Stay current with our airline news coverage.
How Miles Get Hijacked Before They Even Post
So what exactly happened here? One Mile at a Time reports that this kind of scheme typically works like this: someone with access to airline systems, often an employee or contractor, spots a booking without a frequent flyer number attached. Or in some cases, they simply swap out the number that's already there. The traveler boards the flight, collects the boarding pass, and everything looks normal. But behind the scenes, the frequent flyer number on file has been changed, so when the miles post weeks later, they land in the fraudster's account, not yours. "This is often an inside job, meaning that an airline employee or airline contractor notices a ticket without a frequent flyer number and switches out the frequent flyer number, to 'intercept' the miles," One Mile at a Time reported. This fraud is harder to spot than a password breach. Your boarding pass can still display the correct program code, and you won't know anything's wrong until you check your account balance weeks or months later and realize the miles never arrived. By then, if you're past the airline's retro-claim window, you may be out of luck entirely. Cathay Pacific's retro-claim period is six months, according to the report; if the traveler discovered the problem after that deadline, there's no mechanism to claw those miles back. The reporting notes that this kind of mileage theft has been going on for at least 15 to 20 years, with particularly high incidence in the Middle East and Africa.The Strange Domain and What It Suggests
The @qmdfcd.com domain attached to the AAdvantage account is a red flag all on its own. It's not a recognizable email provider, and it's not the traveler's own address. One Mile at a Time suggests that fraudsters may create accounts with these obscure domains specifically to collect intercepted miles without tying them to a real identity. It makes the scheme harder to trace and gives the thief a clean path to book awards or sell the miles onward. What's particularly galling here is that the traveler had an American AAdvantage account of their own. The miles could have legitimately been credited there if the traveler had chosen AA as the earning program for the Cathay flight. Instead, someone else's AA account got the benefit, and the traveler got nothing.Why This Scheme Is So Hard to Stop
Unlike password theft, which leaves a login trail, mileage interception happens within airline systems that travelers can't see or audit. You rely on the airline to post credits correctly, and if someone with access decides to reroute those credits, you won't know until it's too late. There's no two-factor authentication that can stop this, no password reset that fixes it. The fraud happens before the transaction even touches your account. Airlines do have fraud detection systems, and loyalty programs can lock accounts if suspicious activity is detected (as happened with the traveler's AA account in 2022). But if the interception is subtle and the fraudster only grabs a few flights here and there, it may fly under the radar entirely. And once the retro-claim window closes, even a sympathetic customer service agent has limited power to help. Travelers can protect themselves somewhat by always adding a frequent flyer number at booking, double-checking that number on boarding passes, and tracking expected mileage posts closely. If miles don't show up within a few weeks of a flight, follow up immediately. Don't wait months; airlines won't always bend the rules for late claims, even when fraud is involved.The Booking Calculus Just Got More Paranoid
This case is a good reminder that loyalty fraud isn't just about hackers guessing weak passwords. Sometimes the threat is internal, and sometimes the miles disappear before they ever hit your account. That's a harder problem to solve, because it requires airlines to police their own employees and contractors, audit ticketing workflows, and respond quickly when travelers report discrepancies. For travelers, the lesson is simple but frustrating: check your mileage posts obsessively, especially on premium-cabin tickets where the stakes are high. Set calendar reminders if you need to. Screenshot your boarding passes. And if something looks off, don't wait to investigate. Once that retro-claim window closes, your miles might be gone for good, and the person who took them may be long gone too. The fraud described here isn't new; it's been around for decades. But it's still catching people by surprise, and that's exactly what makes it effective. If your miles go missing and you never had your password stolen, this might be why.More travel news
Over 200 Asian Flights Canceled Across 3 Countries
JAKARTA, Indonesia - Garuda, AirAsia, Malaysia Airlines, Lion Air, and Batik Air face over 200 flight cancellations across Indonesia, Malaysia, and Hong Kong, stranding travelers on domestic and international routes.
Hong Kong Seizes Devices If Travelers Refuse Passwords
HONG KONG — Refusing to unlock your phone or laptop for Hong Kong authorities is now a criminal offense under expanded national security regulations.
Top Global Airports Ranked by Amenities and Experience
GLOBAL — An industry veteran weighs in on the world's top airports, from butterfly gardens to business-class lounges, and why no single hub can claim the crown for everyone.
United warns Delta’s LAX-Hong Kong launch will lose money
Los Angeles travelers gain a new nonstop option to Hong Kong on June 6 as Delta returns to the route, intensifying a three-way rivalry with Cathay Pacific and United.