Don’t Let Your Travel Points Get Stolen By Hackers

My friend just had all her points stolen from her Marriott account plus they booked hotels all over the world using the Amex card on her account

Teri Radichel
Cloud Security
Published in
4 min readMar 29, 2024

--

You should go look at your Marriott or any other travel account you have if you haven’t logged in for a while.

She has a Marriott number and she used to have about 49,000 points associated with that number. The other day she got an email that her hotel room was ready. In London. She was reading her email in Seattle.

She went to check her app and noticed that all her points were gone and that she had 5 bookings mostly in Manchester City but also one in Chicago.

In addition, she had an American Express card associated with that Marriott app that was closed. But because she had another American Express card, somehow the thieves were able to book trips and the charges transferred to the new card. Not sure why American Express allows this in the first place but she had to call them to get those transactions reversed. Also, I don’t think she got her points back.

She admitted to me that she did not have a good password on her account. In addition, she clearly did not have two-factor authentication enabled.

I went in to check my own account and I saw that two-step or two-factor authentication was not enabled. I always enable this on every account if it is an option. I’m…

--

--

Teri Radichel
Cloud Security

CEO 2nd Sight Lab | Penetration Testing & Assessments | AWS Hero | Masters of Infosec & Software Engineering | GSE 240 etc | IANS | SANS Difference Makers Award