Going the Extra Mile: Travel Rewards Turn into Underground Currency.

Going the Extra Mile: Travel Rewards Turn into Underground Currency.

Stolen airline miles and hotel points are treated as tradable inventory in underground markets, with access commonly obtained through credential compromise and malware. Flare’s analysis of Telegram channels reveals organized sellers who redeem rewards into bookings and resell them, contributing to an estimated $1–$3 billion in annual losses. #Infostealers #United

Keypoints

  • Underground Telegram channels list compromised airline and hotel loyalty accounts like commercial inventory.
  • Account takeover is often achieved via phishing, brute force, credential stuffing, or infostealers.
  • The fraud cycle: gain account access, identify valuable balances, redeem miles into travel, then resell bookings.
  • Flare analyzed 322 posts from 35 actors with 3,007 vendor mentions, indicating large-scale credential harvesting.
  • Pricing observed averages roughly $1 per 1,000 miles and often includes full email access to ease resale.

Read More: https://www.bleepingcomputer.com/news/security/going-the-extra-mile-travel-rewards-turn-into-underground-currency/