ShieldLabs
Back to blog

How to prevent loyalty fraud

Loyalty fraud: reward points drained from a hijacked account and farmed across many fake accounts on one device, converted into cash-equivalent value

Last updated on July 27, 2026 · 9 min read

Loyalty points are money that most people guard like it is not. A rewards balance converts into flights, gift cards, and merchandise, so a hijacked airline or retail account is a cash withdrawal to a fraudster, and programs are a growing target: Thomson Reuters put annual global rewards-program fraud losses in 2025 at $1 billion to 3 billion. Yet customers watch their points far less closely than their bank balance, which is exactly why the losses run quiet and deep.

Loyalty fraud is the exploitation of a rewards program to extract value it was never meant to give up. This guide covers what loyalty fraud is, the main types from draining a real account to farming fake ones, why programs are such attractive targets, and how to defend a program, including the device signals that expose both a takeover and a farm.

Key takeaways

  • Loyalty fraud is the theft or illegitimate accumulation of reward points, miles, or perks, because those rewards carry real, liquid value.
  • The main external types are account takeover to drain a real member's points, and fake-account farming to harvest signup and referral bonuses at scale.
  • Programs are attractive because points are cash-equivalent, weakly monitored by members, and easy to liquidate into gift cards or transferred miles.
  • Two of the biggest external vectors leave a device trail: a takeover arrives from an unfamiliar device, and a farm runs many accounts from one.

What is loyalty fraud?

Loyalty fraud is any abuse of a loyalty or rewards program that extracts value fraudulently, whether by stealing points from a real member's account or by manufacturing accounts and activity to earn rewards that were never legitimately owed. Because a points balance is redeemable for real goods, the program is effectively a store of value, and loyalty fraud is the act of draining or minting that value without earning it.

It spans a few motives. Some fraudsters steal from existing members, breaking into accounts to cash out balances. Others manufacture value from nothing, spinning up fake members to collect welcome and referral bonuses over and over. A third kind is internal, where staff issue or redeem points improperly, which is a different problem solved with internal controls rather than the account-level signals this guide focuses on.

The main types of loyalty fraud

The external attacks that hit programs cluster into a few recognizable forms:

  • Account takeover. Attackers use credential stuffing or phishing to break into a real member's account and drain the balance, transferring miles or redeeming points for gift cards before the owner notices. This is account takeover aimed at a wallet most people rarely check.
  • Fake-account farming. Fraudsters create many accounts to collect signup bonuses, welcome points, and tiered perks repeatedly, which is multi-accounting pointed at a rewards program.
  • Referral manipulation. Self-referral through fake accounts harvests referral rewards, the same referral fraud mechanism applied to loyalty incentives.
  • Points reselling and laundering. Stolen or farmed points are sold on secondary markets or converted into gift cards, which turns illiquid rewards into clean, spendable value and is often why the points were taken in the first place.
  • Internal fraud. Staff issue points to accomplices or redeem them improperly. This is real, but it is a controls-and-audit problem rather than an account-signal one.

The through-line for the external types is an account that is not what it claims: a hijacked one, or one of many run by a single operator.

Why loyalty programs are a target

Loyalty programs are attractive for three reasons that compound. First, points are cash-equivalent: they redeem for flights, gift cards, and goods, so stealing them is stealing money, without the fraud controls that guard a payment card. Second, they are weakly watched. People check a bank balance far more often than an airline or retail rewards balance, so a drained account can go unnoticed for months, giving a fraudster time to cash out and move on.

Third, rewards are easy to liquidate. Points convert into gift cards or transfer as miles, and both are hard to claw back once spent, which turns a stolen balance into clean value quickly. The pull is strong enough that payments networks treat it as a front-line issue; writing on the travel industry in 2024, Mastercard framed fighting loyalty fraud as essential. Put together, a rewards program is a lightly guarded store of money that customers do not monitor, which is close to an ideal target. That is why defending one means treating points like the currency they are.

Which industries loyalty fraud targets most

Loyalty fraud follows the value, so the programs with the largest, most liquid rewards take the most fire:

  • Airlines and travel. Frequent-flyer miles are the prize target, because they are high-value, transferable, and redeemable for flights and upgrades, which makes a hijacked mileage account easy to resell on secondary markets. A redemption from an unfamiliar device is the tell.
  • Hotels and hospitality. Points redeem for stays and gift cards, and balances sit dormant for months, so a drained account often goes unnoticed until a booking fails. Watching for a login from a device the member has never used matters most here.
  • Retail and e-commerce. The pressure is on the signup side: welcome points, tiered perks, and referral bonuses get farmed across many fake accounts, the multi-accounting pattern, so linking those accounts back to one device is the core defense.
  • Restaurants and quick-service. App-based rewards with generous signup and referral offers invite the same farming at scale, where one operator spins up dozens of app accounts from a handful of devices.
  • Grocery, fuel, and convenience. High-frequency, app-driven rewards make small-value farming worthwhile in volume, and the shared device behind a cluster of accounts is what separates a real regular from a farm.
  • Crypto and Web3. Exchange loyalty tiers, staking rewards, and token airdrops are farmed at scale by Sybil operators running many wallets and accounts, so the device behind a swarm of supposedly independent claimants is the clearest sign they are one farm.

The dominant vector shifts by vertical, takeover-heavy where balances are large and liquid, farming-heavy where signup bonuses are generous, but both leave the same device trail.

How to prevent loyalty fraud

Defending a program means protecting both the real accounts holding points and the signup flow minting them:

  • Protect the login against takeover. Because draining a real account is the headline attack, strong authentication and takeover detection on loyalty logins matters as much as on any financial account. A login from an unfamiliar device is a leading takeover signal.
  • Link fake accounts by device. Signup and referral bonus farming runs many accounts, so recognizing when a cluster of members traces back to one device exposes the farm even when each account looks distinct.
  • Step up on high-risk redemptions. Treat a large redemption, a points transfer, or a payout to a new destination as a high-risk action, especially from a device the account has not used, and add verification before value leaves.
  • Watch velocity and anonymity. Bursts of signups or redemptions, or activity arriving over VPNs, proxies, and anti-detect browsers, are strong signals that the account is not a genuine member.
  • Monitor balances and notify members. Alerting a member on a redemption or a transfer, and flagging dormant-then-suddenly-active accounts, catches takeovers that slip past login.

The first two close the biggest external doors, takeover and farming, and the rest reserve friction for the moments when value actually moves.

Preventing loyalty fraud with ShieldLabs

ShieldLabs gives a loyalty program the device layer under both of its biggest external threats. You add one JavaScript snippet to your signup, login, and redemption pages, and each visit returns persistent identification that recognizes a returning device across cleared cookies and a rotated IP, plus a risk score from 0 to 100 with the named signals behind it. When a member logs in or redeems from a device the account has never used, that unfamiliar device is a strong takeover signal; when many accounts trace back to one device, that is the many-accounts-on-one-device pattern behind bonus farming.

We tested that recognition against the resets fraudsters lean on, flushing cookies and switching networks between visits, and the returning device still tied back to a device we had already seen. That durability is the point: in 2019, when Firefox began blocking third-party tracking cookies by default, cookie-based recognition weakened across the board, while a device read that outlives a cleared cookie is exactly what separates a member's real device from the unfamiliar one behind a takeover, or the single device behind a cluster of farmed accounts.

Alongside it, the anonymity signals, VPN, proxy, Tor, and anti-detect browser use, flag the masked sessions that farms and account-takeover operations rely on. ShieldLabs scores the session and names the evidence; it does not manage your points ledger, catch internal staff fraud, or make the redemption decision itself. You read the score and the pattern through the API and webhooks and decide, by your own rules, when to allow, challenge, or hold, so the decision stays in your program. The free tier covers your first 5,000 identifications.

Sources

  1. Thomson Reuters: The unexpected cost of rewards programs fraud (2025)
  2. Mastercard: How to Fight Loyalty Fraud in the Travel Industry (2024)
  3. Wikipedia: Loyalty program

Frequently asked questions

What is loyalty fraud?
Loyalty fraud is any abuse of a rewards or loyalty program that extracts value fraudulently, either by stealing points from a real member's account or by manufacturing fake accounts and activity to earn rewards that were never owed. Because points redeem for flights, gift cards, and goods, they carry real value, so stealing or minting them is effectively stealing money. It ranges from account takeover to fake-account farming to internal staff abuse.
Is loyalty fraud illegal?
Yes, in most cases. Stealing points from another member's account, or systematically manufacturing accounts to extract rewards, is fraud and can carry legal consequences, and stolen points are sometimes used in money laundering, which adds to the exposure. Businesses hit by loyalty fraud also absorb the cost of reimbursing stolen points and rebuilding customer trust, on top of any legal risk.
How do fraudsters steal loyalty points?
Most often through account takeover: they use credential stuffing or phishing to break into a member's account, then transfer miles or redeem points for gift cards before the owner notices, since people rarely check reward balances. Others farm fake accounts to harvest signup and referral bonuses, or resell stolen and farmed points on secondary markets to turn them into spendable cash.
How do you detect loyalty fraud?
By reading the account and device rather than trusting the points balance. A login or redemption from a device the account has never used is a strong takeover signal, and many accounts tracing back to one device exposes bonus farming. Adding velocity limits, anonymity signals like VPN and anti-detect browser use, and step-up verification on large redemptions catches most external loyalty fraud before value leaves.
Does ShieldLabs prevent loyalty fraud?
ShieldLabs provides the device signal behind the two biggest external loyalty threats, account takeover and fake-account farming, rather than managing your points ledger or catching internal staff fraud. It gives every signup, login, and redemption persistent identification and a risk score with the named signals, so your program can flag an unfamiliar device or a cluster of accounts on one machine and decide when to step up. Your rules still own the decision, and the free tier covers your first 5,000 identifications.

Related articles