My Southwest Fast Rewards account was hacked: How I received my factors again
Nicely, it lastly occurred — I fell sufferer to certainly one of my loyalty program accounts being hacked, particularly my Southwest Fast Rewards account. On Dec. 3, I obtained an electronic mail from Southwest at 9:30 p.m. EST confirming my resort reservation at Hampton Inn & Suites Kalamazoo-Oshtemo for a check-in date of Dec. 4 and a checkout date of Dec. 5.
The e-mail said that 17,100 Southwest factors have been deducted from my account to e-book this resort. In response to TPG’s December 2024 valuations, that is about $240 in worth. Initially, I believed this may be a phishing electronic mail rip-off attempting to coax me into clicking on the hyperlinks offered to steal info. Instantly, I logged into my Southwest account to examine if the factors had been deducted.
Sadly, sure, this hacker had used my hard-earned reward factors to e-book a resort keep.
Listed below are the steps I took to get my factors again and how one can attempt to forestall hackers from stealing your factors and miles.
Associated: defend your self in opposition to rewards program knowledge breaches
What I did when my Southwest Fast Rewards account was hacked
After realizing that somebody had accessed my Fast Rewards account, I instantly modified my password to forestall further factors from getting used. Subsequent, I known as Southwest to tell the airline that my account had been hacked and that my factors had been used fraudulently.
As a result of it was late at evening, the Southwest consultant knowledgeable me that this was a Fast Rewards situation — she might solely help with flights and never resort reservations — so I would wish to name the telephone line for the loyalty program within the morning when it reopened.
Nevertheless, the Southwest rep informed me to name the resort on to allow them to know that this reservation was made as a result of my account had been hacked. Although it might not assist me get my factors again instantly into my account, it was value leaving a paper path of the steps taken to indicate that this was fraud.
Once I known as the resort immediately, the entrance desk worker was extraordinarily apologetic. Although she couldn’t cancel the reservation on her finish, she left an in depth notice for her supervisor to present me a name within the morning so he might attempt to resolve the problem.
Every day Publication
Reward your inbox with the TPG Every day e-newsletter
Be a part of over 700,000 readers for breaking information, in-depth guides and unique offers from TPG’s specialists
Associated: establish and stop bank card fraud
Although nothing additional could possibly be carried out that evening to get my Southwest factors again, I spent the following few hours ensuring my loyalty program passwords have been up to date. Whereas some airways and resort applications have employed two-step authentication, others, similar to Southwest, haven’t but adopted go well with.
To present myself peace of thoughts, I made a decision to alter all of my passwords to attempt to mitigate the chance of my different accounts being hacked and my rewards being stolen utilizing my info.
The following morning, I known as Southwest Fast Rewards and gave the lady an in depth description of what had occurred, explaining that I had instantly contacted Southwest, knowledgeable the airline of the account hack, known as the resort and altered my account password. The rep informed me that she could be submitting a report and that somebody from Southwest would observe up with me by way of electronic mail relating to my factors. She famous a number of instances that it was an excellent factor I had found the hack instantly, as some folks do not understand for months that they’ve rewards lacking from their account.
After I used to be carried out talking with the Southwest rep, the resort supervisor gave me a name to let me know that he had obtained the reserving notice and he could be canceling the reservation on his finish. As a result of this reservation was booked with factors via a 3rd celebration, he couldn’t give me again my rewards, however once more, it confirmed Southwest {that a} paper path was being left to assist my case.
Southwest did give me my factors again, however …
On Dec. 4, I obtained an electronic mail from a Southwest Fast Rewards rep telling me that the airline takes “the safety of our members’ Fast Rewards accounts severely, and we defend our members from fraudulent exercise by fortifying your knowledge in opposition to a breach.” The e-mail states that Southwest “requires members to enter a password previous to accessing any of their account info,” and so they encourage the usage of a “robust password.”
The e-mail additionally cites Southwest’s phrases and circumstances, noting that the airline is “not liable for unauthorized entry to a member’s account and won’t change stolen factors or awards.”
Nevertheless, as a “gesture of goodwill and one-time exception,” Southwest determined to refund me the 17,100 factors.
Apart from being a Fast Rewards member, I additionally maintain the Southwest Fast Rewards® Plus Credit score Card. I am unsure if this truth was taken under consideration when my case was being reviewed.
Whereas I’m grateful that Southwest returned my reward factors, I can not assist however acknowledge that we dwell in a digital age wherein hackers and scammers work endlessly to entry folks’s private account info. Even large companies have fallen sufferer to those hacks. For Southwest to rely solely on one password and never a further step to authenticate the person appears a bit behind the instances.
We reached out to Southwest with my expertise, and a spokesperson despatched us the next assertion:
Southwest is dedicated to defending our Clients’ accounts with complete cyber safety controls. We’ll proceed to boost our core expertise and have applied a spread of proactive and responsive safety measures throughout our platforms.
It is value noting that Southwest is not alone right here, as a number of different airways — together with American and Frontier — do not have two-factor authentication choices for securing your loyalty account balances.
So, how am I attempting to guard my accounts within the wake of this hack?
Associated: Understanding 3D bank card safety and the way it might have an effect on your journeys to different nations
Steps to guard your loyalty accounts to safeguard your factors and miles
Although these further steps aren’t assured to guard your private info and loyalty accounts, they positive will not damage.
Change and replace your passwords
Whether or not you’ve got been hacked or not, updating your password usually is a good suggestion, particularly if you have not carried out so in a very long time. Moreover, be sure to have totally different passwords for every of your accounts. In case you have one password (or a really related one) for each account, hackers could simply entry all of them.
Arrange two-step authentication (when doable)
These days, many airline and resort loyalty applications provide two-step authentication to assist safe your account. This system will sometimes require a further code, which can be despatched by way of electronic mail, textual content or via an authentication app similar to Google Authenticator.
Get electronic mail and/or textual content alerts
Although nobody likes to be inundated with a bunch of emails and/or texts, it is a good suggestion to verify your communication preferences are up to date. Most applications will contact you when a reserving is made, your factors and miles are used or even when your contact info/profile has been up to date. This can provide help to establish fraud early — which might make it simpler to resolve.
As a result of Southwest instantly notified me about my reserving — and since I am somebody who ceaselessly checks my emails on my telephone — I might contact the correct events instantly, change my account password and resolve the problem.
Associated: My AAdvantage account was hacked: Here is what occurred and how one can defend your self
Backside line
A hacker just lately redeemed greater than 17,000 of my Southwest Fast Rewards factors, although I used to be in a position to rapidly take steps to get them again. Sadly, I’m not the primary — and will not be the final — factors and miles fanatic to fall sufferer to an account hack. Earlier this yr, TPG managing editor Clint Henderson had nearly 400,000 American Airways AAdvantage miles stolen from his account. Fortunately, he too received them again.
However as fraudsters proceed to get extra intelligent of their hacking strategies, it is best to be diligent and pay shut consideration to your private accounts. Although Southwest refunded me my factors, based on their phrases, this was not assured and alternative of stolen factors is seemingly solely authorized on a case-by-case foundation. Subsequently, to make sure you do not utterly lose out in your hard-earned rewards, take further steps to safe your accounts.
Supply hyperlink