Spread the love

As Australians pack their bags for Christmas reunions, beach escapes and long-overdue family catch-ups, a less festive trade is booming quietly in the shadows of the internet. On the dark web, stolen airline miles and hotel points, worth tens of thousands of dollars, are being flogged for less than the price of a servo coffee.

It is the uncomfortable finding of a joint investigation by cybersecurity firm NordVPN and travel eSIM provider Saily, which has lifted the lid on a thriving black market targeting the loyalty programs of some of the world’s biggest airlines and hotel chains. The message is blunt: while travellers chase upgrades and free nights, cybercriminals are chasing them.

The research reveals that compromised frequent flyer and hotel loyalty accounts are being traded for as little as 75 cents and as much as $200, depending on their value. Meanwhile, leaked hotel databases containing sensitive guest information, including loyalty details, can fetch as much as $3,000. In an industry built on trust, convenience, and repeat custom, that is a troubling exchange rate.

With the festive travel rush now in full swing, cybersecurity experts warn that the timing could not be worse. Millions of travellers logging in from airport lounges, hotel Wi-Fi networks and unfamiliar devices are unknowingly making life easier for scammers. Loyalty points are beautiful because they are fast, flexible and frustratingly difficult to trace once stolen.

Airlines are squarely in the firing line.

Dark web scams

Dark web scams

According to the study, airlines dominate dark web chatter linked to travel cybercrime. American Airlines, Southwest, Emirates, United, Alaska Airlines and Delta alone accounted for more than 54 per cent of airline-related discussions on darknet forums.

The appeal is obvious. A single compromised account can hold hundreds of thousands of points, which can be instantly converted into flights, upgrades or rewards often resold within hours. Unlike credit card fraud, which triggers alarms quickly, loyalty redemptions frequently blend into normal booking behaviour.

Cybercriminals gain access through familiar and depressingly effective methods: phishing emails posing as airlines, data breaches exposing customer records, and credential-stuffing attacks that exploit reused passwords across multiple services. Once inside, points are drained, transferred or converted before the legitimate account holder realises anything is amiss.

“The travel industry is a lucrative target for hackers due to the sensitive personal and financial data they handle. Our research shows that airlines continue to face data breaches, and this stolen information has a thriving market on the dark web,” says Marijus Briedis, chief technology officer at NordVPN. “Consumers should strengthen their account security, particularly during busy travel periods when scammers are most active.”

It is a sober assessment and one the industry can ill afford to ignore.

Hotels face a growing loyalty problem.

Airlines are not alone. The hospitality sector is increasingly exposed, with hotel loyalty programs emerging as a preferred currency on the dark web. Global giants such as Marriott, Hilton, IHG and Accor feature prominently in forum discussions linked to leaked databases, scams and credential-stuffing services.

Dark web scams put major airlines’ and hotels’ loyalty programs at risk

Dark web scams put major airlines’ and hotels’ loyalty programs at risk

Marriott alone accounts for roughly 35 per cent of mentions of the dark-web hotel market, according to the study, an uncomfortable statistic for a brand that has spent years rebuilding trust after past data breaches.

What makes hotel data particularly valuable is its depth. Leaked databases often include names, email addresses, stay histories, loyalty balances and, in some cases, passport numbers. These are not just points; they are identity kits. Collections containing millions of records can circulate for years, only to be recycled and resold as new scams emerge.

“The price of stolen databases isn’t determined by their volume,” says Vykintas Maknickas, chief executive of Saily. “What drives the value are sensitive details like passport numbers, loyalty points, or information linked to places or organisations that attract extra attention. High-value data like this justifies much higher prices, which motivates cybercriminals to target companies in the travel sector more aggressively.”

For travellers, the risk extends beyond a lost free night. Identity theft, account takeovers and financial fraud often follow.

Why travellers are unwitting accomplices

Part of the problem is habit. NordVPN’s research shows that roughly half of consumers reuse the same password across multiple accounts — a gift to hackers armed with automated tools.

“Using strong, unique passwords for every account and turning on multi-factor authentication is one of the simplest ways to stay protected,” Briedis says. “Yet many people still don’t do it.”

Travel compounds the risk. Logging in to accounts from public Wi-Fi, shared devices, or unsecured networks increases exposure precisely when accounts are most active. Airports, hotels and cafés remain prime hunting grounds for cybercriminals.

Maknickas urges travellers to be vigilant before and after trips. “Check your accounts before and after a trip. Travelling increases exposure simply because you’re accessing your accounts more and not always on trustworthy networks. Consider using a travel eSIM to minimise these risks.”

Enabling alerts for unusual redemptions can also make the difference between a near miss and a painful lesson.

A wake-up call for an industry built on loyalty

For airlines and hotels, the reputational stakes are high. Loyalty programs are no longer fringe marketing tools; they are billion-dollar balance-sheet assets. When trust erodes, so does customer lifetime value.

The irony is hard to miss. Programs designed to reward loyalty are now being weaponised against the very customers they aim to keep. As cybercrime grows more sophisticated, the industry’s response must move beyond quick fixes and fine print.

Greater transparency around breaches, stronger default security settings, and proactive customer education are no longer optional. Nor is collaboration across airlines, hotels and technology providers.

Travellers, meanwhile, should treat loyalty accounts with the same care as bank logins. Points may feel like Monopoly money until they are gone.

For those wanting to understand the scale of the issue, NordVPN’s full methodology and findings are available at:
https://nordvpn.com/blog/leaked-airline-loyalty-accounts/.

In the age of digital travel, loyalty still matters. But safeguarding it, it seems, now requires more than just flying often and checking in on time.

by Jason Smith – (c) 2025

Read time: 6 minutes.

About the Writer.
Jason Smith - BIO PicJason Smith has the kind of story you can’t fake, built on long flights, new cities, and that unmistakable hum of hotel life that gets under your skin and never quite leaves. Half American, half Asian, he grew up surrounded by the steady rhythm of the tourism trade in the U.S., where his family helped others see the world long before he did.
Eager to carve out his own path, Jason packed his bags for Bangkok and the Asian Institute of Hospitality & Management, where he majored in Hotel Management and found a career and a calling. From there came years on the road, Singapore, Malaysia, Vietnam, each stop adding another thread to his craft.
He made his mark in Thailand, eventually becoming Director of Sales for one of the country’s leading hotel chains. Then came COVID-19: borders closed, flights grounded, and a new chapter began.
Back home in America, Jason turned his knack for connection into words, joining Global Travel Media to tell the stories behind the check-ins written with the same warmth and honesty that have always defined him.

=====================================