TL;DR: Loyalty reward fraud is rising through fake sign-ups, account takeovers, and abusive redemptions, with Strivacity citing The Loyalty Security Association’s estimate of $3.1 billion in fraudulent points redeemed and about $1 billion in annual losses. The weak point is customer identity flow design, where sign-up, sign-in, and redemption controls still let synthetic accounts and compromised credentials move too far.
At a glance
What this is: This is a CIAM fraud analysis showing how loyalty programmes are being targeted through fake registrations, account takeover, and risky redemptions.
Why it matters: It matters because customer identity controls now shape both fraud loss and customer experience across enrolment, authentication, and rewards fulfilment.
Context
Loyalty reward fraud is a customer identity problem, not only a rewards abuse problem. When fake sign-ups, credential theft, and suspicious redemptions are allowed through the same customer journey, the programme loses money at multiple stages instead of at one obvious point of failure.
The control gap is in the CIAM flow itself. Registration, authentication, and reward redemption need to be governed as one trust chain, because fraudsters exploit the handoff between them far more effectively than a single isolated control.
For identity teams, this is a reminder that consumer access risk behaves differently from workforce identity risk. The account may be low friction by design, but low friction cannot mean low assurance when points can be converted into direct financial loss.
Key questions
Q: What breaks when loyalty programmes rely on sign-up checks alone?
A: Sign-up checks only protect the first gate. Loyalty fraud usually succeeds when attackers move from registration to login and then to redemption, where value is extracted. If assurance is not repeated at the point of use, synthetic accounts and stolen credentials can pass the programme’s weakest control and convert rewards into direct loss.
Q: Why do compromised customer credentials create so much loyalty fraud risk?
A: Because customer accounts often need only a valid login to expose rewards value. When passwords are reused, phished, or breached, attackers can access the account and redeem points before the fraud is visible. The risk grows when programmes lack device history, geolocation checks, or step-up rules at the moment of redemption.
Q: What are the signs that loyalty fraud controls are not working?
A: Watch for rapid sign-up spikes, repeated use of disposable phone numbers, unusual login locations, proxy traffic, failed breached-password attempts, and redemption requests that do not match normal customer behaviour. A rise in support complaints about missing points is often a late indicator that the control surface is too weak or too fragmented.
Q: Should teams treat loyalty redemption as an authentication event?
A: Yes. High-value redemption is where identity assurance becomes financial control. If a points transaction can trigger real loss, it deserves its own trust check, whether that is re-authentication, step-up challenge, or a temporary hold for review. The control should follow the value being released, not just the user logging in.
Technical breakdown
How fake sign-ups bypass customer assurance
Fraud at loyalty enrolment usually starts with synthetic accounts, bots, or stolen identity data. The technical weakness is that registration systems often accept self-asserted attributes too early, before identity proofing, contact validation, and breached credential checks have enough context to separate real customers from fabricated ones. Bot signals such as rapid-fire sign-ups, repeated IPs, and disposable phone numbers are useful because they expose scale, not just intent. In loyalty environments, the goal is to stop account creation abuse before incentives create a monetisable identity at all.
Practical implication: harden sign-up with layered proofing, bot detection, and breached-password checks before welcome offers are issued.
Why account takeover works so well in loyalty flows
Account takeover succeeds when compromised credentials are still enough to reach the account, especially where password reuse and weak step-up rules remain common. Adaptive access shifts the control point from static authentication to contextual risk evaluation, using device recognition, geolocation, impossible travel, proxy detection, and behaviour analytics to decide when additional proof is needed. In CIAM terms, this is not just MFA usage. It is trust recalculation at every login attempt, so a stolen credential is not automatically treated as a legitimate customer session.
Practical implication: challenge risky logins with context-aware authentication instead of relying on passwords alone.
How risky redemptions become the loss event
Many loyalty attacks only become visible when points are redeemed unusually fast, at high value, or from patterns that do not match the account’s normal behaviour. That matters because the redemption step is often the conversion point from suspicious access to real monetary loss. Controls such as re-authentication for high-value redemptions, geolocation checks, and temporary account disablement work because they create a second trust checkpoint before value leaves the programme. Without that checkpoint, stolen points are often spent before investigations begin.
Practical implication: add step-up controls and hold rules at redemption thresholds where fraud turns into cash-equivalent loss.
Threat narrative
Attacker objective: The attacker’s objective is to monetise loyalty points through fraudulent redemption while avoiding early detection.
- Entry begins with fake sign-ups, credential stuffing, or compromised customer credentials that allow an attacker into the loyalty environment.
- Escalation occurs when the attacker moves from basic access to account control, then exploits weak trust checks across sign-in and reward redemption.
- Impact follows when points are redeemed, drained, or converted before the fraud is detected, creating direct loss and customer churn.
Breaches seen in the wild
- 23andMe credential stuffing 2023: Credential stuffing into 18,000 accounts exposed nearly 7 million people through the DNA Relatives feature.
- Gitloker GitHub extortion campaign: Phishing via GitHub notifications tricked developers into authorising malicious OAuth apps; Gitloker then wiped repos and demanded contact.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Loyalty fraud is a CIAM failure before it is a rewards problem. Loyalty programmes lose money when registration, authentication, and redemption are treated as separate controls instead of one customer trust chain. The article shows that attackers exploit whichever stage has the weakest assurance, then convert that gap into financial loss. Practitioners should read loyalty fraud as a customer identity governance issue, not just a commercial abuse problem.
Customer identity assurance has to be dynamic at the point of value transfer. Static sign-up checks do not protect a programme when the real loss happens at redemption. Behavioural risk, device history, and contextual authentication matter because fraud becomes materially relevant only when the account can be used to extract value. The implication is that CIAM design must shift from access eligibility to transaction trust.
Reward programmes create a low-friction identity surface that fraudsters can industrialise. Welcome bonuses, referral incentives, and high-volume redemptions all increase the economic value of a single compromised account. That makes loyalty identity flows an attractive target for synthetic identity fraud and account takeover in ways that ordinary consumer logins are not. Practitioners should assume the abuse economics will keep improving.
“Trust at redemption” is the named control concept this article surfaces. The critical control point is no longer only account creation, but the moment points become spendable value. Redemptions need their own assurance threshold because fraudsters often wait until that phase to cash out. The practical conclusion is that identity policy must follow value, not just login.
CIAM telemetry becomes fraud telemetry when teams correlate sign-up, login, and redemption signals. Fragmented views leave fraud hidden until complaints arrive. The article’s operational lesson is that support, marketing, and identity teams need a shared evidence chain so suspicious behaviour can be interpreted across the customer lifecycle. Practitioners should align detection, investigation, and customer comms around the same identity signals.
From our research library:
- Nearly 60% of companies reported that fraud losses were still increasing in 2025.
What this signals
Trust at redemption is the control boundary that matters most here. Loyalty fraud becomes materially harder to contain when programmes only validate identity at sign-up and then assume the session remains trustworthy forever. The better governance model is to re-check trust when points become spendable value, because that is when fraud converts into loss.
Customer identity programmes for loyalty should be evaluated against the full fraud chain, not just the authentication step. If bot-driven sign-ups, breached credentials, and redemption abuse are measured separately, fraudsters exploit the seams between the controls. Teams need one operating picture across acquisition, access, and value transfer.
Fraud, support, and marketing teams need shared telemetry because loyalty abuse is both a security event and a customer experience event. The more quickly suspicious accounts are correlated across enrolment, login, and redemption, the less likely it is that losses will be discovered only after customers complain.
For practitioners
- Harden loyalty sign-up assurance Add identity proofing, breached-password screening, phone risk checks, and bot detection before welcome rewards are issued.
- Apply contextual controls at login Use device history, proxy detection, geolocation checks, and behaviour analytics to challenge suspicious customer sessions without adding friction to routine logins.
- Gate high-value redemptions Require re-authentication or step-up approval when redemption value, location, or device signals diverge from normal customer behaviour.
- Correlate fraud signals across the journey Unify sign-up failures, risky logins, redemption anomalies, and repeated resend requests into one investigation view for fraud and support teams.
- Disable suspicious accounts during review Suspend accounts automatically when multiple risk indicators converge so investigators can contain point theft before further redemptions complete.
Key takeaways
- Loyalty reward fraud is primarily a CIAM governance problem because attackers exploit the handoff between registration, login, and redemption.
- The article cites $3.1 billion in fraudulent points redeemed and about $1 billion in annual losses, which shows the scale is already material.
- The decisive control is to add risk checks at the point where rewards become spendable, not only at account creation.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-04 — Insecure Authentication | Weak customer sign-in and step-up flows let stolen credentials reach loyalty accounts. |
| NHI-10 — Human Use of NHI | Fraudsters abuse customer identities and support flows to extract loyalty value. | |
| NHI-02 — Secret Leakage | Breached passwords and reused credentials are a direct input to account takeover. | |
| Recommendation — Harden customer authentication where loyalty value can be redeemed. Separate legitimate customer behaviour from abusive automation and account misuse. Scan breached credentials and revoke access before reward redemptions are allowed. | ||
| NIST SP 800-53 Rev 5 | IA-8 — Identification and Authentication (Non-Organizational Users) | Customer identities in loyalty programmes map directly to external-user authentication controls. |
| IA-5 — Authenticator Management | Password reuse, breached-password checks, and step-up credentials all sit in authenticator lifecycle. | |
| Recommendation — Apply IA-8 to raise assurance for customer access at sign-up and login. Use IA-5 to manage customer authenticators and reject known-compromised credentials. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | Loyalty redemptions are entitlement decisions that should be governed by contextual authorisation. |
| Recommendation — Tie redemption access to PR.AA-05-style entitlement checks and step-up decisions. | ||
Key terms
- Loyalty Fraud: Loyalty fraud is the theft, abuse, or monetisation of rewards account value through compromised access, manipulated transactions, or policy loopholes. It becomes a security issue when points, vouchers, and account data can be converted into real-world value without strong identity assurance.
- Synthetic Identity Document Fraud: Synthetic identity document fraud is the use of fabricated or AI-generated identity documents to impersonate a real or invented person. It targets verification workflows by presenting fake passports, driver’s licences, or IDs that can look credible enough to pass basic checks unless teams use stronger authenticity and anomaly detection controls.
- Risk-Based Authentication: An access model that changes verification requirements based on the estimated risk of the request. It combines identity assurance, device posture, application sensitivity, and contextual signals to decide whether to allow, block, or step up verification before access is granted.
- Step-up Authentication: Step-up authentication is an additional verification step triggered when a session becomes higher risk or a user attempts a sensitive action. It is used to reduce exposure without forcing extra friction across every interaction, which makes it useful for runtime access governance.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
Published by the NHIMG editorial team on June 7, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org