The incidents were not the result of hacks on the airlines own systems – the thieves obtained user credentials such as usernames and passwords elsewhere, the companies said. The airlines warned customers against using the same passwords on multiple websites.
American said that about 10,000 accounts were compromised, with two used to book free travel or an upgrade. United said up to three dozen accounts were compromised. American said it began notifying customers of the incidents by email on Monday, while United said it notified customers in late December.
The incidents involve frequent-flyer accounts, which allow users to make purchases using accumulated air miles. United said it would restore miles to affected users. American said it would pay for one year’s credit-watch service for custoemers involved in the incidents.
American said some accounts have been suspended while new accounts are set up, beginning with customers who have at least 100,000 miles. The company said it has notified the FBI of the matter.
The airlines said they monitor user accounts for unusual activity and may require users to enter additional information if a transaction seems suspicious. United said it has begun requiring customers to enter their rewards programme number when logging in.
Are you a security pro? Try our quiz!
Suspended prison sentence for Craig Wright for “flagrant breach” of court order, after his false…
Cash-strapped south American country agrees to sell or discontinue its national Bitcoin wallet after signing…
Google's change will allow advertisers to track customers' digital “fingerprints”, but UK data protection watchdog…
Welcome to Silicon In Focus Podcast: Tech in 2025! Join Steven Webb, UK Chief Technology…
European Commission publishes preliminary instructions to Apple on how to open up iOS to rivals,…
San Francisco jury finds Nima Momeni guilty of second-degree murder of Cash App founder Bob…