Community
Wiki Posts
Search

Priority Club Point Theft

Thread Tools
 
Search this Thread
 
Old Aug 18, 2012, 8:19 am
  #76  
Suspended
 
Join Date: Jul 2007
Posts: 4,477
Yes the hotel should never print the membership number and balance on welcome letter nor invoice. Name and address is good enough. If I want to know the balance of my points i could always check my account using in room wifi......
FlyerTalker688786 is offline  
Old Aug 18, 2012, 4:34 pm
  #77  
FlyerTalk Evangelist
 
Join Date: Aug 2010
Location: CPH
Programs: UAMP S, TK M&S E (*G), Marriott LTP, IHG P, SK EBG
Posts: 11,089
Originally Posted by chongcao
Yes the hotel should never print the membership number and balance on welcome letter nor invoice. Name and address is good enough. If I want to know the balance of my points i could always check my account using in room wifi......
Only if wifi is free at the hotel ...... a lot of IHG properties don't give out free internet.
nacho is offline  
Old Aug 18, 2012, 4:43 pm
  #78  
Suspended
 
Join Date: Aug 2010
Location: DCA
Programs: UA US CO AA DL FL
Posts: 50,262
Originally Posted by ChinaShrek
This is a really good idea. How often do people change email addresses anyway?
Uhh - Maybe when they change jobs?

This is a silly idea. All that's necessary is rewriting the script so that when an email change is made, an email is sent to the old and the new address. The email specifically notes, "if you did not make or authorize this change, please call us immediately...."

Done by virtually every other online vendor, no reason it can't be done here.
Often1 is offline  
Old Aug 18, 2012, 5:49 pm
  #79  
A FlyerTalk Posting Legend
 
Join Date: Aug 2006
Location: Argentina
Posts: 40,210
How much access to your account do check-in staff have?

If not that I would say the using of a public computer is the more likely cause for someone accessing your account.
HIDDY is offline  
Old Aug 18, 2012, 6:19 pm
  #80  
FlyerTalk Evangelist
 
Join Date: Aug 2010
Location: CPH
Programs: UAMP S, TK M&S E (*G), Marriott LTP, IHG P, SK EBG
Posts: 11,089
Originally Posted by HIDDY
How much access to your account do check-in staff have?

If not that I would say the using of a public computer is the more likely cause for someone accessing your account.
If they can tell you how many points you have and your PC number and your name and address and your CC number.......they pretty much have everything they need to hack anyone's account.
nacho is offline  
Old Aug 19, 2012, 4:06 am
  #81  
Moderator: InterContinental Hotels and Germany
 
Join Date: Oct 2002
Posts: 6,552
The problem with the invoices slipped under the door or lying in front of the room open or in open envelopes is a somehow common problem and not limited to IHG hotels only.

There was an issue at at Sheraton a couple of month ago:

http://www.flyertalk.com/forum/starw...-envelope.html
FLYGVA is offline  
Old Aug 19, 2012, 4:13 am
  #82  
FlyerTalk Evangelist
 
Join Date: Aug 2010
Location: CPH
Programs: UAMP S, TK M&S E (*G), Marriott LTP, IHG P, SK EBG
Posts: 11,089
Originally Posted by FLYGVA
The problem with the invoices slipped under the door or lying in front of the room open or in open envelopes is a somehow common problem and not limited to IHG hotels only.

There was an issue at at Sheraton a couple of month ago:

http://www.flyertalk.com/forum/starw...-envelope.html
I stayed at a Marriott hotel and I got 2 bills slipped through my door, and one of them is not mine. I can see his name and address but not his MR number.
nacho is offline  
Old Aug 19, 2012, 4:57 am
  #83  
FlyerTalk Evangelist
 
Join Date: Jul 2004
Location: UK
Programs: Mucci, BA LTG + GGL, SPG LTP, HHonors Diamond, IHG Spire Ambassador
Posts: 12,695
What's interesting about that is there are at least 3 problems raised there, all of which seem to be fixed (and it's only been a couple of months):

1) The original lazy hotel, the GM was forced into fixing it (we hope, at least promising it would be fixed)

2) The Google URL for cancelled reservations now seems to yield nothing - presumably SPG fixed it.

3) The page where you could view anyone's bookings with just a name or SPG number no longer appears to have that option - presumably SPG fixed it.

So bravo to Starwood. I've never been a big SPG person, always been a ICHG man primarily. Maybe I should begin to pay more attention to SPG ^
G-BOAC is offline  
Old Aug 19, 2012, 1:55 pm
  #84  
Suspended
 
Join Date: Jul 2007
Posts: 4,477
Originally Posted by nacho
Only if wifi is free at the hotel ...... a lot of IHG properties don't give out free internet.
That is correct. But so far only North American properties printed the membership number and balance. And majority of North American properties have free wifi.
FlyerTalker688786 is offline  
Old Aug 19, 2012, 2:11 pm
  #85  
Moderator: GLBT travelers, India-based Airlines and India; FlyerTalk Evangelist
 
Join Date: Jan 2004
Location: Asia
Programs: Yes!
Posts: 15,512
Originally Posted by chongcao
That is correct. But so far only North American properties printed the membership number and balance. And majority of North American properties have free wifi.
Just in the last month, I have had membership number and balance printed at several Asian hotels too. Including,
- Holiday Inn Golden Mile HKG
- Crowne Plaza New Delhi Okhla
- Crowne Plaza Gurgaon

So I don't think it just a north American thing.
AJLondon is offline  
Old Aug 19, 2012, 3:35 pm
  #86  
 
Join Date: Feb 1999
Location: San Jose, California, USA
Programs: AS 100K, UA MM, AA MM, IC Plat Amb, Marriott Gold, Hilton Gold, Hyatt Explorist
Posts: 3,146
Originally Posted by G-BOAC
What's interesting about that is there are at least 3 problems raised there, all of which seem to be fixed (and it's only been a couple of months):
What's depressing is that there are at least 3 straightforward fixes that IHG could do -- already mentioned in this thread, in fact -- that would increase security by an order of magnitude, yet IHG continues to ignore these gaping security holes.

Looks like we have no choice but to monitor our account balances like a hawk (and if we notice something wrong, hope that IHG believes us).
mikew99 is offline  
Old Aug 19, 2012, 4:45 pm
  #87  
FlyerTalk Evangelist
 
Join Date: Jul 2003
Posts: 11,377
I would suggest that any concerned individuals file complaints through the Privacy Office at IHG: http://www.ichotelsgroup.com/ihg/hot...vacy_statement

If resolution isn't forthcoming, then go the TrustE route.
soitgoes is offline  
Old Aug 19, 2012, 8:06 pm
  #88  
Moderator: CommunityBuzz!, OMNI, OMNI/PR, and OMNI/Games & FlyerTalk Evangelist
 
Join Date: Nov 2000
Location: ORD (MDW stinks)
Programs: UAMM, AAMM & ExPlat, Marriott lifetime Plat, IHG Plat, Hilton Diamond
Posts: 23,506
Originally Posted by LarryMcAdoo
As a follow up, PCR does not issue the cards, another company does. Once PCR deems that the account was accessed without hacking, then they wash their hands of anymore responsibility. I have asked the questions about IP addresses, tracking the products redeemed by these cards etc.
They find it easier to believe that some one in my family is a thief. Unless my hound has learned how to log-on, then that would be impossible.

They could do so much more to help.....

In the end, the hackers are smarter than their IT!
Originally Posted by IHG Care
Larry,

We would like to look into and follow up on your unfortunate experience. I have sent you a PM in order to obtain additional details.

Thank you,

Ben J
IHG Care
Can this thread or the IHG forum get an official response from IHG Care or IHG corp?

I can understand not commenting on the specific case of LarryMcAdoo but how about details on how IHG determines that an account was not hacked?

Also any developments on increasing security measures (some of which have been suggested in this thread).
Sweet Willie is offline  
Old Aug 20, 2012, 1:03 am
  #89  
uk1
Suspended
 
Join Date: Jan 2004
Location: UK
Posts: 11,969
I really hope that they don't just run and hide on this.
uk1 is offline  
Old Aug 20, 2012, 8:41 am
  #90  
 
Join Date: Dec 2004
Location: UK
Programs: Bonvoy Gold, AA Plat, Volare Premier, VS Silver, National Emerald Elite, Hertz President Circle
Posts: 2,526
Originally Posted by Sweet Willie

I can understand not commenting on the specific case of LarryMcAdoo
Actually given the OP has asked for a resolution in public, unless he objects, I see no reason why they should not say why they regard his specific case as not fraudulent. There are no legal proceedings and none are likely.
wobbly wings is offline  


Contact Us - Manage Preferences - Archive - Advertising - Cookie Policy - Privacy Statement - Terms of Service -

This site is owned, operated, and maintained by MH Sub I, LLC dba Internet Brands. Copyright © 2024 MH Sub I, LLC dba Internet Brands. All rights reserved. Designated trademarks are the property of their respective owners.