Go Back  FlyerTalk Forums > Miles&Points > Airlines and Mileage Programs > United Airlines | MileagePlus
Reload this Page >

Suspended MP Accounts / Username Access Disabled / 3rd Party Security Breach-Dec 2014

Community
Wiki Posts
Search

Suspended MP Accounts / Username Access Disabled / 3rd Party Security Breach-Dec 2014

Thread Tools
 
Search this Thread
 
Old Jan 3, 2015, 1:18 am
  #76  
FlyerTalk Evangelist
 
Join Date: Apr 2008
Location: LGA/JFK/EWR
Programs: UA 1K1.75MM, Hyatt Globalist, abandoned Marriott LTT (RIP SPG), Hertz PC
Posts: 21,167
Still crickets from United on this issue. Bad form.
UA-NYC is offline  
Old Jan 3, 2015, 9:48 am
  #77  
Formally known as reinmedia
 
Join Date: Jun 2006
Location: Los Angeles | Honolulu
Programs: AA EXP | EX UA 1K | Marriot Titanium
Posts: 363
I actually received a call last week from the security department saying there was suspicious activity on my account and asked if I was trying to purchase Amazon gift cards which I was not. They hack had changed all of my personal information, login, and PIN. They were able to manually reset my PIN and have since changed my password and PIN.

About five days prior to the call from United about my MP account, my Chase Club Card was compromised and someone was trying to make online purchases at Walmart.com with my number. Not sure if they are related but find it interesting that it happened within a matter of days.

I will give credit to both UA and Chase for both contacting me via phone so I was able to get it resolved without really any harm being done besides having to get a new CC# and reseting everything in my MP account. Doesn't make up for the breach though.
Flyloha is offline  
Old Jan 3, 2015, 3:03 pm
  #78  
 
Join Date: Jul 2003
Location: SFO
Programs: COdbaUA Platinum 2MM
Posts: 5,532
Originally Posted by reinmedia
I actually received a call last week from the security department saying there was suspicious activity on my account and asked if I was trying to purchase Amazon gift cards which I was not. They hack had changed all of my personal information, login, and PIN. They were able to manually reset my PIN and have since changed my password and PIN.
I do not understand why UA cannot send us an email when a redemption occurs. I recently redeemed some AA miles on US, I received an email from AA within two hours of redemption. It is so much easier for everyone involved.
1KChinito is offline  
Old Jan 3, 2015, 4:41 pm
  #79  
 
Join Date: Jul 2007
Location: San Francisco/Sydney
Programs: UA 1K/MM, Hilton Diamond, Marriott Something, IHG Gold, Hertz PC, Avis PC
Posts: 8,155
Originally Posted by 1KChinito
I do not understand why UA cannot send us an email when a redemption occurs. I recently redeemed some AA miles on US, I received an email from AA within two hours of redemption. It is so much easier for everyone involved.
They likely do. The fraudsters will change the email address before redeeming, so one way or another you won't see it.

This is why some companies will send an email to your OLD email address when you change your contract details - so at least there's a chance you'll see something is wrong.
docbert is offline  
Old Jan 3, 2015, 9:14 pm
  #80  
 
Join Date: Jul 2003
Location: SFO
Programs: COdbaUA Platinum 2MM
Posts: 5,532
Originally Posted by docbert
They likely do. The fraudsters will change the email address before redeeming, so one way or another you won't see it.
I have redeemed numerous award tickets with UA over the years, l have yet to receive one single email confirming my redemption.

This is why some companies will send an email to your OLD email address when you change your contract details - so at least there's a chance you'll see something is wrong.
It would be ideal if any change to my profile, UA would send me an email confirming the change like many companies. If there is an email change, an email will be send to both new and old email address. I bet in the long run, it would be much easier and cheaper for UA, not to mention less stress/surprise to passengers.
1KChinito is offline  
Old Jan 3, 2015, 9:48 pm
  #81  
 
Join Date: Dec 2012
Location: Charlotte
Programs: Hilton Diamond, Marriott Platinum Elite, AA Platinum Pro, Hertz Presidents
Posts: 1,214
Originally Posted by mahasamatman
Since the timing pretty closely corresponds to iDine changing their login system to directly use your MP information, I'd lay odds that's where the breach happened.
.
Purely baseless conjecture.
Yawn.
scottsam66 is offline  
Old Jan 5, 2015, 7:48 am
  #82  
 
Join Date: Mar 2007
Posts: 4,963
I just had my password and account stop working. Had to reset password. Wonder if it had anything to do with this.
olouie is offline  
Old Jan 5, 2015, 8:15 am
  #83  
 
Join Date: Nov 2010
Location: San Francisco Bay Area, CA
Programs: UA, Marriott Lifetime Plat
Posts: 94
So even after changing my password, I cannot login to my account. I think there's a broader issue with the website...
Juggy007 is offline  
Old Jan 5, 2015, 4:52 pm
  #84  
 
Join Date: Oct 2007
Location: SFO
Programs: UA GS 1MM
Posts: 693
Got an email last night from someone in the fraud department.

1 million miles spent on MPshopping but most have now been returned.

New PIN, new password, no more username. Could have been worse.

I wonder who the third party is in this breach.
snowed is offline  
Old Jan 5, 2015, 5:03 pm
  #85  
Moderator: United Airlines
 
Join Date: Jun 2007
Location: SFO
Programs: UA Plat 1.995MM, Hyatt Discoverist, Marriott Plat/LT Gold, Hilton Silver, IHG Plat
Posts: 66,832
Originally Posted by snowed
... I wonder who the third party is in this breach.
Where did you use the same username and password as had been on your UA account?
If folks listed that we could figure this out from the intersection of sites.
WineCountryUA is offline  
Old Jan 5, 2015, 6:46 pm
  #86  
 
Join Date: Mar 2007
Posts: 4,963
Hm... Login with MP number works now but not username or email.
olouie is offline  
Old Jan 5, 2015, 7:24 pm
  #87  
 
Join Date: Oct 2007
Location: SFO
Programs: UA GS 1MM
Posts: 693
Originally Posted by WineCountryUA
Where did you use the same username and password as had been on your UA account?
If folks listed that we could figure this out from the intersection of sites.
Just got home and looked this up. The places with the same documented login/pass were:
- Award Nexus
- Register.com
- Flight Diary
- Flight Memory
- Flyer Talk
- MP Dining
- Open Flights

As this was my very first login/pass there are probably many other forgotten sites that also had it over the course of the past 10 years.

Anyone else see a pattern with their logins?

Based on their proactivity my bet is the breach occurred at MP Dining but that is all speculation on my part.
snowed is offline  
Old Jan 5, 2015, 7:25 pm
  #88  
 
Join Date: Oct 2007
Location: SFO
Programs: UA GS 1MM
Posts: 693
Originally Posted by olouie
Hm... Login with MP number works now but not username or email.
That is expected behavior even after resetting one's password/PIN/secquestion is reset.

Last edited by snowed; Jan 5, 2015 at 8:04 pm
snowed is offline  
Old Jan 7, 2015, 8:04 am
  #89  
 
Join Date: Oct 2002
Location: Port St Lucie, FL, UA1K since 1994 and 3mm, Delta 1mm
Programs: Marriott Titanium Life, Hilton Gold
Posts: 566
Just had a fraud alert on my Chase Visa MP card. This was the card associated with MP Dining. Wonder if there is a relation.

United did not lockout my MP account because I have different PW/PINS on these but will have to now monitor the other MP dining cards registered.
PaulMCO is offline  
Old Jan 7, 2015, 10:47 am
  #90  
 
Join Date: Sep 2011
Location: ORD
Programs: UMP Silver and Marriott Platinum
Posts: 162
Not able to login to UA with username, only MP Number

Has anyone else been having trouble logging into the UA MP account with their username? I keep getting an error stating:

! The MileagePlus number entered does not match our records, or, you have used a username or e-mail address. Sign-in using username or email is currently unavailable. Please try again using your MileagePlus number. If you’ve forgotten your information, please use one of the links below for help.

This has been going on since sometime last week for me.
SychoSly is offline  


Contact Us - Manage Preferences - Archive - Advertising - Cookie Policy - Privacy Statement - Terms of Service -

This site is owned, operated, and maintained by MH Sub I, LLC dba Internet Brands. Copyright © 2024 MH Sub I, LLC dba Internet Brands. All rights reserved. Designated trademarks are the property of their respective owners.