Loyalty fraud covers any scheme that steals or manipulates the value a program holds. Because points and miles convert to cash-equivalent rewards, a balance is a target much like a bank account. Attacks include taking over member accounts to drain points, enrolling fake members to harvest sign-up bonuses, manipulating balances from the inside, and reselling stolen rewards on secondary markets.
A frequent driver is credential stuffing: attackers test stolen username and password pairs against a program's login, take over the accounts that match, and quickly redeem or transfer the points before the member notices. Programs that watch less closely than banks do are attractive precisely because the theft can go unseen.
Fraud is both a financial loss and a trust problem for an operator. Drained accounts damage the member relationship the program exists to build, and losses come straight off program economics. Defense layers transaction monitoring, strong authentication, anomaly models that separate normal behavior from attacks, and alerts on high-risk actions like redemptions and transfers, balanced so security does not make legitimate members work harder than they will tolerate.