There’s all kinds of fraud in the miles & points world, as there’s a big underground industry of bartering rewards. While we hear about cases of rewards being stolen all the time, here’s an unusual twist on that, whereby someone managed to get someone else’s rewards credited to their frequent flyer account.
I first covered this yesterday, but would like to provide an update, as I have some more insights into how this happens, and what exactly the scheme is.
In this post:
Flight somehow credited to unknown frequent flyer account
An OMAAT reader shared the following experience with me, so let me just post it in full:
I was just organizing some past flights I took last year that I hadn’t credited yet. At the time, I was still deciding where to credit them, as I mainly flew on award tickets and lacked status, but these were long haul business class tickets on CX. I noticed on my boarding passes that the frequent flyer program listed was CX, but when I logged into my account, the miles hadn’t been credited. Since I couldn’t file a claim online because it was beyond the six-month period, I decided to reach out to their WhatsApp customer service team. It was there that I was informed that the flights were credited to American.
As I rarely used AA in the past, I quickly glossed over what the agent said, assuming they had meant “an American airline,” so I logged into my AS account. I found no points there. Then, I reread the message and tried logging into my AA account, and discovered it was locked. It turns out the account was locked since 2022, because someone tried to log in. I never used AA, so I must have missed the email notification and didn’t report the fraud then. However, I also managed to retrieve my AA number.
I reached out to CX to confirm if the agent meant AS or AA, and she said AA, American Airlines. I then confirmed if it was my AA number which I provided to review and they said no, it was credited to [different account number]. I then entered that number into AA’s password reset area and used my name, since they would’ve needed my name to credit the miles. Sure enough, it was associated with a different email address using a bizarre domain. I also did a WHOIS search, which showed that the domain was registered in Beijing last year.
I then called AA and they said it’s bizarre and they’ve never seen a case like this before and they will open a case with Fraud. Fraud then said they need to unlock my account first before they can move onto the next investigation.
What is also surprising is that I listed my CX FFP numbers before and during check-in, my boarding passes reflect this, and the return journeys were nearly three weeks long. I’m not sure how they could have modified the FFP details after flying. The agent at CX was also really not helpful and dismissive about potential fraud and compromised data on their end.
Just in case that isn’t clear (or if you just want the summary), let me simplify it as much as possible. This person had their Cathay Pacific frequent flyer number on a reservation, but the flight never credited to the account (which he only found out about later, while “auditing” his accounts). He was informed that the flight was credited to American AAdvantage, which he never requested, and on top of that, it wasn’t the number he uses with the program.
Furthermore, below is the message he received on American’s website when he tried to reset the password for the account this was reportedly credited to, which had the @qmdfcd.com domain.

And then when he looked up that domain, it was linked to being registered in Beijing, China.

How does this mileage crediting scam actually work?
When it comes to mileage theft, the single most common type of fraud involves hacking into a frequent flyer account, and then redeeming those miles for someone else for a last minute ticket. Those people typically sell tickets to unsuspecting customers using those miles, so the people actually traveling often don’t even realize what they got involved in.
So what exactly is going on here? Obviously the upside here is much more limited, given that:
- You can typically only credit miles to an account that matches the name of a traveler (though there are sometimes glitches that allow miles to be credited to others, and in some cases, mileage pooling is also possible)
- The total number of miles earned from a single ticket isn’t typically going to be that high, so this isn’t as lucrative as hacking into an account with a million miles
However, the more research I’ve done, the clearer it is that this is a more common issue than I had assumed. How does this work?
- This is often an inside job, meaning that an airline employee or airline contractor notices a ticket without a frequent flyer number (or in this case even one with it), and switches out the frequent flyer number, to “intercept” the miles; in other cases, it could even be people picking up used boarding passes without frequent flyer numbers on them
- They then create accounts they can credit the miles to (typically in the name of the passenger, so that they match), and try to cash them out as efficiently as possible; maybe it’s not enough miles for an airline ticket, but most loyalty programs let you redeem miles for merchandise, and in some cases, even some sort of cash back
This seems to be a widespread issue with Cathay Pacific in particular, and it’s reportedly one of the reasons the airline stopped letting people switch frequent flyer numbers after check-in as of late 2025 (I initially thought it was to prevent using one program for earning miles, and one program for using elite perks, but I believe that’s not actually the primary motivation).

Bottom line
A traveler booked a Cathay Pacific business class ticket and intended to credit the flight to Cathay Pacific’s loyalty program, only to find that the flight never posted. He later discovered that the flight was credited to American AAdvantage, but not even to his account (the information for which he never provided), but instead, to an account registered to a @qmdfcd.com domain. Presumably that account was still made in his name, or else the flight wouldn’t have credited.
This is apparently a more widespread scheme than I had assumed, and more often than not, it’s an inside job, either by an airline employee or a contractor. The idea is to steal the miles of others, and then quickly redeem them, even if it’s at a poor redemption value for merchandise.
What do you make of this mileage credit fraud scheme?
This fraud happens and what you are hearing about are only the cases where this is noticed. The pattern with this fraud is middle east airlines with predominantly Indian staff. Culturally the middle east airlines do not care if this happens, and the Indian staff have no qualms about doing this, and from my observation, whole departments collude on this scam. They are able to get away with this due to large number of elderly...
This fraud happens and what you are hearing about are only the cases where this is noticed. The pattern with this fraud is middle east airlines with predominantly Indian staff. Culturally the middle east airlines do not care if this happens, and the Indian staff have no qualms about doing this, and from my observation, whole departments collude on this scam. They are able to get away with this due to large number of elderly South Asian passengers who travel transcontinental on these flights on tickets bought by their children and are not aware of the value of miles.
The most lucrative is Etihad as Etihad allows you to convert your miles into actual cash on a virtual debit card. I noticed this first hand when my in-laws travelled on an Etihad flight to JFK via AUH. I created FFP accounts for them after the tickets were purchased but gave up trying to add them to the booking as the UI never worked. After the segments were flown when I tried to claim the miles retroactively, the miles had already been credited to some rando Virgin Australia account. Customer Support clammed up and stopped responding to emails.
This is a serious problem that needs to be highlighted to the DOJ/FTC/FAA. Was not worth my time for 15k miles.
This happened to me last year with an Air France flight that was inexplicably credit to a Saudia FFP account belonging to someone else. Got bounced around by both AF and Saudia. Never managed to get to the end of it.
There's a update on the case in the Flyertalk discussion linked in the para in this post just above Bottom line. tl;dr, it's probably got something to do with passenger's middle name causing a rejection, and some insider exploiting that rejection before OP can react to it.
@Lucky, just a clarification on the chronology of CX's FFP change policies FYI:
Prior to changes - unlimited changes by phone/Manage My Booking/check-in/CX lounge/CX gate
1st...
There's a update on the case in the Flyertalk discussion linked in the para in this post just above Bottom line. tl;dr, it's probably got something to do with passenger's middle name causing a rejection, and some insider exploiting that rejection before OP can react to it.
@Lucky, just a clarification on the chronology of CX's FFP change policies FYI:
Prior to changes - unlimited changes by phone/Manage My Booking/check-in/CX lounge/CX gate
1st change was early Aug 2025 - no changes thru phone or Manage My Booking. Can still change at check-in/CX lounge/CX gate. This is anti-fraud.
2nd change was mid-Nov 2025 - no changes at CX lounge or CX gate. This stops someone using one status FFP for benefits e.g. lounge and another FFP for miles and status points accumulation <-- but I can't understand why from a revenue protection/reimbursement perspective (honestly, they can't collect from status FFP after the FFP on boarding pass has been changed for accumulation? Sounds like a system limitation from here)
I can't be sure but my gut reaction is not scam but technical error on someone's IT infrastructure like at the database level. someone in IT incorrectly refreshed his data which is a lot easier to do than you think. The reason I don't think it's a scam is because the alleged scammer's email address is not (lack of a better word) scammy enough. Looking at those screen shots nothing comes off feeling like a...
I can't be sure but my gut reaction is not scam but technical error on someone's IT infrastructure like at the database level. someone in IT incorrectly refreshed his data which is a lot easier to do than you think. The reason I don't think it's a scam is because the alleged scammer's email address is not (lack of a better word) scammy enough. Looking at those screen shots nothing comes off feeling like a insidious account which I normally can spot in 5 seconds. If it is a data error of course you'll never know.
@ Bob -- I can assure you, it is a scam.
Can you please write a story about all the miles theft of AS miles? That's also an inside job.
Please check your articles and specifically TITLES for mistakes!!
This one missing a word (at least), other misspelled.
Sloppy posting does not have excuses.
Listen, you spell "Alex" like "Aleks" so, I donno, man...
I'm guessing when someone gives you a present and the card has incorrect spelling you go off on that person who just gave you something for free.
This one *is* missing a word.
GDPR : how can miles be credited to an account with a different name and contact. They have to match. It seems it’s also the airline’s fault, therefore he should make a subject access request. GDPR applies to any company doing business in Europe, even if the member isn’t domiciled there.
They do march. The fraud involves creating an account in that name. Also, what does GDPR have to do with it?
It's absolutely insane that the airlines don't actually do anything about it. I'm guessing the "inside job" for stealing miles is probably at a lower-tier, like the check-in agent or something. Why would management, or IT, etc. some department like that not try to follow up? Surely there is an audit trail for each API call / modification to FFP or the ticket in general; which should be traced back to the authorization check and...
It's absolutely insane that the airlines don't actually do anything about it. I'm guessing the "inside job" for stealing miles is probably at a lower-tier, like the check-in agent or something. Why would management, or IT, etc. some department like that not try to follow up? Surely there is an audit trail for each API call / modification to FFP or the ticket in general; which should be traced back to the authorization check and then trivially identify the source?!
I'm going to E-Mail Cathay and ask for a formal comment, let's see.
I recently experienced the same flying SQ EWR-SIN-BKK. Hadn’t decided which program to credit, left it blank. Received printed BPs at the airport, all fine. When I went to credit a few months later, SQ said it was already credited to VA, an account I never created. They ultimately credited the miles to my SQ account, but when I asked them to investigate the transaction, they said no wrongdoing had been found and stopped replying to my messages.
Passenger in this case claimed FFPs changed after boarding passes issued. Given CX's changes last Aug and Nov to lock the FFP at the check-in stage, this seems to suggest there's some insider involvement - very likely the check in agent - in this case.
Lucky, do you have any inside contact with CX? This case is really interesting, given the anti-boarding pass FFP fraud steps they put up has been bypassed.
@Lucky,
If the ticket was booked through a travel agent who has access to the PNR, or if there was a "collaborator" within CX that could access the PNR, the FF number can be changed right after boarding but before the flight departs, on a segment-specific basis. That way, the miles will go to the new account, and the traveller would not notice anything wrong on the boarding pass. CX does limit retro-claim period...
@Lucky,
If the ticket was booked through a travel agent who has access to the PNR, or if there was a "collaborator" within CX that could access the PNR, the FF number can be changed right after boarding but before the flight departs, on a segment-specific basis. That way, the miles will go to the new account, and the traveller would not notice anything wrong on the boarding pass. CX does limit retro-claim period to 6 months, so even if the miles didn't go elsewhere, the traveller would not be eligible for retro-claim to CX account, either.
Has been happening for about a year with CX https://www.flyertalk.com/forum/cathay-pacific-cathay/2204815-someone-added-someone-s-frequent-flyer-my-booking.html , though the programs used were QF Frequent Flyer and Q Avios, dunno why AA is used this time
CX's recent changes not to allow FFP changes 1) online for non-logged-in accounts, 2) under any circumstances after check-in – while having the effect of inconveniencing those of us who with to credit to one programme while benefiting from another – are almost certainly in response to this fraud on a larger scale.
The solution is that airlines should not allow just any employee to modify the FF field in a reservation. Only the passenger should be able to do that either by logging into their account, or calling customer service and being verified. I've seen some airlines allow FF number changes simply by accessing the reservation with name and PNR which are on boarding passes and luggage tags, so that needs to stop. Really, allowing access to...
The solution is that airlines should not allow just any employee to modify the FF field in a reservation. Only the passenger should be able to do that either by logging into their account, or calling customer service and being verified. I've seen some airlines allow FF number changes simply by accessing the reservation with name and PNR which are on boarding passes and luggage tags, so that needs to stop. Really, allowing access to a reservation at all with just name and PNR is a huge security flaw that needs to be closed.
Quite easy to explain this. STOP POSTING YOUR BOARDING PASSES AND RESERVATIONS ON SOCIAL MEDIA! Fraudsters skim Instagram and Facebook for idiots who publish their reservation details; then they open a frequent flyer account in their name and credit/redeem these miles. It's also a well-known tactic with check-in agents, especially for travelers who don't present their own FFN at the counter.
CX stopped people from changing FFPs after obtaining their boarding passes since August 2025, so even if I sent you boarding pass pic, and even if I entered no FFP when I checked in, you can’t add a FFP.
However the email and contact details should match the PNR. If the email is john [email protected] and someone opens an account under [email protected] the airline should ask for proof /ID.
This kind of fraud has been happening for at least 15-20 years, particularly in the Middle East and Africa. Check-in staff flag high value business class tickets and set up new accounts in that passenger name, sometimes doing the switch even after boarding passes are printed so the passenger doesn't suspect anything. The miles then credit and are spent immediately on high value shorthaul tickets (yes, these are incredibly profitable for last minute bookings) and...
This kind of fraud has been happening for at least 15-20 years, particularly in the Middle East and Africa. Check-in staff flag high value business class tickets and set up new accounts in that passenger name, sometimes doing the switch even after boarding passes are printed so the passenger doesn't suspect anything. The miles then credit and are spent immediately on high value shorthaul tickets (yes, these are incredibly profitable for last minute bookings) and the passenger doesn't even realise there is anything fishy until its too late.
This has been happening to me for YEARS with Saudia and Flying Blue. Everyone told me I am getting it wrong, but I insisted, and now I know I have been right all along. Every time I fly business with Saudia on longhaul routes, that are supposed to generate insane amounts of XP and points, I double and triple check that my Flying Blue account is on booking and boarding passes. After flying, nothing happens...
This has been happening to me for YEARS with Saudia and Flying Blue. Everyone told me I am getting it wrong, but I insisted, and now I know I have been right all along. Every time I fly business with Saudia on longhaul routes, that are supposed to generate insane amounts of XP and points, I double and triple check that my Flying Blue account is on booking and boarding passes. After flying, nothing happens inside Flying Blue. After some time, support tells me "flights have been credited to a different account on my name". Sometimes it was a new flying blue account that I never created. Sometimes it was a Saudia account that I also never created.
It is someone inside the airline. Stuff inside Saudia is doing this for years on a massive scale. I could not prove it, but I always knew this. It came to a point when I double check the correct FFP number on EVERY step before boarding - including lounge, and the gate itself. Everywhere I repeat that I will start a police investigation if somehow the number changes after I take the flight. The last time credited normally, for the first time in 3 years and tens of flights with them.
If you want to know more you can contact me, Ben.
wow this happened to me as well. I had to re-print boarding passes in Jeddah and that must be where it happened. The check in agent printed double copies and "destroyed" one set. I was at my wit's end trying to convince FB that I did not have a Al Fursan account and they kept insisting that the ticket was credited already. I thought the name on the ticket and the account have to match?
the names match. They take your name and create a different account using it, and credit there,
The sine qua non solution when any scam becomes suspect , is to Cancel All Miles , anywhere . Otherwise , the scammer can track you backwards . Especially this one .
The same happened to QR when they had a huge data breach. Scammers used info from passengers without a FFP attached to their booking to create one under their name and then move the Avios around.
This happened to me on a QR flight after checking in in Chennai. My AA account was displayed on the boarding pass, miles never credited, follow-up with Qatar indicated they ended up on a Qantas account that I had no control over. Took almost 5 months to get everything resolved - no one wanted to take ownership
"This domain is connected to Beijing, China" ... h'welp. Good luck with that one!
(That's what Xi said...)
The Only solution is to immediately Cancel All Miles to escape the danger .