Someone Is Hacking My Mileage Account
The mystery of my British Airways Executive Club account deepens. And I have a theory.
Continue reading: Someone Is Hacking My Mileage Account
Share your questions, experiences, and thoughts below.
Lucky,
If it gets serious you should contact BA fraud department and see if they can track an ISP for the log ins. If they are not willing to cooperate an attorney to request it may be worthwhile. You have a valuable blog that has brand and recognition and if someone is using the BA website to attempt to disrupt your credibility that is not a good thing.
Good luck with this, bro.
I think that you're getting A LOT media attention lately. While I wouldn't suspect loyal readers, there are a lot of people who get REALLY jealous. And they might try to screw you over (and indeed get you into trouble). Or they try to first check if you notice. If you don't notice anything strange, they might continue with their evil plan to spend your miles (let's say short notice of 12h in advance & using false identity).
I've seen a lot of bad reactions of people when the press writes about your blog. It's actually really a shame.
Are you actually using secure passwords and/or using a password manager? If no, you should. If yes, check that your password manager password isn't compromised in any way (just to avoid other bad things).
My theory is that there are some system settings that are causing to automatically get your flights credited to Avios and request credits. If it were a person - then you ought to have seen them using the miles from your account - nothing less. My Lifemiles was hacked and ask me how hard it was to get them to fix things and re-credit back the miles that hacker had used to book hotels... yeah... hotels using lifemiles!
Given your description I think its the system and not a person... let's see how this turns out.
BA should be able to trace this if it really is an internal problem. Yikes. Weird malignant stalker types.
Ben -
I do believe it is someone inside the airlines and they are attempting to get you expelled from a specific airline program...or several. I wonder if airlines share a 'blacklist' of sorts of scammers?
If you were falsely identified as an individual trying to defraud the airlines then several might terminate your participation in their frequent flyer programs.
Hence, I suspect that may be the real intent of this person (perhaps more than one sharing information and working together.)
Isn't displaying your BA membership number a little foolish given the situation?
I would certainly request a new number now given what has happened.
Best of luck.
Would love to hear more as you investigate with BA. This is certainly fascinating and I'm curious to see how they respond.
As I was reading this it felt like a phishing scam trying to get you to click on a link to the. Enter your details. But then when you said about getting the miles credited it got weird.
BA should be able to trace where the requests are coming from, hope you get to the bottom of it soon.
Get BA to issue you a new account number and transfer the points in. Use a new password obviously. Also, make sure to change the password on any other accounts that used the same password.
given your notability in the field, you should be rigorous about changing your passwords every 4-6 weeks at the very least. i think that's the standard most IT departments have in larger corporations. we've all seen how irrational some of your detractors can be.
there certainly were more than a few people who went ballistic when you criticized BA recently.
(FWIW i flew club world LHR-JFK the other day and the service was phenomenal! such a warm and friendly crew. the seats, on the other hand...)
hope this all works out!
This might sound really basic-- but are there other accounts someone may have hacked into that would give them your detailed itinerary info? Do you use TripIt? Even your e-mail account that would contain all your itineraries? I would definitely change all passwords immediately.
Never attribute to malice that which is adequately explained by stupidity.
Seems so odd if it's for flights you actually took but didnt review my bet is something odd system wise, like auto filling missing claims if you credited to another program.
Just seems too strange, as if someone was trying to be malicious, this would be an odd way to do it.
If someone was able to hack your BA account, they likely were able to hack your email account. All your flights are likely sent to that single email address, which would allow a hacker to know all your flight plans.
What strikes me is:
1. This person would have to know all your flights or know someone who knew all your flights;
2. This person would have to be good enough to figure out to access your account;
3. This person would have to be relatively knowledgable about how miles work (probably not so hard to find in your group of friends)
Have you ever used a public computer? Or borrowed someone else's computer? Even a friend. Or have you befriended a lounge employee who looked up your flights?
Definitely creepy...
Ben, if you use an app such as TripIt, perhaps that is the account that has been compromised. That would explain how they would have info on all your flights as well as account numbers etc.
Very easy to capture passwords when you are using public wifi as well.
Does it seem like every flight that was an award flight or credited to other program has had a missing request made, or just some? It seems if it was system related it would at least be consistent.
I would definitely contact BA to find where the person logged in.... I doubt it was a someone with malicious intent , especially since it practically benefited you. Maybe a BA agent entered your account details by accident when processing another claim ? Do tell us if you make any progress.
Good luck!
BA has a real problem with their system.
My account was hacked, looks like from their side, as I didn't get any emails of any transaction and from my account someone booked a hotel room for a week in Russia.
I contacted them and they put my account on hold...
Still waiting, it's been a month and I still didn't get my points back...
Unrelated, but given Lucky's fascination with GA, thought he might be interested that Garuda will be taking delivery if a new A330 this month, with a new reverse herringbone business class seat.
That is fraud and will be dealt with severely by BA, I hope they work with you to sort it out Ben.
I'm an expert at this stuff personally I think the following could have happen
A. Your e-mail account was compromised
B. An internal error at BA
C. Somebody stole your information through public WiFi
I recommend that you change your e-mail and BA account passwords and then see what happens
Nice, make a blog post first so the BA people have to read this. Way to get some extra views
hahahahahahaaahahaha
You'd NEVER try something shady.....right?
LOLOLOL
I say we stand UNITED against this hack.
Ben - have you thought about the hack being done from someone within AwardWallet? They have all your account information and passwords. Just a thought.
For the past three years, I have been receiving credit for 3 or 4 nights stays at the Berlin Hyatt. It wasn't me, and I have Hyatt Platinum status, but when I called Hyatt to ask about this, they seemed concerned, but never corrected it. No one has tried to use my number, but it is a bit weird.
I'd suggest to reset your passwords to ALL miles accounts you have for all airlines/awardwallet (yes i realise this will take time) and take maximum use of the password policy in place (yes i realise this will take even longer) and then reset the password to the email account which those miles accounts are attached to, again taking account of their own password policy.
It's best to take a "scorched earth" policy and reset everything related just to be sure.
I read your blog through your posts on FB. I've noticed the last week or so that each story I click for your site gets redirected to a virus or malware installer page. Norton stops it each time and quarantines it, then I'm able to re-click the link from FB and come directly to the site. I think the ad server service you're using has some malicious content rotating through. Just fyi....
Blame the Chinese - remember the cabin crew that got sent to the gulag for your flight review of an awful first class experience on China's premier airline? Just sayin' ;-D
@Christian. It is probably you trying to deflect attention to pointing to Ford. You are a lame ahole. Probably homophobic as well. Now go away.
Some men aren't looking for anything logical, like money. They can't be bought, bullied, reasoned, or negotiated with. Some men just want to watch the world burn.
Any angry, ex-OMAAT staff out there? Just a thought I didn't see so far. Beyond that I agree with email hacks or some service tracker (Tripit, Award Wallet, etc) hack.
Honestly Ben, my money is with the airline employee trying to get you booted from the program. They can easily access all past flight info with a few simple key strokes, then deliberately requesting points for award tickets and tickets that you already earned another carrier's miles is a sure fire way to get you kicked off. Keep us posted.
Ben, Love you, Love the blog...
That said, you have always been quite honest regarding your flight and lounge reviews. Could it be a BA super fan?
revenge is a dish best served cold...
keep up the good work!
RR
Really strange, it sounds like an inside job to me. How else would they get your flight info for flights you don't even blog/tweet/ig about.
@Ron Seeber: Your situation is easier to explain plausibly. There is a regular annual guest to Berlin who has a frequent customer profile on the local hotel system. When creating that profile, the front desk agent mistyped the guest's HGP number and yours was entered in error.
It is not a traceable problem until the guest takes the initiative to find out why points weren't credited...and even then it may stop at HGP Customer Service and never get traced back to the hotel. Although that being said, I thought the HGP number appeared on the hotel receipt (so maybe the guest is dyslexic and didn't realize that number or two had been switched or mistyped). Or else they are disorganized or they don't care. By the way, do you work at ILR/CU?
Suspicious but not overtly malicious, so one possibility is BA has simply confused you with with another Executive Club member. Earlier this year, I received repeated emails from Hyatt welcoming me to the Andaz 5th Ave for my honeymoon, only I had no stays at that Andaz and no honeymoon trip either. I contacted Hyatt and they apologized for their mistake.
Could definitely be BA confusion. My wife was recently credited for several flights of someone else who had the same first and last name. Earned Bronze status in the process.
In case you weren't aware, at many firms (not airlines specifically), many employees have access to the username and password databases. This means that someone at American could hypothetically have your American password, and could attempt to use that password on Delta's site. To truly secure all of your online accounts, you need a DISTINCT password for each domain.
Ben,
You really should not use public wifi, it is extremely vulnerable, and yes this does happen on airplanes fairly often.
https://medium.com/matter/heres-why-public-wifi-is-a-public-health-hazard-dd5b8dcb55e6#.vgxesb3uy
This reeks of internal foulplay. The fact that you are receiving tier points and mileage for award flights implies that it isn't just some random person off the street who's doing this.
I have spent years working on things like this and even testifying as an expert witness in computer networking cases. If someone brought these facts to me, the first thing that I would say is that it is internal to BA, not someone else hacking your account. I would suspect either a BA employee with strange motives or a system problem at BA (more probably the latter). Nothing else makes a lot of sense. Besides, if someone did want to get at you and was able to hack your accounts, this is a rather obtuse way of approaching the issue. It just doesn't fit a hacker.
You find it easier to write a blog, post it publicly then link to it when you contact customer services than simply detail the issues when you contact customer services?
Oh please!
To have all these informations, the person must also have access to your email account. If you use GMail, you can check via their security page where you have (or had) open sessions in recent times.
If you use mileage websites (awardwallet.com for instance), maybe they have an automated service to claim mileage and have a bug?
Lucky, IT'S NOT your BA account was hacked! IT'S YOUR EMAIL ACCOUNTS HAVE BEEN HACKED.
Whoever hacked your email account didn't touch anything in your email account but was able to see all your itinerary. Your BA account password maybe the same as your email account. After he logged in your BA account, he started to claim missing Avios.
If you use gmail, go to account center, check recent log in. Turn on 2-step verification.
Also keep in mind, the hacker also can see the post......
You just fed a troll big time and inspired copycats. This information should have been kept private for your security.
Another thing to consider and to be careful of is public wifi, especially in foreign countries. They can be far from secure and people with malicious intentions can have a field day. Consider using a VPN to be more secure, especially with all the travelling you do.
I think it's likely that the hacker also hacked into your (or Ford's) email account(s), thus the knowledge about flights you took in private. That possibility is more likely than an airline insider accessing your confidential records on a company-owned computer system.
I would consider changing ALL of your passwords on ALL of your accounts (email, reward program, instant message, iMessage (or the Android equivalent)).
As others have noted, your use of public wifi (gogo, free lounge wifi, airplane wifi, hotel wifi) etc are all very easy vectors to sniff your network traffic and steal your login credentials. When you consider some of the locales you travel to/through (UAE, HKG, etc.) are tightly surveilled by their own governments, it would be extremely wise to invest in a VPN service (or two, as a backup) to keep your network activities and information secure.
Second - Although BA/AA/etc will probably have logs of all IP addresses that have logged into your account, I assume that may be a fruitless effort considering your "normal" usage is probably from anywhere on the globe anyways.
Going forward, get a password manager (lastpass, etc) to handle all of your private information. Cycle your passwords and let the password manager handle it. Update your security questions. Set your VPN client to automatically log in when on wifi. That should help quite a bit.
"Once is chance. Twice is coincidence. Three times is enemy action." Looks like you have a really bizarre enemy. The more public you become, the larger your subset of potential enemies; ergo, the larger the subset of weird potential enemies. Or perhaps your enemy is just crazy like a fox, given that the tactic (short-term "help" that results in long-term harm) is plausibly deniable. Your enemy may be counting on BA's first question being "cui bono."
I think your email account has been hacked. You should use several email-accounts for several purposes - for example: One to communicate with the public (this account is the most viewable, so it is at high risk), one for airline related stuff, one for hotels and so on.
You should use a password-manager, read the corresponding part of this article: http://www.bento.de/gadgets/tipps-fuer-mehr-privatsphaere-im-internet-von-edward-snowden-118889/#refsponi (German)
If you are still using Apple computers this might be interesting to you, even if i think that this is not how you got into trouble: http://www.golem.de/news/matthew-garrett-apple-rechner-eignen-sich-nicht-fuer-vertrauliche-arbeiten-1601-118332.html (German)
Good luck!
Hum, I'd think it was someone who works for one of the airlines -on one of the flights- that you wrote a not so good review about and has access to your BA account, in other words someone who works for BA.
I'd push them all the way to find out who did it. That is not funny!
Wow, lots of conspiracy people here. What'll probably happen is BA will rectify the mistake and apologise. Then Ben will make another post bashing BA for not giving any miles (which he'll of course say he didn't want) or he'll have a go at BA for not making a public apology for what is quite simply a tiny mistake that a blogger has gone over the top for
Suggest contacting them via http://www.flyertalk.com/forum/showthread.php?t=1642302&goto=newpost ; may be the most effective way.
curiouser and curiouser ... looking forward to hearing what you find out.
I wonder if there is an un-authenticated web page where you can make these requests and the other person is miss-typing their number? Back in the day Northwest didn't make you sign in to request missing millage, just enter your worldperks number and ticket number into a webform.
Hackers aren't this sophisticated. Nor do I think they'd go though all this trouble just to play games with you.
Simplest explanation is always the best: BA's site is just buggy.
"Nice, make a blog post first so the BA people have to read this. Way to get some extra views"
Consider that account support staff aren't available at all hours and that Ben often writes posts in the air where it's not necessarily feasible to engage in an exchange with a party on the ground. Seems like this sort of reaction is why this hack seems creepy instead of glitchy.
My guess is it is absolutely an airline employee, or someone in your inner circle, who is trying to get you in trouble. Maybe an FA you pissed off that got in trouble because of something you published sometime. You're already banned from UA, and this person is trying to seek vengeance. Obviously let the airlines know your account is compromised.
FRAUD possibility:
I asked to add my wife's middle name to her BAEC account.
They said I had to be a nominee.
She added me as a nominee and used password.
When I called, they had me verify the 3rd,5th,7th letter of the password.
Did that mean that the rep could see the whole password or just the selected letters? This is a password I use for a lot of things?
Did you use a nominee for any account with your password?
