SAT Exam Hub
Loyalty Account Hacked? 7 Recovery Steps for Students
Your loyalty points or miles have been stolen. This 7-step guide shows you the exact order of actions to maximize your chances of recovery, including the critical weekend gap and the police report requirement that many students miss.
- SAT
- ACT
- GRE
- MCAT
- ASVAB
- digital-sat
- adaptive-testing
- registration-fee
- content-outline
- score-target

If your airline miles, hotel points, credit-card rewards, or retail loyalty balance just disappeared, treat the next 48 hours like a recovery window. For students, recovering a hacked loyalty account is not the same as disputing a credit-card charge. Recovery is possible, but loyalty points generally do not get the same Fair Credit Billing Act protection that caps credit-card fraud liability; program terms often define points as belonging to the issuer, not the member, and restoration depends heavily on the provider’s process.[1]
That means the first move is not to argue about fairness. The first move is to create a clean trail: account locked, fraud department contacted, timestamps saved, police report filed if the program asks for it, and escalation ready if the first answer is no. You can do that while you are still studying for the GRE, MCAT, SAT, ACT, or ASVAB, but only if you stop treating this as a vague “password problem” and start treating it as a claim file.
The First 48 Hours: Do These in Order

| Order | Action | Why It Comes Here |
|---|---|---|
| 1 | Confirm what was stolen and preserve what you see | You need the original balance, redemption, email-change notice, or order details before screens change. |
| 2 | Contact the provider’s fraud department | The provider controls the account lock, reversal review, and case number. |
| 3 | If it is the weekend, use every available channel | Some fraud departments operate weekdays only, and weekend delays can give the attacker more time. |
| 4 | Lock down the account, email, and payment methods | A password reset alone may not remove the attacker if email forwarding or account recovery settings were changed. |
| 5 | Build the documentation packet | Screenshots, timestamps, ticket numbers, and call notes make the claim easier to review. |
| 6 | File a police report when required or when the loss is significant | Some programs may require a report before restoring miles or points. |
| 7 | Escalate if denied, then monitor for reversals and repeat access | A first refusal is not always the final answer, especially when you can provide a stronger record. |
1. Confirm the Theft Before You Change Everything
Before you reset anything, capture the evidence that proves the account changed. Take screenshots of the current balance, the missing balance if your account history shows it, the suspicious redemption, delivery address, linked email, linked phone number, new device alert, password-change notice, and any gift-card or travel booking details. If the account shows a time zone, IP location, or device name, save that too.
Write down the discovery time in your own notes. For example: “July 23, 2026, 9:14 p.m. UTC: opened airline account, saw 0 miles, account history shows redemption I did not make.” That line helps you keep a stable timeline when the provider asks when you last saw the points, when you discovered the theft, and whether you authorized the redemption.
Do not spend an hour digging through forums before you call. Confirm enough to describe the problem, save the screens, then move to the provider. The company that runs the program is the only party that can freeze the loyalty account, review the redemption, and decide whether to restore the points.
2. Call the Provider’s Fraud Department, Not General Support
Use the official website or app to find the fraud, security, account takeover, or loyalty-program support number. Do not call a number from a random search result or an email link. If the program has no separate fraud line, call the main number and say clearly: “My loyalty account appears to have been taken over, and points were redeemed without my authorization. I need the account locked and a fraud case opened.”
Ask for four things before the call ends: a case number, the account-lock status, the documents they require, and the expected review timeline. If they tell you to file a police report, ask whether the report number is enough or whether they need a full copy later. If they say the redemption is still pending, ask whether it can be stopped before fulfillment.
- Keep the call short and factual: account number, missing points, unauthorized redemption, discovery time, and whether your email or phone number was changed.
- Do not guess how the attacker got in. Say “I do not recognize this redemption” rather than inventing a cause.
- Ask the agent to note that you are requesting preservation of records connected to the unauthorized redemption.
- If you are disconnected, call back and give the previous case number instead of starting from zero.
This is also where expectations matter. If a stolen credit-card charge appears, federal protections may limit your liability. With loyalty points, the provider’s terms and internal review process matter much more. That does not mean you should accept a loss. It means your best leverage is a fast, well-documented claim that gives the fraud team a reason and a record to reverse the redemption.
3. If It Is Friday Night, Saturday, or a Holiday, Do Not Wait Quietly
Weekend timing is not a footnote. KCRA reported in May 2026 that fraud departments at major programs often operate Monday through Friday, and that attackers may exploit the weekend gap when customers cannot quickly reach the right team.[2] For a student, that gap is exactly how a small account problem eats the weekend you were supposed to use for a practice test.
If the fraud department is closed, still create records before Monday. Use the provider’s secure message center, app chat, web form, and general customer-service line if available. Send a concise message: “I discovered unauthorized redemption activity on my loyalty account today. Please freeze the account, block further redemptions, and open a fraud review. I did not authorize the transaction.” Save the confirmation screen or email.
If the account is tied to a credit card, call the card issuer’s fraud number too. Make clear whether the card itself has unauthorized charges or whether the issue is limited to points. The card issuer may not be legally required to restore rewards in the same way it handles card fraud, but it can still lock access, replace a card if needed, and document the linked-account compromise.
4. Lock the Account, Then Check the Email Account Behind It
After the provider has a record of the fraud claim, change the loyalty account password from a trusted device. Use a password you have never used anywhere else. Turn on multi-factor authentication if the program offers it. Remove unfamiliar phone numbers, emails, addresses, authorized users, saved payment methods, and connected shopping or travel partners.
Then check the email account connected to the loyalty program. This step is easy to skip because it feels like a separate problem, but it may decide whether the attacker gets back in. The FTC advises people recovering hacked accounts to update security software, change passwords, review account settings, and tell contacts if needed.[3] The UK National Cyber Security Centre also emphasizes checking account settings and recovery details when recovering a hacked account.[4]
Look specifically for forwarding rules, filters, delegated access, unfamiliar recovery emails, unfamiliar recovery phone numbers, and recently connected devices. A forwarding rule can quietly send password-reset messages to the attacker even after you change the loyalty password. If you find one, screenshot it, remove it, and include it in your documentation packet.
- Email: remove forwarding rules, unknown filters, and unknown recovery options.
- Loyalty account: remove unfamiliar addresses, linked cards, devices, and partner accounts.
- Card or bank account: check for unauthorized charges, not just missing rewards.
- Shared devices: sign out of all sessions before logging back in.
5. Build a Documentation Packet While the Details Are Fresh

Create one folder for the claim. It can be a cloud folder, a laptop folder, or a notes app if that is all you have. The format matters less than the fact that you can find everything fast when a fraud agent asks for it during a ten-minute call between class and work.
- Screenshots of the missing balance, unauthorized redemption, account-history page, and profile changes.
- Copies of password-change alerts, redemption confirmations, shipping notices, or email-change notices.
- Provider case numbers, chat transcripts, secure-message confirmations, and names or IDs of agents if given.
- A timeline with dates, times, what you noticed, whom you contacted, and what each person told you.
- Police report number or report copy if filed.
A clean packet changes the conversation. Instead of saying “my points are gone,” you can say, “Case 18472 was opened on July 23. The unauthorized redemption posted at 2:08 a.m. I filed police report number 26-1049. I have screenshots of the changed email and the redemption confirmation.” That gives the next reviewer something to act on.
6. File the Police Report If the Program Requires It
A police report can feel excessive when the stolen item is “just points,” especially if you are already behind on a study schedule. But in loyalty theft, it may be the document that moves the claim from sympathy to procedure. KCRA reported a case in which American Airlines restored 449,500 stolen miles, valued at about $13,260, after the customer filed a police report.[2] Montgomery County Police also tells victims of airline mileage theft to file a police report and contact the airline’s fraud department.[5]
You do not need to solve the crime for the report. Report what you know: the account, the unauthorized redemption, the approximate value if the provider shows one, when you discovered it, and what the provider told you. If your local police department lets you file online, use that. If you are away at school, start with the jurisdiction where you live now or where the theft was discovered, then follow the department’s instructions if they direct you elsewhere.
Ask for a report number immediately, even if the full report will take longer. Then send that number to the provider through the same case thread if possible. Do not rely on a phone promise that “we added it.” Upload it, message it, or email it in a way that gives you a timestamp.
7. Escalate If the Provider Says No
A denial is not always the end, but the next appeal should be tighter than the first complaint. Ask the provider to explain the reason for denial in writing. Then respond with the case number, police report number, timeline, screenshots, and the specific remedy you want: restoration of the stolen points, reversal of the unauthorized redemption, or reopening of the fraud review.
The Chase case reported by Elliott.org is a useful reminder that procedure can change the result. Chase initially refused to restore 200,000 points, worth about $2,000, after saying the customer had received fraudulently ordered gift cards. After executive-level escalation, Chase restored the points.[6] That does not prove every denial can be overturned. It does show why a student should not stop at the first front-line refusal when the documentation is strong.
Escalation can mean a supervisor, an executive customer-relations office, the issuer’s written dispute channel, or a regulator-forwarded complaint when a bank or credit-card issuer is involved. A CFPB complaint may be relevant for a financial institution because it creates a formal paper trail that is forwarded for response; it is not a magic restoration button, and it may not fit every airline, hotel, or retail program.
Keep the escalation letter boring. Emotional detail is understandable, but the reviewer needs a file they can verify. Lead with the account, the unauthorized transaction, the provider case number, the police report number if you have one, and the exact action requested.
Short Escalation Template
Subject: Request to reopen fraud review for unauthorized loyalty redemption
I am requesting review and restoration of points removed from my account without authorization. Provider case number: [case number]. Police report number: [report number, if available]. I discovered the issue on [date/time]. The unauthorized redemption appears on [date/time] for [points/miles amount or item]. I did not authorize this redemption and did not receive the benefit. I have attached screenshots, account notices, and my timeline. Please reopen the fraud review, preserve records connected to the redemption, and confirm the next review step in writing.
How Big Is the Problem?
The broad scale numbers are useful, but they should not scare you into paralysis. Industry sources cited by OpenLoyalty estimate that loyalty fraud accounts for about one in four online fraud attempts and costs U.S. programs about $3.1 billion annually.[7] Frommer’s, citing Sift, reported that account-takeover attacks on loyalty programs rose 307% between 2019 and 2021.[1] Treat those as moderate-quality industry indicators, not student-specific incidence data.
There is no single study here showing that college students are uniquely likely to lose loyalty points. What is reasonable to say is narrower: students often rely on accounts they do not check daily, may reuse passwords across school, work, shopping, and travel accounts, and may sign in from shared or borrowed devices. Bitdefender reports that 57% of loyalty-program members never check their balances, which gives attackers more time before anyone notices.[8]
That is why the recovery plan is built around speed and records, not perfect cybersecurity theory. If you were saving points for a flight home, a test-center hotel, or gift cards during a tight month, the practical question is whether you can put a credible claim in motion before the redemption becomes harder to reverse.
After the Claim Is Open, Keep the Account Quietly Watched
Once the fraud case, police report, and escalation path are moving, you can shift from emergency mode to monitoring. Check the loyalty account daily for the first week, then weekly until the provider closes the case. Watch for restored points, reversed redemptions, new profile changes, new shipping addresses, and fresh password-reset emails.
If the points are restored, do not immediately redeem everything unless you actually need to. First confirm that the attacker is locked out: new unique password, multi-factor authentication if available, clean email forwarding settings, current recovery phone and email, and no unfamiliar connected partners. If you are trying to get back to MCAT prep or a GRE study block, this is the point where a fifteen-minute calendar reminder is better than checking compulsively all night.
This article is not legal advice, and program terms vary. The hard truth is that students cannot force restoration of loyalty points the same way they can dispute certain protected card charges. The useful truth is that you can improve your odds by moving in the right order: provider first, account lockdown, documentation, police report when required, escalation if denied, and monitoring until the account stays clean.
References
- Hackers Can Steal Your Frequent Flier Miles — Frommer's
- Hackers target loyalty rewards points possibly worth thousands — KCRA, May 2026
- How To Recover Your Hacked Email or Social Media Account — FTC
- Recovering a hacked account — UK NCSC
- Airline Mileage Theft — Montgomery County Police
- Stolen rewards points: What to do when Chase won't help you — Elliott.org
- Loyalty fraud: Risks, examples, and how to prevent program abuse — OpenLoyalty
- Loyalty Fraud: What it is, how it happens and what you can do about it — Bitdefender
Related exhibits & inventory
Verified outcomes
No verified outcomes on file for this exam yet
See Methodology for how outcome evidence is disclosed once logged.
Planners
No planner filed for this exam yet
A downloadable timeline template for this exam hasn't been published yet.
Tool verdicts
AI-tool cautions
No AI tools tested for this exam yet
No hands-on AI-accuracy logs have been filed for this exam.
Questions about this plan
Ask a question about a specific section, timeline, or citation in this plan — or flag something that needs correcting.

Comments
Join the discussion with an anonymous comment.