DISCUSSION

How should retailers secure their rewards programs?

Written by RetailWire Staff

Credit card fraud is a known epidemic in the U.S., one that financial institutions and retailers are finally moving to address with EMV technology. But with all eyes on credit cards, there are other avenues into the bank accounts of retailers and customers that are softer targets for hackers: loyalty and rewards programs are becoming prime targets for fraud.

According to CreditCards.com, hackers are increasingly focusing on stealing loyalty rewards points as well as undertaking identity theft through rewards programs. A 2015 study by Colloquy indicated the average household belongs to 29 loyalty programs, and 17 of those are inactive. So hackers can presumably take advantage of defunct but active accounts that consumers have forgotten about.

Recent news of vulnerabilities in high-profile loyalty programs illustrate just how real the concerns are.

Starbucks cyber crime

Earlier in 2015, Starbucks' highly-popular rewards program was hacked by penetration tester Egor Homakov. Mr. Homakov, who blogs at security threat assessment solution provider Sakurity, was able to hack a Starbucks loyalty card and add non-existent funds from one card to another. According to his blog, Mr. Homakov presented the breach as a white hat endeavor and revealed it to the company immediately.

Mr. Homakov further explained that he was told by a support person at Starbucks that it was impossible to put him in touch with anyone on the company's technical team. When he finally was able to reach someone after two weeks, Starbucks did not express thanks for the heads up.

"The unpleasant part is a guy from Starbucks calling me with nothing like 'thanks' but mentioning 'fraud' and 'malicious actions' instead," Mr. Homakov wrote on his blog. "Sweet!"

Other loyalty program-heavy spaces, such as the hotel industry, have also been targeted.

Most notoriously, Hilton's HHonors loyalty program experienced one of the industry's first large-scale rewards data breaches in 2014. Legitimate rewards accounts were hacked and sold online. This resulted in fraudulent rewards points being used to buy goods off of participating sites.

Security Intelligence notes that, in light of the growing number of data breaches in the loyalty space, customers may grow reticent to sign up for such programs.

Discussion Thread0