
An investigation recently published by NordVPN, a VPN service provider, and Saily, a travel eSIM application, reveals massive trafficking of loyalty data on the dark web. Airline loyalty accounts hacked, hotel histories divulged, passport numbers on sale over the counter: all this data that millions of travellers enter on travel-related sites finds itself exposed to potential identity theft and financial fraud.
Airlines, an Eldorado for cybercriminals
American Airlines, Southwest, Emirates, United, Alaska and Delta: they alone account for more than 54 % of conversations about airline cybercrime in the recesses of the dark web, according to NordVPN. Pirated accounts, sometimes containing hundreds of thousands of miles, are sold for modest sums: between 75 cents and 200 dollars (0.64 cents and 170 euros).
The modus operandi is well established. The hackers use phishing to extract identifiers, take advantage of data leaks or systematically test re-used passwords. Once inside, they empty the accounts by booking flights which they then resell, or transform the points into gift cards before disappearing into thin air.
" The travel industry is a lucrative target for hackers because of the sensitive personal and financial data it handles. Our research shows that airlines continue to experience data leaks, and this stolen information is finding a thriving market on the dark web. "explains Marijus Briedis, CTO at NordVPN. " Consumers should increase the security of their accounts, particularly during peak tourist periods when fraudsters are most active. ".
Hotels also in turmoil
Marriott tops the list of companies most affected: 35 % of hotel-related mentions on the dark web. Hilton, IHG and Accor complete the sad podium. The hacked databases are full of sensitive information: names, e-mails, holiday histories, and sometimes even passport numbers. Black market prices: up to $3,000 (€2,565) for the most expensive items.
" The price of stolen databases is not determined by their volume. What determines their value is sensitive information such as passport numbers, loyalty points or information linked to places or organisations that attract particular attention. High-value data such as this justifies much higher prices, prompting cybercriminals to target companies in the travel sector more aggressively. "explains Vykintas Maknickas, CEO of Saily.
How can you protect yourself effectively?
" Recent research shows that half of those questioned use the same password for several accounts, which considerably increases the risk of identity theft and financial fraud. "explains Marijus Briedis. " Using strong, unique passwords for each account and enabling multi-factor authentication is one of the easiest ways to protect yourself. Regularly check your connection history, activate alerts in the event of suspicious use of your points, and systematically use a VPN on public networks. ".
" Check your accounts before and after travelling. Travelling increases your exposure simply because you access your accounts more and don't always connect to reliable networks. Consider using a travel eSIM to minimise these risks. "advises Vykintas Maknickas.
Methodology : NordVPN and Saily examined five years of activity on the dark web using NordStellar's Dark Web Search tool to conduct this survey. The full survey is availableavailable here.




















