samcurry.nettwitterrss

Leaked Secrets and Unlimited Miles: Hacking the Largest Airline and Hotel Rewards Platform

Aug 3, 2023·21 min read

Between March 2023 and May 2023, we identified multiple security vulnerabilities within points.com, the backend provider for a significant portion of airline and hotel rewards programs. These vulnerabilities would have enabled an attacker to access sensitive customer account information, including names, billing addresses, redacted credit card details, emails, phone numbers, and transaction records.