FlyerTalk Forums

FlyerTalk Forums (https://www.flyertalk.com/forum/index.php)
-   Travel Tools (https://www.flyertalk.com/forum/travel-tools-701/)
-   -   AwardWallet Hack (https://www.flyertalk.com/forum/travel-tools/1698724-awardwallet-hack.html)

DaveInLA Aug 1, 2015 9:22 am


Originally Posted by veresch (Post 25204724)
The majority of the 250 accounts had the same username and password, we know what passwords they were trying to submit from the logs. They tried passwords like "password" or "1234567890".

I'm shocked that someone with multiple FF and/or hotel accounts would use passwords like this.

lopinc1 Aug 1, 2015 5:51 pm


Originally Posted by veresch (Post 25204724)
The majority of the 250 accounts had the same username and password, we know what passwords they were trying to submit from the logs. They tried passwords like "password" or "1234567890".

You log the failed passwords from failed login attempts in a log in clear text? That's not something you should be able to see. What about successful attempts, are those passwords logged as well?

UA1K_no_more Aug 1, 2015 11:06 pm

For the FT members who have posted that their AW account was hacked, were you using "password" or "Password" as your account password, or was your password the same as your user name...?

veresch Aug 2, 2015 2:07 pm


Originally Posted by lopinc1 (Post 25207617)
You log the failed passwords from failed login attempts in a log in clear text? That's not something you should be able to see. What about successful attempts, are those passwords logged as well?

Yes as soon as we noticed what what happening we started logging everything from those IPs.

chrisphx Aug 3, 2015 5:46 pm

I was starting to sign up when I decided to look at Flyertalk real quickly to get feedback. Glad I did so...I will take a pass for now.

LaphroaigAndRibeye Aug 6, 2015 1:08 am

I was also a victim of this hack, and admittedly, I had a VERY insecure password.

I was aware of the dangers of giving it access to my accounts. There's no way it would be able to use those passwords repeatedly to get your balances if they weren't stored in a plain text format that the system could use to login to check those balances. It was my fault for not changing my AW password to something more secure after I started adding those.

I appreciated that AW caught this quickly and notified me before any damage was done. Good on them.

SusanDK Aug 6, 2015 3:17 am


Originally Posted by Steven6702 (Post 25228738)
I was also a victim of this hack, and admittedly, I had a VERY insecure password.

I was aware of the dangers of giving it access to my accounts. There's no way it would be able to use those passwords repeatedly to get your balances if they weren't stored in a plain text format that the system could use to login to check those balances. It was my fault for not changing my AW password to something more secure after I started adding those.

I appreciated that AW caught this quickly and notified me before any damage was done. Good on them.

Thanks for posting and sharing your experience. I'm a fairly new AW user and have strengthened my password based on the information in this thread.

One thing I wish AwardWallet had done was email all users that there had been a very limited security breach and suggesting that all users reinforce good password practice.

Had I not read this on FT, I would not have known and may have been the next victim. I understand why they may have only wished to notify the 250 affected account holders as they didn't want to generate massive panic, but I would have very much appreciated an approach of full disclosure so other potential victims would have time to take appropriate action to secure their accounts.

A1pax Aug 25, 2015 12:43 am

Has my award wallet account been hacked??

Today I received an email from award wallet advised changes to scheduled flight times for JL flight from ICN to NRT next March. Howevever I checked JAL website and AA website (I booked tickets thru AA) and there was no such changes!

Has anyone received such strange email?

Middle_Seat Jan 4, 2016 8:31 pm

How to Turn Off 2-Factor Authentication?
 
A few weeks ago I turned on 2-factor in AW, but now I'd like to turn it back off. How can that be done?

ANSWER: Ten minutes before posting this, an email was sent to me from Award Wallet stating that 2-factor had been turned off. Does someone there have psychic powers??


All times are GMT -6. The time now is 8:47 am.


This site is owned, operated, and maintained by MH Sub I, LLC dba Internet Brands. Copyright © 2026 MH Sub I, LLC dba Internet Brands. All rights reserved. Designated trademarks are the property of their respective owners.