Are your Hilton HHonors points safe?

Hilton HHonors points are currently being sold in the  market at around 100k points for $4.50, and those could well be yours. I don't mean that you can buy them at that price (well, you could if you were inclined). What I mean, is that those points that are being sold could be yours! And that means your HHonors account has been hacked and you don't have those points any more.

HHonors recently introduced a CAPTCHA (Completely Automated Public Turing test to tell Computers and Humans Apart) authentication for member accounts.



But notwithstanding that, some hacker forums have now started selling HHonors points online, through the route of compromising user accounts and selling the account credentials online.

Threads like these on Milepoint and Flyertalk are actively discussing this. In particular, see this post by FT user myapologies, which I quote below (spelling and grammar errors from the original post by Imperfectluck - the hacker/seller of points):

------------------------------------------------------------------------------------


The Cheapest HHonor Hilton Bulk Available FAST and ONLINE
Currently Stocked on HHonorHilton accounts!

You can view what you can get with how many points by looking here, Points Catalogue. Remember these are cracked accounts thats why they are cheap, most them have been inactive and all are checked and I know exactly how much is in which. View things you could buy is say with 30k point account you can get a $50 Giftcard etc, for those who all don't know about HHonor Hilton. I'm pretty active so expect fast accounts, all are checked and I know how much are in which.

Payments BTC/PP only

30k-39k - $1.50 cents.
40k-49k - $2
50k-59k - $2.50
60k-69k - $3
70k-79k - $3.50
80k-89k - $4
90k-100k - $4.50

Please Post here then send me a PM. prices could vary.

T.O.S
1. I'am not responsible for what you choose to do with the accounts after purchase.
2. If account does not work moment after purchase a refund will be issued or replace with a new account.

------------------------------------------------------------------------------------

Did you see those prices? $4.50 for 100k points. That's a steal, because frankly, the whole deal is indeed and in fact a steal. For those who are interested, HHonors has two sets of dual-authentication mechanisms - you could provide a username or your account number, and you need to provide a password or PIN. The main thing here is that you could use these in any combination, ie:
  • username + password
  • username + PIN
  • account number + password
  • account number + PIN

Therefore, there are more chances of an account being compromised to a hacker. I've just now checked my account, and the points are in order. However, you should go ahead and check yours too right now. More importantly, here's what you can do to protect your account:
  • Change your account password and your PIN, to something more complex. Unfortunately, the PIN can only be a 4-number combination.
  • The targetted accounts seem to be those with more than 30k points in them, so if you have fewer than that, you should be OK. Presumably this is the hacker's optimal threshold, but I wouldn't rely on that.
  • Consider making a booking for a date well into the future, that you can cancel later. In fact, I suggest multiple bookings at category 1 or category 2 hotels, using this interactive map from TravelIsFree. That'll hopefully minimise the risk if you forget to cancel!

I hope all your accounts are safe, but if there's a problem, you should immediately write to Hilton HHonors. Several users are apparently doing this, and also providing references to online threads on the topic, in the hope that Hilton will take action.

Have any of you been affected by this?


Comments

Popular posts from this blog

Free Marriott Silver status...

50% off at Marriott in Thailand, for one night

Qatar, Etihad and Gulf Air fare sales - ending soon