How to protect yourself against rewards program data breaches
In recent years, it’s become clear that cybersecurity is an issue many companies struggle with. Unfortunately, that extends to the world of loyalty programs. Both Marriott Bonvoy and IHG One Rewards have been subjected to data breaches that affected millions of consumers, and the Equifax hack of 2017 left millions of Americans vulnerable to identity theft. Clint Henderson, a managing editor at TPG, recently had his AAdvantage account hacked and over 300,000 miles stolen.
With loyalty programs being vulnerable targets, protecting your information from exposure is more important than ever. So, how do you go about doing that?
TPG spoke to Bahman Hayat, a software engineer specializing in cybersecurity who has worked for IBM and Microsoft, for advice on keeping our data safe from hackers. According to Hayat, data hacks are becoming more common due to poor cybersecurity and sometimes negligence.
“There are many ways data breaches happen, from storage buckets and databases being left unsecured on the internet to social engineering attacks against authorized users to simple human errors,” Hayat said. “At this point, we should assume that we have already been affected and expect to be affected again."
While giving out our information exposes us to risk, joining a rewards program isn’t something we can bypass. So, what can we do to protect ourselves against future data breaches? Here are simple steps you can take.
Avoid giving out sensitive information unless necessary

The first step to protecting your account is to avoid giving out sensitive information in the first place.
“Any time you have to give your personally identifiable information to a service, think twice about whether it’s necessary," Hayat said. "The less we give out, the fewer chances of us being affected by a breach.”
Your date of birth, passport number and even address can put you at risk, so avoid giving these out if possible. If you need to hand over this information, there is less risk if the website offers two-factor authentication. If the program doesn’t, then Hayat recommends reaching out and requesting that it starts offering it.
Related: How to identify and prevent credit card fraud
Use two-factor authentication
Setting up two-factor authentication for your loyalty account is an easy but critical way to enhance your online security.
Two-factor authentication adds an extra layer of security by requiring two verification forms before granting access. Typically, this involves something you know (like a password) and something you have (such as a smartphone app that generates a temporary code or sends a push notification or an email) or using biometrics such as fingerprints or facial recognition. This dual requirement makes it much harder for unauthorized individuals to gain access, as they would need both your password and the second factor.
Additionally, two-factor authentication provides an immediate alert if someone attempts to access your account, allowing you to take swift action to secure it. This proactive approach is crucial in preventing unauthorized transactions or misuse of your points and miles.
If you’re an Amazon customer, you’ve probably set up two-factor authentication and are used to receiving text messages with verification codes when you attempt to log in to your account. This keeps your information safe from potential hackers who may access your password and charge things to your Amazon account. You might think, "That’s not smart. They would have to provide their home address for those orders. They would get caught."
A hacker might have various motivations for wanting access to your Amazon account, including a scam called "brushing," in which they send substandard products to customers who did not order them to then leave fake reviews of these products to increase their reach in the online marketplace.
According to Hayat, multifactor authentication can help prevent scenarios like this one. While Amazon uses text-based authentication, Hayat advises against it.
“Those are vulnerable to SIM swap attacks, where an attacker can convince your carrier to transfer your phone number to their SIM," he said. "If you must use text-based authentication, call your carrier and set up a PIN with them. I recommend using Microsoft Authenticator or Google Authenticator. If you want to take it a step further, use YubiKey.”
Related: Understanding 3D credit card security and how it could affect your trips to other countries
Check if your data has been compromised

Hayat also recommends that you regularly check Have I Been Pwned to see whether your information has been leaked due to a data breach. If your account has already been compromised, the best thing to do is immediately change your passwords and start using a password manager and multifactor authentication.
Use a password manager
Confession: In the past, I kept all my rewards program passwords in a document on my laptop. If anyone had accessed that document, all my information would have been compromised. Experts recommend creating unique passwords for each account, but that’s incredibly tough to manage if storing them all on a computer or paper file isn’t an option.
Hayat recommends a password manager as a secure way to store all your login credentials in one place.
“That way, you will have a strong and unique password for every service and if one of them gets leaked, the attacker won’t be able to use that on other services. This will protect you against something called 'credential stuffing,'" Hayat said.
"Credential stuffing is where an attacker uses leaked credentials to gain unauthorized access to user accounts on other services," Hayat continued. "For example, if you use the same password on websites A and B, if website A’s data gets breached, an attacker could use that to log into website B. Using unique passwords will protect you against such an attack.”
Hayat recommends 1Password as a great option that is reputable and secure.
Related: Why a password manager is a critical part of my points and miles strategy
Monitor your credit

Whether you invest in a credit monitoring service or check your score occasionally, Hayat recommends checking your credit report annually to ensure there are no discrepancies. If a hacker maxes out your credit card in your name, you’ll see it on your credit report. You can even get free credit monitoring through Experian and receive notifications when a new account is opened or your credit score changes.
Hayat recommends freezing your credit and then lifting the freeze temporarily before opening a new account for more peace of mind. A credit freeze will prevent anyone from accessing your credit information or opening a new account. If your data has been leaked, a credit freeze is the best way to protect yourself against further damage.
Related: 6 things to do to improve your credit score
Petition loyalty programs to get serious about security
With all the recent data breaches, it’s become apparent that companies are not taking the necessary precautions to keep our data safe.
“Many companies today don’t make the necessary investments in their cybersecurity," Hayat told TPG. "We see repeatedly that leaked passwords are not hashed and salted or weak hashing like MD5 is used, which can be easily cracked. Therefore, as users, we must take the necessary steps so we are protected in the event of a breach."
Hayat recommends contacting loyalty programs and banks that haven’t implemented two-factor authentication and requesting that they do. After all, we’re responsible for our data, and if we’re handing it over to a third party like a loyalty program, we should ensure that it remains safe.
How is your loyalty program protecting you against a breach?
A spate of recent data breaches has led to various airline and hotel loyalty programs requiring two-factor authentication as a compulsory step when logging into an account. While this can be frustrating for anyone who logs into an account regularly, it's better to be safe than sorry. Here is how major loyalty programs are combatting data breaches:
Airline programs
- American Airlines AAdvantage: Optional two-factor authentication by email
- Delta SkyMiles: No two-factor authentication option
- Frontier Miles: Optional two-factor authentication
- JetBlue TrueBlue: Compulsory two-factor authentication by email with the option to change to a more secure text message two-factor authentication
- United MileagePlus: Rolling out selective testing of two-factor authentication
- Southwest Rapid Rewards: No two-factor authentication option
- Free Spirit: No two-factor authentication option
- Air Canada Aeroplan: Compulsory two-factor authentication by email
- Air France-KLM Flying Blue: Compulsory two-factor authentication by email
- British Airways Executive Club: Optional two-factor authentication by email
- Qatar Airways Privilege Club: Compulsory two-factor authentication by email
- Singapore Airlines KrisFlyer: Optional two-factor authentication for flight bookings; mandatory two-factor authentication for changes to KrisFlyer accounts
Hotel programs
- Hilton Honors: Compulsory two-factor authentication by email for only limited activities, such as logging on using a new device
- Marriott Bonvoy: Optional two-factor authentication for email or phone verification
- IHG One Rewards: No two-factor authentication option
- Radisson Rewards: No two-factor authentication option
- World of Hyatt: No two-factor authentication option
Related: Why small charges on your credit card could mean big problems
Bottom line
With technology continuing to advance, it's no surprise that hackers are targeting our information. Since loyalty programs contain personal information as well as potentially hundreds of thousands of points or miles, keeping your account safe is pivotal.
Follow the tips outlined in this story to minimize potential damage and help protect yourself against further identity theft.
TPG featured card
Rewards
| 4X | Earn 4X Membership Rewards® points per dollar spent on purchases at restaurants worldwide, on up to $50,000 in purchases per calendar year, then 1X points for the rest of the year. |
| 4X | Earn 4X Membership Rewards® points per dollar spent at US supermarkets, on up to $25,000 in purchases per calendar year, then 1X points for the rest of the year. |
| 3X | Earn 3X Membership Rewards® points per dollar spent on flights booked directly with airlines or on AmexTravel.com. |
| 2X | Earn 2X Membership Rewards® points per dollar spent on prepaid hotels and other eligible purchases booked on AmexTravel.com. |
| 1X | Earn 1X Membership Rewards® point per dollar spent on all other eligible purchases. |
Intro offer
Annual Fee
Recommended Credit
Why We Chose It
There’s a lot to love about the Amex Gold. It’s a fan favorite thanks to its fantastic bonus-earning rates at restaurants worldwide and at U.S. supermarkets. If you’re hitting the skies soon, you’ll also earn bonus Membership Rewards points on travel. Paired with up to $120 in Uber Cash annually (for U.S. Uber rides or Uber Eats orders, card must be added to Uber app and you can redeem with any Amex card), up to $120 in annual dining statement credits to be used with eligible partners, an up to $84 Dunkin’ credit each year at U.S. Dunkin Donuts and an up to $100 Resy credit annually, there’s no reason that foodies shouldn’t add the Amex Gold to their wallet. These benefits alone are worth more than $400, which offsets the $325 annual fee on the Amex Gold card. Enrollment is required for select benefits. (Partner offer)Pros
- 4 points per dollar spent on dining at restaurants worldwide and U.S. supermarkets (on the first $50,000 in purchases per calendar year; then 1 point per dollar spent thereafter and $25,000 in purchases per calendar year; then 1 point per dollar spent thereafter, respectively)
- 3 points per dollar spent on flights booked directly with the airline or with amextravel.com
- Packed with credits foodies will enjoy
- Solid welcome bonus
Cons
- Not as useful for those living outside the U.S.
- Some may have trouble using Uber and other dining credits
- You may be eligible for as high as 100,000 Membership Rewards® Points after you spend $6,000 in eligible purchases on your new Card in your first 6 months of Card Membership. Welcome offers vary and you may not be eligible for an offer. Apply to know if you’re approved and find out your exact welcome offer amount – all with no credit score impact. If you’re approved and choose to accept the Card, your score may be impacted.
- Earn 4X Membership Rewards® points per dollar spent on purchases at restaurants worldwide, on up to $50,000 in purchases per calendar year, then 1X points for the rest of the year.
- Earn 4X Membership Rewards® points per dollar spent at US supermarkets, on up to $25,000 in purchases per calendar year, then 1X points for the rest of the year.
- Earn 3X Membership Rewards® points per dollar spent on flights booked directly with airlines or on AmexTravel.com.
- Earn 2X Membership Rewards® points per dollar spent on prepaid hotels and other eligible purchases booked on AmexTravel.com.
- Earn 1X Membership Rewards® point per dollar spent on all other eligible purchases.
- $120 Uber Cash on Gold: Add your Gold Card to your Uber account and get $10 in Uber Cash each month to use on orders and rides in the U.S. when you select an American Express Card for your transaction. That’s up to $120 Uber Cash annually. Plus, after using your Uber Cash, use your Card to earn 4X Membership Rewards® points for Uber Eats purchases made with restaurants or U.S. supermarkets. Point caps and terms apply.
- $84 Dunkin' Credit: With the $84 Dunkin' Credit, you can earn up to $7 in monthly statement credits after you enroll and pay with the American Express® Gold Card at U.S. Dunkin' locations. Enrollment is required to receive this benefit.
- $100 Resy Credit: Get up to $100 in statement credits each calendar year after you pay with the American Express® Gold Card to dine at U.S. Resy restaurants or make other eligible Resy purchases. That's up to $50 in statement credits semi-annually. Enrollment required.
- $120 Dining Credit: Satisfy your cravings, sweet or savory, with the $120 Dining Credit. Earn up to $10 in statement credits monthly when you pay with the American Express® Gold Card at Grubhub, The Cheesecake Factory, Goldbelly, Wine.com, and Five Guys. Enrollment required.
- Explore over 1,000 upscale hotels worldwide with The Hotel Collection and receive a $100 credit towards eligible charges* with every booking of two nights or more through AmexTravel.com. *Eligible charges vary by property.
- No Foreign Transaction Fees.
- Annual Fee is $325.
- Terms Apply.
Rewards Rate
| 4X | Earn 4X Membership Rewards® points per dollar spent on purchases at restaurants worldwide, on up to $50,000 in purchases per calendar year, then 1X points for the rest of the year. |
| 4X | Earn 4X Membership Rewards® points per dollar spent at US supermarkets, on up to $25,000 in purchases per calendar year, then 1X points for the rest of the year. |
| 3X | Earn 3X Membership Rewards® points per dollar spent on flights booked directly with airlines or on AmexTravel.com. |
| 2X | Earn 2X Membership Rewards® points per dollar spent on prepaid hotels and other eligible purchases booked on AmexTravel.com. |
| 1X | Earn 1X Membership Rewards® point per dollar spent on all other eligible purchases. |
Intro Offer
You may be eligible for as high as 100,000 Membership Rewards® Points after spending $6,000 in eligible purchases on your new Card in your first 6 months of Membership. Welcome offers vary and you may not be eligible for an offer.As High As 100,000 points. Find Out Your Offer.Annual Fee
$325Recommended Credit
Credit ranges are a variation of FICO® Score 8, one of many types of credit scores lenders may use when considering your credit card application.Excellent to Good
Why We Chose It
There’s a lot to love about the Amex Gold. It’s a fan favorite thanks to its fantastic bonus-earning rates at restaurants worldwide and at U.S. supermarkets. If you’re hitting the skies soon, you’ll also earn bonus Membership Rewards points on travel. Paired with up to $120 in Uber Cash annually (for U.S. Uber rides or Uber Eats orders, card must be added to Uber app and you can redeem with any Amex card), up to $120 in annual dining statement credits to be used with eligible partners, an up to $84 Dunkin’ credit each year at U.S. Dunkin Donuts and an up to $100 Resy credit annually, there’s no reason that foodies shouldn’t add the Amex Gold to their wallet. These benefits alone are worth more than $400, which offsets the $325 annual fee on the Amex Gold card. Enrollment is required for select benefits. (Partner offer)Pros
- 4 points per dollar spent on dining at restaurants worldwide and U.S. supermarkets (on the first $50,000 in purchases per calendar year; then 1 point per dollar spent thereafter and $25,000 in purchases per calendar year; then 1 point per dollar spent thereafter, respectively)
- 3 points per dollar spent on flights booked directly with the airline or with amextravel.com
- Packed with credits foodies will enjoy
- Solid welcome bonus
Cons
- Not as useful for those living outside the U.S.
- Some may have trouble using Uber and other dining credits
- You may be eligible for as high as 100,000 Membership Rewards® Points after you spend $6,000 in eligible purchases on your new Card in your first 6 months of Card Membership. Welcome offers vary and you may not be eligible for an offer. Apply to know if you’re approved and find out your exact welcome offer amount – all with no credit score impact. If you’re approved and choose to accept the Card, your score may be impacted.
- Earn 4X Membership Rewards® points per dollar spent on purchases at restaurants worldwide, on up to $50,000 in purchases per calendar year, then 1X points for the rest of the year.
- Earn 4X Membership Rewards® points per dollar spent at US supermarkets, on up to $25,000 in purchases per calendar year, then 1X points for the rest of the year.
- Earn 3X Membership Rewards® points per dollar spent on flights booked directly with airlines or on AmexTravel.com.
- Earn 2X Membership Rewards® points per dollar spent on prepaid hotels and other eligible purchases booked on AmexTravel.com.
- Earn 1X Membership Rewards® point per dollar spent on all other eligible purchases.
- $120 Uber Cash on Gold: Add your Gold Card to your Uber account and get $10 in Uber Cash each month to use on orders and rides in the U.S. when you select an American Express Card for your transaction. That’s up to $120 Uber Cash annually. Plus, after using your Uber Cash, use your Card to earn 4X Membership Rewards® points for Uber Eats purchases made with restaurants or U.S. supermarkets. Point caps and terms apply.
- $84 Dunkin' Credit: With the $84 Dunkin' Credit, you can earn up to $7 in monthly statement credits after you enroll and pay with the American Express® Gold Card at U.S. Dunkin' locations. Enrollment is required to receive this benefit.
- $100 Resy Credit: Get up to $100 in statement credits each calendar year after you pay with the American Express® Gold Card to dine at U.S. Resy restaurants or make other eligible Resy purchases. That's up to $50 in statement credits semi-annually. Enrollment required.
- $120 Dining Credit: Satisfy your cravings, sweet or savory, with the $120 Dining Credit. Earn up to $10 in statement credits monthly when you pay with the American Express® Gold Card at Grubhub, The Cheesecake Factory, Goldbelly, Wine.com, and Five Guys. Enrollment required.
- Explore over 1,000 upscale hotels worldwide with The Hotel Collection and receive a $100 credit towards eligible charges* with every booking of two nights or more through AmexTravel.com. *Eligible charges vary by property.
- No Foreign Transaction Fees.
- Annual Fee is $325.
- Terms Apply.

