Skip navigation

Cheap Airfare, Vacation Deals, Car Rental, and Discount Travel - SmarterTravel.com
My SmarterTravel

Email scam targets frequent flyers

Posted by Tim Winship
images/photos/columnists/timwinship.gif
Photo: American Airlines
Editor's Note: This story was originally published on June 6, 2008. To see the most recent SmarterTravel articles on related topics, please click on any of the following links: American, American AAdvantage, frequent flyer, mileage earning, Tim Winship, Up Front with Tim Winship.

As do all Internet users, I receive my share of spam and scam in my email inbox. As a longtime Web enthusiast, I thought I'd seen just about every possible permutation of the online hustle. But yesterday a colleague forwarded me an email he deemed suspicious (correctly), and which featured a novel twist.

The email's subject line was "AAdvantage Survey Program" and read as follows:

Greetings from AA.com

Welcome to the American Airlines AAdvantage(R) program, the first and largest loyalty program in the world! We are proud to inform you that today June. 26 /2008 AmericanAirlines.com launch a new reward program. Please log in to your American Airlines account and take the 5 questions survey. For your effort you will be rewarded with $50

Your 50 dollars bonus code is AA-001NXX-2008NX22. Please log in to your www.aa.com account and follow the steps.

Thank you very much for your help and your patient and hope you will enjoy the American Airlines reward program in the future

Sincerely,
American Airlines Reward Department

Advertisement

Those who clicked on the link in the email were taken first to a web page that looked exactly like a page on AA.com where they were asked to provide an AAdvantage membership number and PIN; then to an online survey with questions pertaining to American's website; and finally to a page requesting the user's personal information, including social security number, date of birth, mother's maiden name, credit card number, expiration date, code, and ATM PIN.

This is classic phishing. (According to Wikipedia, "phishing is an attempt to criminally and fraudulently acquire sensitive information, such as usernames, passwords and credit card details, by masquerading as a trustworthy entity in an electronic communication.")

I can't say for sure that this is the very first frequent flyer program-related email scam, but it is the first one I'm aware of. Also noteworthy is American's response.

A recipient of the email forwarded it to American spokesman Tim Wagner, who alerted the AAdvantage department and American's IT security personnel. It was determined that the email, which appeared to have been sent from AA.com, actually traced back to a server in Moscow. American then took the unusual step of sending an email to AAdvantage members, as follows:

It has come to our attention that a "phishing" email was received by many people including some of our AAdvantage(R) members. A phishing email attempts to trick unsuspecting people into revealing personal information to a third party. This particular phishing email is a fraudulent email message that claims to be from American Airlines and offers a $50 payment in return for completing a survey.

If you received this email, do not open the link and delete the email immediately.

If you have received the phishing email and have provided your personal AAdvantage information, please log on to AA.com immediately, verify your account balance and change your password. If unauthorized changes have been made to your account, please call us at 1-800-882-8880 and speak "AAdvantage Services," then select "Account Information" and ask for an "agent."

If you provided other personal information when completing the phishing survey, we suggest you contact your financial institutions.

Wagner suspects the culprits were more interested in obtaining credit card information than in using AAdvantage information to fraudulently obtain free tickets. I think he's right—frequent flyer awards are easily traced.

Targeting frequent flyer program members may be a one-time-only event. Unfortunately, it's more likely that this is just the beginning of a new trend.

As banks and credit card issuers know, frequent flyers are a highly desirable segment of the consumer universe. Perpetrators of phishing scams recognize that too, and can be expected to target mileage program members again. And again and again and again.

Think that email is from your frequent flyer program? Don't be too sure. (See the Wikipedia article referenced above for assistance in recognizing and eliminating phishing emails.)

More blog entries

Guidelines: We love hearing from you, especially when your posts are thoughtful, polite, concise and unique. However, we do reserve the right to remove posts that are written in less than a "community spirit". Please see the full list of unacceptable comment types here.
Comments FAQ's

 

Archived Comments:

  • trpetersons - June 8, 2008

    Thank you Tim for this informative article on phishing scams, using frequent flyer emails as a cover. I don't know if I would have fallen for this or not.......but it is nice to know we have fore warning now, that it's out there, so we definately don't! Thank you for taking the time to write this! We really appreciate it.

  • Mike - June 13, 2008

    I got that email. There were a few misspelled words (e.g., patient instead of patience) which caused me not to follow the survey link. Then I read that it was a fraud on some forums. You just can't be too careful today.

  • Deb E. - June 17, 2008

    What can we look for in the page source information that indicate a website may not be legitimate? Are there certain words or symbols that always or sometimes are suspicious in the page source? Thank you.

ALERT!
Your pop-up blocker security
setting is too high.



To view this page and still use your pop-up blocker, please make the following adjustment to Internet Explorer.

- Click on "Tools"
- Click on "Pop-up Blocker"
- Click on "Always Allow Pop-ups from This Site..."
- Try the link again

If you are not using Internet Explorer or are still having issues, please email feedback@smartertravel.com with details

Hotels

COMPARE PRICES
Air Departure Date Calendar
Air Return Date Calendar
NEWSLETTER SIGN UP
Get the early word on the latest travel deals of the day picked by our editors. Sign up for our free Deal Alert newsletter.

email address:

DESTINATIONS