Update On My Hacked...
 

Update On My Hacked IHG Account

33 Posts
5 Users
0 Reactions
246 Views
Posts: 0
Topic starter
(@andrew)
Joined: 10 years ago
[#7719]
wpf-cross-image

Last week I wrote about how I discovered that my IHG account had been hacked and almost 80,000 points were stolen. The agent on the phone told me that my account would be disabled for three to five business days while they investigated the incident. Sure enough, five days after that, they called me and…

Continue reading: Update On My Hacked IHG Account

Share your questions, experiences, and thoughts below.


32 Replies
32 Replies
 LDS
(@LDS)
Joined: 10 years ago

Posts: 10

This happened to me with HHonors last year. Someone got into my account and changed my email address - no email notification came to me (I believe they've since beefed up these security features). Then someone transferred 75,000 points out.

I logged in about 30 days later when I couldn't log into my account and noticed. I called in and they immediately noted that there was a new email address and that a large points transfer had occurred. I was very impressed with how quickly they acted - within 48 hours the old account was closed, new account opened, and points reinstated. This is a great reminder to regularly check all of your awards accounts.


Reply
(@Andrew)
Joined: 9 years ago

Posts: 33

The best way to protect yourself in these instances is to either burn your points immediately or simply stop using IHG. Their crap security is one of the reasons that I won't use them. Also, Holiday Inn sucks so there's that.


Reply
 k.m.
(@k.m.)
Joined: 9 years ago

Posts: 37

" IHG takes the security of our members very seriously"

....uses PIN codes as passwords.

what a bunch of unbelievable marketing BS.

also just curious, has anyone had an IHG card that has been hacked more than once? getting hacked 3 times and getting 15,000 points each time for the "frustration caused by the delayed response in gaining access to your account" is like signing up for a credit card to get the bonus. its rather dumb but unfortunately i can see this happening to IHG account holders.


Reply
(@nonamelive)
Joined: 5 years ago

Member
Posts: 0

How could possibly IHG take the security of their members very seriously while they only have 4-digit pin?


Reply
(@Frank)
Joined: 12 years ago

Posts: 33

I got hacked for 425k points ! Took a month to fix ! They said 5 days and I got no gesture .


Reply
 B
(@B)
Joined: 8 years ago

Posts: 1

Any hotel account with a large balance I have fake hotel bookings to tie up the points. It's an added defense, and in case someone gets in first they won't see many points, second if they do cancel the bookings maybe I'll get an email.


Reply
(@mike murphy)
Joined: 15 years ago

Posts: 187

How long after paying off the card do the points show up?

I paid it off 2 weeks ago, and still shows no points balance ?


Reply
(@Roger)
Joined: 9 years ago

Posts: 5

Gotta love the american pc propaganda marketing corporate jibber jabber. Help Mr. Schalpig out--this is BS!!!


Reply
 Mo
(@Mo)
Joined: 14 years ago

Posts: 135

I guess its Mr Lawyer frim executive office hagaha 15000 points,thats ridiculous,i would have declined them.
Even being Royal ambassador spire elite,IHG is a crap of crap.


Reply
(@nikdro)
Joined: 5 years ago

Member
Posts: 0

Wow, much better experience then I had with Hilton. Hilton took weeks to resolve and eventually issued me a new account number completely and never offered any type of point compensation.


Reply
(@Robert F)
Joined: 17 years ago

Posts: 41

> We do encourage you to ensure your IHG account is linked to a secure email address with 2
> factor security authentication enabled, and that the security of your PIN is safeguarded.

What's interesting here is that they're delegating security to the user. They're promoting the importance and 2FA, but they don't actually implement it. Instead, they're just suggesting that you get an email provider that does 2FA.

This would be like buying a Camry without seat belts, having a terrible accident, and then being told by Toyota that you should really consider buying seat belts because they'll make for a much safer ride.


Reply
 Alan
(@Alan)
Joined: 14 years ago

Posts: 436

Totally agree with Robert F - why are they harping on about 2FA (which I may say I love!) for your email when they won't even let you have a proper account password!


Reply
(@Gounadave)
Joined: 12 years ago

Posts: 15

My Hilton Account was hacked at the beginning of April . I had a new account within a couple of hours and 80K goodwill points on top of the lost points .

IHG are unbelievably stingy in all aspects of their rewards programme recently to the point where I feel that they think that they are doing you a favour by letting you be a member .
I have shifted my business away accordingly .


Reply
(@Steve)
Joined: 11 years ago

Posts: 29

My guess is these are all inside jobs.


Reply
(@Gounadave)
Joined: 12 years ago

Posts: 15

Inside Job ? Like I gave someone access to my account to scam the hotel company ? That's laughable . I have no Idea where the redeemed points were spent and I'm sure Hilton know that . ..........Or you mean employees inside the hotel companies ? I really doubt that too .With the pathetic security requirements to most rewards programs its no surprise its a soft target for cyber hackers . Its up to the hotel chains to up their security systems .


Reply
(@Brett)
Joined: 10 years ago

Posts: 35

Question.... who is stealing these points? It seems that staying in a hotel, where ID is required, isn’t the best idea. Are people using fake IDs? Do they not fear being caught?

Or is there a more elaborate scam going on...maybe a shady OTA or travel agent taking advance payment for a room and booking it with stolen points?


Reply
(@Chris W.)
Joined: 9 years ago

Posts: 22

Good you have access again. But without a new IHG number you will be hacked again. Its just 9999 combinations and brute force is easy.

My old account was hacked 3x before I got a new one each time 900k-1M points gone. They use it to buy gift cards flights but amso hotels (i had new bookings i didnt do).

My new account is OK now only I get newbie accelerate offers. But was compesated more as just 15k points.

Mu trust in IHG there. Not the safety though. Hope they change it soon.


Reply
(@Neville)
Joined: 8 years ago

Posts: 59

Are you going to contact Executive Office about the points you made about security?


Reply
 Rick
(@Rick)
Joined: 9 years ago

Posts: 32

Ya, 4-digit pin for a password and they take security seriously. Seriously??? With a 4-digit number for password security, I wonder how many seconds it takes to hack an account. Damn, even my bank has graduated to eight digits. C'mon IHG get with it!


Reply
(@Henry Young)
Joined: 10 years ago

Posts: 150

Seems quite possible to write a script that iterates through all 9999 PIN codes until hitting the correct guess. IHG is one of the LEAST secure accounts/sites anywhere on the web !!!


Reply
(@Henry Young)
Joined: 10 years ago

Posts: 150

Plus there are stats out there on the most popular 4 digit PIN codes out there ...


Reply
(@Janet)
Joined: 10 years ago

Posts: 55

Well, one up for World of Hyatt. Whenever you redeem points they immediately send you an email of the activity on your account.


Reply
 Ken
(@Ken)
Joined: 8 years ago

Posts: 1

Award Wallet was the primary source of how my hotel pts were hacked!!!!!! don't blindly trust a 3rd party vendor to keep track of your pts. trust me, you are at their mercy if something goes wrong or if their website gets hacked.


Reply
(@Emirates4Ever)
Joined: 9 years ago

Posts: 186

@Frank - that's because you are not a famous travel blogger who can thrash a company's reputation lol


Reply
 EVR
(@EVR)
Joined: 8 years ago

Posts: 18

@ken - Sorry. Your post is misleadinf as tour information is only half right. Award wallet allows you to store your passwords on your computer or with them. Obviously and for the reasons you mentioned, keeping them on your own computer is the only choice.


Reply
 EVR
(@EVR)
Joined: 8 years ago

Posts: 18

Lol. The TYPOS. Sorry all. Forgot to check for autocorrect issues


Reply
 Ken
(@Ken)
Joined: 8 years ago

Posts: 1

@EVR you must be stupid. Award wallet lets you store your pw on your computer, but they still see it, it's being used on their website and servers. It's up to you, if you like to be risky, and roll the dice. There's no guarantee that there won't be a breach on their servers. Anytime you leave allow access whether local or directly on third party servers, you are setting yourself up for failure. and when your account gets hacked, you have no one else to blame but yourself.


Reply
(@Koldinkanada)
Joined: 8 years ago

Posts: 3

The 4 pin password is as everyone said a joke in today's cyber security world of anti-hacking. I read some place that a combination of caps and numbers takes 300 years to crack vs a few hours for a 4 pin password. (I could be wrong about the 300 years but it is very very long).
IHG could easily change it. Other hotel chains have done so.


Reply
(@Mike Borgen)
Joined: 8 years ago

Posts: 2

My IHG account was hacked. They restored my points but now say my account has been locked.
How can we start a class action lawsuit against them?


Reply
(@Mike Borgen)
Joined: 8 years ago

Posts: 2

IHG account illegally locked.


Reply
(@keyser-soze)
Joined: 5 years ago

Member
Posts: 0

And, just in case anyone think that (ss7-dependent) two-factor authentication implementations are a panacea, here’s one article on why they’re not, written in 2017 no less:

https://arstechnica.com/information-technology/2017/05/thieves-drain-2fa-protected-bank-accounts-by-abusing-ss7-routing-protocol/


Reply
 alex
(@alex)
Joined: 4 years ago

Posts: 1

Why not add 2FA? Password alone is not secure enough.


Reply