already enabled. The issue for many of us is triggering.
Petdog likes this.
smmrfld is offline  
Old Aug 5, 2019, 7:31 am
  #125  
 
Join Date: Feb 2006
Posts: 1,065
Originally Posted by smmrfld
You misread the post. 2FA already enabled. The issue for many of us is triggering.
My apologies, I definitely misread. After your comment, I checked my own account and was unable to get secondary verification to activate.

Thanks for the reply.
diesteldorf is offline  
Old Aug 5, 2019, 9:59 am
  #126  
 
Join Date: May 2007
Location: Seattle area
Programs: Peasant at large
Posts: 595
Couldn't find anything on hilton.com on what triggers 2FA. Not all implementations, including some banks', trigger 2FA at login. They trigger on specific events/actions deemed impactful. Has anyone with Hilton 2FA enabled tried to change/add/remove email/phone/address, use points (redeem for stay or transfer), change password, etc...? If none of those trigger 2FA then it's just for show and someone with media contacts should report them.
strickerj likes this.
crunchie is offline  
Old Aug 5, 2019, 10:05 am
  #127  
 
Join Date: Aug 2002
Location: NYC
Posts: 335
Originally Posted by crunchie
Has anyone with Hilton 2FA enabled tried to change/add/remove email/phone/address, use points (redeem for stay or transfer), change password, etc...? If none of those trigger 2FA then it's just for show and someone with media contacts should report them.
Address change: 2FA not triggered
Email add/switch primary/remove: 2FA not triggered
Password change: 2FA not triggered
Sisosig likes this.
Petdog is offline  
Old Aug 5, 2019, 12:43 pm
  #128  
 
Join Date: Sep 2006
Posts: 376
Checked again today - last time I looked I wasn't offered 2FA - saw it today and it was offered, enrolled.

As a side note, I would tend to think that changing BOTH your username and your password SHOULD offer a bit more protection - as it appears point stealing is still underway.
smithrh is offline  
Old Aug 5, 2019, 8:57 pm
  #129  
 
Join Date: Aug 2008
Location: MCO
Programs: DL-DM/1MM, HILTON-DIA, .HYATT-DIA/GLOB , IHG-PLT,HERTZ 5*, NATIONAL ES
Posts: 8,691
Originally Posted by Finkface
How do you know that it was an Amazon redemption then? If you never received any emails saying the points were used and the activity doesn’t show in your account, how do you know this is what happened?
Basically what happened was that I was having some issues logging in, and was not receiving the email for a password reset. I reached out via chat on the Hilton site and was eventually able to change the email account so that I could receive the link on my work email. Once I logged in I quickly noticed the points were missing, but there was not activity showing where they had gone, so I inquired with support. They informed me that the points were used for Amazon purchases. I find it odd that they can be used and not show in the activity of the account... I used to watch the account much closer, but I am off the road most of the time since I started a business.

I am assured they will replace the points, but it sounds like a nightmare to push them to do so.. Hoping my luck is a little better......

I miss this community as I was always in the know when I traveled thanks to you all.
strickerj likes this.
Crazyhotelguy is offline  
Old Aug 5, 2019, 9:11 pm
  #130  
 
Join Date: Aug 2008
Location: MCO
Programs: DL-DM/1MM, HILTON-DIA, .HYATT-DIA/GLOB , IHG-PLT,HERTZ 5*, NATIONAL ES
Posts: 8,691
Originally Posted by Crazyhotelguy
Basically what happened was that I was having some issues logging in, and was not receiving the email for a password reset. I reached out via chat on the Hilton site and was eventually able to change the email account so that I could receive the link on my work email. Once I logged in I quickly noticed the points were missing, but there was not activity showing where they had gone, so I inquired with support. They informed me that the points were used for Amazon purchases. I find it odd that they can be used and not show in the activity of the account... I used to watch the account much closer, but I am off the road most of the time since I started a business.

I am assured they will replace the points, but it sounds like a nightmare to push them to do so.. Hoping my luck is a little better......

I miss this community as I was always in the know when I traveled thanks to you all.

Just to update, As I was typing my reply here, I received an email stating that the fraud department had verified my case and returned the points to the account. I am very much relieved and hope this does not happen to anyone else...

I appreciate the quick resolution from Hilton. It means a lot.
serfty and strickerj like this.
Crazyhotelguy is offline  
Old Aug 6, 2019, 4:03 pm
  #131  
 
Join Date: Oct 2000
Location: Seattle WA, USA
Programs: Hilton Diamond, Marriott LT Plat, AS Lounge
Posts: 3,478
Originally Posted by crunchie
Couldn't find anything on hilton.com on what triggers 2FA. Not all implementations, including some banks', trigger 2FA at login. They trigger on specific events/actions deemed impactful. Has anyone with Hilton 2FA enabled tried to change/add/remove email/phone/address, use points (redeem for stay or transfer), change password, etc...? If none of those trigger 2FA then it's just for show and someone with media contacts should report them.
Yeah, if they would at least request the code before allowing a points redemption/transfer it would help with the Amazon issue.
Westcoaster is offline  
Old Aug 7, 2019, 10:14 am
  #132  
 
Join Date: Sep 2006
Posts: 376
Originally Posted by Westcoaster
Yeah, if they would at least request the code before allowing a points redemption/transfer it would help with the Amazon issue.
Or the Amazon point stealing is an inside job that they want to collect more data on before dropping the hammer.

One can dream...
Westcoaster likes this.
smithrh is offline  
Old Aug 8, 2019, 10:34 am
  #133  
 
Join Date: Oct 2001
Location: SJC
Programs: AA 2MM PLT, HH Gold, Marriott Silver
Posts: 612
FYI, it's still happening - lost (temporarily, I hope) over 500k points overnight with the usual emails, used for an Amazon redemption. I've contacted customer support, changed my password and enabled 2FA but it sounds like the latter isn't actually being used for anything.
JHunter is offline  
Old Aug 8, 2019, 11:42 am
  #134  
 
Join Date: Sep 2006
Posts: 376
Changed my username - 2FA was not invoked. Ugh.

Now - if there's theft from my account, it's likely from the inside. New password, new (orthogonal and unique) username, and 2FA enabled.
smithrh is offline  
Old Aug 8, 2019, 2:15 pm
  #135  
 
Join Date: Sep 2006
Posts: 376
Update - called the Diamond Desk to make a reservation today and they did use 2FA while on the call, and is was very quick.
smithrh is offline  


Contact Us - Manage Preferences - Archive - Advertising - Cookie Policy - Privacy Statement - Terms of Service -

This site is owned, operated, and maintained by MH Sub I, LLC dba Internet Brands. Copyright © 2024 MH Sub I, LLC dba Internet Brands. All rights reserved. Designated trademarks are the property of their respective owners.