Close Menu
TechCentralTechCentral

    Subscribe to the newsletter

    Get the best South African technology news and analysis delivered to your e-mail inbox every morning.

    Facebook X (Twitter) YouTube LinkedIn
    WhatsApp Facebook X (Twitter) LinkedIn YouTube
    TechCentralTechCentral
    • News
      The AI jobs reckoning is here

      The AI jobs reckoning is here

      2 March 2026
      MTN Ghana delivers the goods as West Africa fires on all cylinders - Stephen Blewett

      MTN Ghana delivers the goods as West Africa fires on all cylinders

      2 March 2026
      Multilateral wheeling could transform South Africa's electricity market - Gerjo Hoffman

      Multilateral wheeling will define the next phase of South Africa’s energy transition

      2 March 2026
      Components price shock hitting South African PC buyers hard

      Components price shock hitting South African PC buyers hard

      1 March 2026
      US cybersecurity giant invests big in South Africa - Helmut Reisinger

      US cybersecurity giant invests big in South Africa

      1 March 2026
    • World
      OpenAI secures $840-billion valuation in latest funding round

      OpenAI secures $840-billion valuation in latest funding round

      1 March 2026

      Stripe mulling bid for PayPal: report

      25 February 2026
      Xbox chief Phil Spencer retires from Microsoft

      Xbox chief Phil Spencer retires from Microsoft

      22 February 2026
      Prominent Southern African journalist targeted with Predator spyware

      Prominent Southern African journalist targeted with Predator spyware

      18 February 2026
      More drama in Warner Bros tug of war

      More drama in Warner Bros tug of war

      17 February 2026
    • In-depth
      The last generation of coders

      The last generation of coders

      18 February 2026
      Sentech is in dire straits

      Sentech is in dire straits

      10 February 2026
      How liberalisation is rewiring South Africa's power sector

      How liberalisation is rewiring South Africa’s power sector

      21 January 2026
      The top-performing South African tech shares of 2025

      The top-performing South African tech shares of 2025

      12 January 2026
      Digital authoritarianism grows as African states normalise internet blackouts

      Digital authoritarianism grows as African states normalise internet blackouts

      19 December 2025
    • TCS
      Watts & Wheels S1E4: 'We drive an electric Uber'

      Watts & Wheels S1E4: ‘We drive an electric Uber’

      10 February 2026
      TCS+ | How Cloud On Demand is helping SA businesses succeed in the cloud - Xhenia Rhode, Dion Kalicharan

      TCS+ | Cloud On Demand and Consnet: inside a real-world AWS partner success story

      30 January 2026
      Watts & Wheels S1E4: 'We drive an electric Uber'

      Watts & Wheels S1E3: ‘BYD’s Corolla Cross challenger’

      30 January 2026
      Watts & Wheels S1E4: 'We drive an electric Uber'

      Watts & Wheels S1E2: ‘China attacks, BMW digs in, Toyota’s sublime supercar’

      23 January 2026

      TCS+ | Why cybersecurity is becoming a competitive advantage for SA businesses

      20 January 2026
    • Opinion
      The AI fraud crisis your bank is not ready for - Andries Maritz

      The AI fraud crisis your bank is not ready for

      18 February 2026
      A million reasons monopolies don't work - Duncan McLeod

      A million reasons monopolies don’t work

      10 February 2026
      The author, Business Leadership South Africa CEO Busi Mavuso

      Eskom unbundling U-turn threatens to undo hard-won electricity gains

      9 February 2026
      South Africa's skills advantage is being overlooked at home - Richard Firth

      South Africa’s skills advantage is being overlooked at home

      29 January 2026
      Why Elon Musk's Starlink is a 'hard no' for me - Songezo Zibi

      Why Elon Musk’s Starlink is a ‘hard no’ for me

      26 January 2026
    • Company Hubs
      • Africa Data Centres
      • AfriGIS
      • Altron Digital Business
      • Altron Document Solutions
      • Altron Group
      • Arctic Wolf
      • AvertITD
      • Braintree
      • CallMiner
      • CambriLearn
      • CYBER1 Solutions
      • Digicloud Africa
      • Digimune
      • Domains.co.za
      • ESET
      • Euphoria Telecom
      • Incredible Business
      • iONLINE
      • IQbusiness
      • Iris Network Systems
      • LSD Open
      • Mitel
      • NEC XON
      • Netstar
      • Network Platforms
      • Next DLP
      • Ovations
      • Paracon
      • Paratus
      • Q-KON
      • SevenC
      • SkyWire
      • Solid8 Technologies
      • Telit Cinterion
      • Tenable
      • Vertiv
      • Videri Digital
      • Vodacom Business
      • Wipro
      • Workday
      • XLink
    • Sections
      • AI and machine learning
      • Banking
      • Broadcasting and Media
      • Cloud services
      • Contact centres and CX
      • Cryptocurrencies
      • Education and skills
      • Electronics and hardware
      • Energy and sustainability
      • Enterprise software
      • Financial services
      • HealthTech
      • Information security
      • Internet and connectivity
      • Internet of Things
      • Investment
      • IT services
      • Lifestyle
      • Motoring
      • Policy and regulation
      • Public sector
      • Retail and e-commerce
      • Satellite communications
      • Science
      • SMEs and start-ups
      • Social media
      • Talent and leadership
      • Telecoms
    • Events
    • Advertise
    TechCentralTechCentral
    Home » Sections » Information security » Travel fraud surges as criminals loot airline rewards points

    Travel fraud surges as criminals loot airline rewards points

    Travel fraud is surging as criminals take aim at security vulnerabilities in airline rewards programmes.
    By Nkosinathi Ndlovu2 September 2025
    Twitter LinkedIn Facebook WhatsApp Email Telegram Copy Link
    News Alerts
    WhatsApp
    Travel fraud surges as criminals loot airline rewards points - Jason Lane-Sellars
    Jason Lane-Sellers

    Travel fraud and related crime is on the rise worldwide as criminals take aim at the security vulnerabilities of rewards programmes offered by airlines, among other loopholes.

    According to Jason Lane-Sellers, director of fraud and identity for Europe, Middle East and Africa at LexisNexis Risk Solutions, criminals are hacking into multiple rewards programme user accounts, consolidating the rewards points into a single account, and cashing these out for big ticket items such as smart TVs and other household and electronic goods.

    However, smart technological interventions are coming to the rescue.

    People aren’t as secure about their loyalty and travel programmes as much as they are about their banking information

    “Fraud has been present in various forms in the travel industry for decades, but the biggest thing that has changed is digitisation,” Lane-Sellers said in an interview with TechCentral.

    “The other side is the growth of loyalty programmes – there is value there – especially since these programmes can be interrelated. People aren’t as secure about their loyalty programmes and travel information as much as they are about their banking information and those kind of things, making it an easier target.”

    According to Lane-Sellers, impersonation scams are among the most popular modus operandi employed by travel scammers. Hotel and flight deals are advertised on social media where the URL being linked to is deceptively similar to the legitimate entity being impersonated. Users are then tricked into entering their login information on the fake site where the data is harvested and used by hackers to enter the legitimate website and clean out their rewards points.

    ‘Too good to be true’

    In other scenarios, users are tricked into making payments for flight or hotel deals on the fake website and the funds are directed into the criminal’s bank accounts.

    Despite being more digital savvy, younger cohorts aged between 18 to 25 are more susceptible to impersonation scams with “too good to be true” offers like half price flight deals used to lure them in.

    Older, more seasoned travellers – usually business travellers with lots of loyalty points – are more susceptible to a different form of impersonation. Lane-Sellers said a typical example of this is where a traveller’s flight is delayed and they want to engage customer service for help. When they search the web for the airlines website, the first link turns out to be a fake where their login details are copied.

    Read: Cyber crooks cashing in as ATM attacks decline

    “They copy the webpage using AI and screen scraping technology to make a convincing copy of the website. There are multiple ways of attacking, but the core is how easy it is to get access to that data,” said Lane-Sellers.

    The challenge for companies offering loyalty programmes is that standard ways of making their systems more secure also add an administrative burden that diminishes the quality of the experience users have on their websites. An example of this is two-factor authentication which can be used at login as well as for critical functions such as when points are being redeemed or when important data like user contact information is changed.

    Companies are now using a combination of behavioural biometrics and digital identity to improve security without disrupting the user experience, said Lane-Sellers.

    Behavioural biometrics is a form of fraud detection that uses cues from how a user interacts with a computer to identify suspicious behaviour and take corrective action without disrupting those user sessions that fall within an acceptable risk profile. These queues include typing rhythm, swipe gestures and mouse movements.

    “Does this person swipe with two fingers or one, do they prefer landscape or portrait orientation? If they type in their e-mail address in a fraction of a second then that might be a bot, or if they type slowly as though they are one- or two-finger typing then it might be someone reading the password from somewhere. There is commonality between how typical users interact versus how fraudsters interact,” said Lane-Sellers.

    Read: Hackers target Ingonyama Trust in ransomware attack

    Behavioural data is combined with other data such as a user’s frequently used devices, location, time zone and even the level of their batteries. When a number of these factors change, an alert is sent to the service provider – such as an airline loyalty points programme – and the transaction performed can be intercepted or even blocked.

    “This technology makes it easy to realise when there is a problem and then put in controls that are user friendly because, let’s be honest, we all like that easy digital experience and we don’t want to be interrupted all the time,” said Lane-Sellers.—© 2025 NewsCentral Media

    Get breaking news from TechCentral on WhatsApp. Sign up here.

    Don’t miss:

    Hackers target Ingonyama Trust in ransomware attack

    Follow TechCentral on Google News Add TechCentral as your preferred source on Google


    Jason Lane-Sellers LexisNexis LexisNexis Risk Solutions
    WhatsApp YouTube
    Share. Facebook Twitter LinkedIn WhatsApp Telegram Email Copy Link
    Previous ArticleiOCO turnaround gathering pace
    Next Article NEC XON, Smartoptics launch Africa’s first locally supported SFP solution
    Company News
    Galaxy S26 brings proactive AI, pro-grade video and a privacy breakthrough

    Galaxy S26 brings proactive AI, pro-grade video and a privacy breakthrough

    27 February 2026
    Cell C to SMEs: We'll be your partner, not just a provider - Cell C Business

    Cell C to SMEs: We’ll be your partner, not just a provider

    27 February 2026
    The data sovereignty paradox - Altron Digital Business

    The data sovereignty paradox

    27 February 2026
    Opinion
    The AI fraud crisis your bank is not ready for - Andries Maritz

    The AI fraud crisis your bank is not ready for

    18 February 2026
    A million reasons monopolies don't work - Duncan McLeod

    A million reasons monopolies don’t work

    10 February 2026
    The author, Business Leadership South Africa CEO Busi Mavuso

    Eskom unbundling U-turn threatens to undo hard-won electricity gains

    9 February 2026

    Subscribe to Updates

    Get the best South African technology news and analysis delivered to your e-mail inbox every morning.

    Latest Posts
    The AI jobs reckoning is here

    The AI jobs reckoning is here

    2 March 2026
    MTN Ghana delivers the goods as West Africa fires on all cylinders - Stephen Blewett

    MTN Ghana delivers the goods as West Africa fires on all cylinders

    2 March 2026
    Multilateral wheeling could transform South Africa's electricity market - Gerjo Hoffman

    Multilateral wheeling will define the next phase of South Africa’s energy transition

    2 March 2026
    Components price shock hitting South African PC buyers hard

    Components price shock hitting South African PC buyers hard

    1 March 2026
    © 2009 - 2026 NewsCentral Media
    • Cookie policy (ZA)
    • TechCentral – privacy and Popia

    Type above and press Enter to search. Press Esc to cancel.

    Manage consent

    TechCentral uses cookies to enhance its offerings. Consenting to these technologies allows us to serve you better. Not consenting or withdrawing consent may adversely affect certain features and functions of the website.

    Functional Always active
    The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
    Preferences
    The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
    Statistics
    The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
    Marketing
    The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
    • Manage options
    • Manage services
    • Manage {vendor_count} vendors
    • Read more about these purposes
    View preferences
    • {title}
    • {title}
    • {title}