By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: Here’s how to protect yourself from cyber bandits stealing loyalty points
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > News > Here’s how to protect yourself from cyber bandits stealing loyalty points
News

Here’s how to protect yourself from cyber bandits stealing loyalty points

News Room
Last updated: 2025/09/13 at 4:35 PM
News Room Published 13 September 2025
Share
SHARE

CYBER criminals are stealing loyalty card points in a black market worth £300million, the Sun on Sunday can reveal.

So-called “points bandits” are targeting the likes of the Nectar and Boots Advantage schemes — with up to five per cent of Brits affected.

7

‘Points bandits’ are targeting the likes of the Nectar and Boots Advantage schemesCredit: Getty
Woman holding a Nectar card after having points stolen.

7

Julie Dowling lost 46,000 points worth £230Credit: Stewart Williams
Man sitting in an airplane seat with a glass of champagne.

7

Rhys Jones lost 500,000 points worth £2,500Credit: supplied

Gangs use artificial intelligence to spew out multitudes of random card numbers, until they land on a valid one by chance.

Then they are able to generate barcodes and steal the points from loyal customers.

Cyber crime expert Frank Teruel, the chief operating officer at anti- cyber crime platform Arkose Labs, told The Sun on Sunday: “This is loyalty card cyber warfare.

“It’s the same as taking cash. But here’s the difference.

“If you walk into a Lloyds branch in London and steal some money, you’ll probably be caught and go to prison.

“If you steal someone’s points online and you are potentially miles away, it’s a really difficult problem.

‘Despicable thing to do’

“Loyalty cards, right now, are the point of least resistance.

“It’s probably the least protected digital currency you have.”

Last year the Competition and Markets Authority found 97 per cent of shoppers are members of at least one supermarket loyalty scheme, and on average consumers belong to three.

And, according to the latest research, Brits have an estimated £6billion of unclaimed loyalty points stacked up on cards.

AI tricks to beat scammers as scam texts, calls and emails surge

Now a new global survey from the Loyalty Security Alliance and Arkose Labs reveals up to five per cent of loyalty cards have been compromised.

The alliance says that the ­figure “reflects the UK market”, meaning £300million of points are at risk of being drained.

Julie Dowling, 50, from Crayford, Kent, was horrified when 46,000 Nectar points worth £230 were taken from her account in June.

Julie, a cleaner, and her builder husband Keith, 54, had been saving up the points to spend on their Christmas food shop in Sainsbury’s.

She said: “Nectar thieves stole my family’s Christmas money.

“It’s a despicable thing to do.”

The message she was sent revealed 46,000 points had been deducted in St Albans, Herts.

She was left with 1,159 points worth £5.79.

Julie, who got her points refunded, warned: “People need to know as it’s just like stealing money out of your wallet or purse.”

5 WAYS TO PROTECT YOURSELF

HERE are Loyalty Security Alliance co-founder Michael Smith’s five steps to protect loyalty card cash.

  1. Your online loyalty program has real money sitting behind the points. Treat it like your bank account – you’ve earned it.
  2. Don’t use the same password across your accounts. There are lots of free password managers – Apple and Google both offer that service and companies like LastPass have free services.
  3. If your loyalty scheme offers two-factor authentication, use it because it makes it a bit harder to have your account taken over.
  4. Check your balances from time to time (and take advantage of your points!) so you know they are still there.
  5. Be careful in replying to texts or emails asking you to log into your account. These could be phishing attempts to access your personal data.

Community midwife Gail Birch had 15,800 Nectar points, worth £79, stolen in February.

They were used to make a purchase in London’s Finsbury Park — 150 miles away from her home in Bridgnorth, Shrops.

Gail, 69, said: “I feel quite sick to think that someone targeted me.

“It’s awful.”

While in April retired Metropolitan Police support staff worker Helen Maitland had almost all of her Nectar card balance drained.

Helen, 61, of Bexley, Kent, had 3,500 Nectar points, worth £17.50, pinched when her card was drained leaving just £2 worth behind.

She said: “Cyber crooks must be raking it in.”

Sainsbury’s was forced to issue a warning in June after it was reported 12million Nectar points — worth £63,000 — had been stolen in 2024.

The spate of thefts saw the retailer add a ‘Spend Lock’ feature to its Nectar loyalty app that prevents your points from being redeemed without your knowledge.

Points a hot target

Jennifer Bruton, a cyber crime consultant at Bores, said: “The problem is that to spend points with something like a Nectar card all you need is the barcode — and the card numbers which are used to create the barcode are predictable.

“Nectar is aware of the issue, and in most cases, they’ll refund the ­stolen points.”

But some loyalty card hacks are more sophisticated.

Organised crime gangs based in China, Russia and Africa use industrial scale phishing enterprises — sending scam emails or other messages purporting to be from reputable firms, to steal logins and take over loyalty accounts.

Photo of Helen Maitland, who had her Nectar card points stolen.

7

Helen Maitland lost 3,500 points worth £17.50Credit: Stewart Williams
Man working on laptop at night.

7

Cyber gangs use artificial intelligence to spew out multitudes of random card numbersCredit: Getty

In 2020, Boots was forced to ­suspend its Advantage Card payments after hackers attempted to access 150,000 customer accounts using a tactic called “password stuffing” — where criminals use leaked usernames and passwords to break into other sites.

Tesco Clubcard suffered a similar attack in the same year, affecting more than 600,000 users.

The Loyalty Security Alliance and Arkose Labs’ report The Silent Threat — shared exclusively with The Sun on Sunday — found that airlines and holiday loyalty schemes are a hot target for cyber criminals.

Their survey found 68 per cent of hotels are concerned about points theft, with travel ­booking sites ­facing “persistent threats from cybercriminals”.

Rhys Jones had 500,000 Avios points — worth at least £2,500 — swiped from his British Airways Executive Club household account this year.

BA’s fraud team restored the accounts, reset the email details and said the stolen points would be returned.

Rhys, 29, a travel writer with frequent flyer website Head Of Points, warned that Avios points were increasingly being ­targeted.

Woman holding a Nectar card.

7

Gail Birch lost 15,800 points worth £79Credit: Roland Leon
Frank Teruel, Chief Operating Officer of Arkose Labs.

7

Cyber crime expert Frank Teruel, chief operating officer at anti-cyber crime platform Arkose LabsCredit: Supplied

He said: “With an ever-growing number of partners, Avios is becoming a target for hackers who know it is a versatile currency with many opportunities for attack.”

Customers are urged to check their balance regularly and cash in their points to protect against theft.

But those who find themselves victims of points fraud can face difficulties in seeking justice.

Under the Home Office’s Counting Rules for fraud, loyalty scheme fraud is not covered.

It means there is confusion over how to best prosecute the crime.

Consumer champion Martyn James said: “Even though the points aren’t cash, they can be ­converted into virtual money — so we vitally need to change the fraud rules so the theft of these points is treated just as seriously as any other type of fraud.

“Leaving customers at the mercy of scammers is unacceptable, ­particularly given that there’s no ombudsman scheme or regulator for the retail industry.”

A Sainsbury’s spokesperson said that the security of Nectar accounts was a “highest priority” and insisted that the number affected by points theft was “small”.

A British Airways spokesperson said: “We always investigate any alleged instances of fraud against our members.”

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article How to Watch the 77th Emmy Awards Without Cable
Next Article Galaxy S25 Ultra plunges in price, making it an even smarter purchase
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

Generative AI: Is It Moving From Large Language Models to Small Languge Models? | HackerNoon
Computing
What is Handheld Laser Welder and How it Works
Gadget
New iPhone 18 and iPhone 18 Pro Rumors: Smaller Dynamic Island, No Under-Screen Face ID
News
Google Tasks may be getting an upgrade that makes it worthy as a standalone app (APK teardown)
News

You Might also Like

News

New iPhone 18 and iPhone 18 Pro Rumors: Smaller Dynamic Island, No Under-Screen Face ID

7 Min Read
News

Google Tasks may be getting an upgrade that makes it worthy as a standalone app (APK teardown)

3 Min Read
News

5 shows that start slow but become unforgettable

7 Min Read
News

Today's NYT Connections: Sports Edition Hints, Answers for Sept. 14 #356

3 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?