Account takeover happens when an attacker gains control of a member's loyalty account, usually with stolen or guessed credentials, then drains the balance by redeeming rewards, transferring points, or changing the account details to lock the real member out. Loyalty accounts are appealing targets because balances hold real value and often carry weaker protection than financial accounts.
The typical path starts with credentials leaked from an unrelated breach. Because people reuse passwords, attackers test those pairs against loyalty logins at scale, take over the accounts that match, and convert points to gift cards or transfer them out within minutes. The member often discovers the theft only when their balance is gone.
For an operator, account takeover combines a financial hit with a serious erosion of trust, since the member's stolen value is a promise the brand made. Defenses include strong or multi-factor authentication, monitoring for unusual login and redemption patterns, alerts on sensitive changes, and step-up verification before high-risk actions. The design goal is to stop takeovers without burdening the large majority of legitimate logins.