The world of frequent flyer miles and credit card points has long been a target for cybercriminals. Traditionally, this took the form of account takeovers—hackers gaining unauthorized access to loyalty accounts to drain balances for last-minute, high-value award bookings. However, a troubling new trend has emerged that bypasses the traditional theft model entirely. Instead of stealing existing points, bad actors are hijacking the earning process itself, redirecting earned miles from legitimate travelers into fraudulent "ghost" accounts.
Recent reports, including a high-profile case involving Cathay Pacific and American Airlines, suggest that this sophisticated scheme is far more pervasive than previously realized. By manipulating the backend systems of airline partnerships, perpetrators are effectively siphoning thousands of miles from unsuspecting passengers before they even hit the travelers’ own accounts.
The Chronology of a Hijacked Itinerary
The mechanics of this scheme are best illustrated by a recent account provided to One Mile at a Time. A passenger, who had flown long-haul business class on Cathay Pacific, was performing a standard audit of his travel history when he noticed a discrepancy. Despite having provided his Cathay Pacific frequent flyer details at check-in, the miles for his flights had never posted.
Upon contacting Cathay Pacific’s customer service via WhatsApp, the traveler was informed that the miles had already been processed—but they were credited to an American Airlines AAdvantage account. The passenger, who maintains a dormant AAdvantage account, initially assumed a clerical error. However, the situation turned from a simple administrative mistake into a clear case of identity fraud.
- The Discovery: The traveler attempted to access his American Airlines account to rectify the error, only to find the account locked due to suspicious login attempts dating back to 2022.
- The Mismatch: After navigating the airline’s security protocols, the traveler confirmed with customer support that the miles were not credited to his personal AAdvantage number, but to a completely different, unauthorized account.
- The Digital Trail: By utilizing the password reset function on the American Airlines portal, the traveler discovered the unauthorized account was linked to an email address using a highly suspicious domain:
@qmdfcd.com. - The Geopolitical Link: A subsequent WHOIS domain lookup revealed that this specific email domain was registered in Beijing, China, suggesting a coordinated, international effort to harvest loyalty currency.
The Anatomy of the Scam: How It Works
This scheme represents a shift from "smash and grab" theft to a more surgical, data-driven approach. The question remains: how can a third party change the frequent flyer details on a booking after the passenger has already verified their own information at the airport?

Vulnerabilities in the Alliance Ecosystem
Airlines operate within complex "interline" and "codeshare" agreements. When a passenger flies on one carrier (Cathay Pacific) but chooses to credit the flight to a partner’s program (American Airlines), the data must travel across systems. Experts believe the vulnerability lies in the gaps between these disparate reservation systems (PNRs).
If a bad actor gains access to a Passenger Name Record (PNR) through leaked credentials or compromised travel agency software, they can theoretically inject a different frequent flyer number into the booking. Even if the traveler provided their own number, a secondary modification at the agent level—or via an automated script exploiting API vulnerabilities—can overwrite the original loyalty data.
The Rise of "Ghost" Accounts
The use of domains like @qmdfcd.com indicates that these criminals are setting up mass-produced, automated accounts. These accounts are designed to act as "sinks" for stolen miles. Once the miles land in these ghost accounts, they are often immediately liquidated. While high-value redemptions for international business class seats are the "gold standard" for miles, these thieves often settle for lower-value, high-velocity redemptions, such as merchandise, gift cards, or domestic economy tickets that are harder to track and easier to sell on the black market.
Supporting Data: A Systemic Issue
This is not an isolated incident. The prevalence of this issue is evidenced by growing threads on forums like FlyerTalk, where users have reported finding unknown loyalty numbers attached to their bookings.
Cathay Pacific has been at the center of these discussions, leading the airline to implement stricter policies. As of late 2025, the carrier stopped allowing passengers to switch frequent flyer numbers after check-in. While this was initially viewed by the public as a cost-cutting measure to prevent "gaming" of elite status perks, industry insiders now suggest it was a defensive maneuver to close a loophole that allowed malicious actors to swap loyalty data mid-trip.

The fact that these scams can persist even when the victim has their own physical boarding pass—which often displays the correct loyalty number—is a damning indictment of the lack of synchronization between airline databases. It suggests that once the flight is completed, the loyalty-posting systems are pulling data from a modified version of the record, rather than the original version captured at check-in.
Official Responses and Internal Security
When faced with these allegations, airlines are often ill-equipped to respond. In the case mentioned, the Cathay Pacific representative was reportedly dismissive, downplaying the potential for data compromise.
This reaction is emblematic of a broader issue: the "inside job" problem. Because these modifications often require access to travel agency portals or restricted airline back-end systems, there is a strong suspicion that the fraud is being facilitated by insiders—either corrupt employees or third-party contractors who sell access to PNRs on the dark web.
When victims approach airlines for recourse, they are often caught in a bureaucratic deadlock. American Airlines’ fraud department, for example, required the victim to first unlock his own account before they could even begin an investigation into the fraudulent one. This "account-first" security protocol, while designed to protect the user, inadvertently provides a buffer for the thief, allowing them time to drain the miles before the victim can regain control of their digital identity.
Implications for the Frequent Flyer Industry
The implications of this trend are significant for both the consumer and the aviation industry:

- Erosion of Trust: As loyalty programs become more digital and interconnected, the inability of airlines to protect the "currency" they issue threatens the perceived value of these programs.
- Increased Security Friction: Travelers should expect more stringent verification processes, including mandatory multi-factor authentication (MFA) for all loyalty account interactions, which may frustrate casual users.
- Data Privacy Liabilities: If these breaches are indeed the result of leaked PNR data, airlines may face increased scrutiny from regulators regarding their data handling practices with third-party partners.
Protecting Your Points: Best Practices
For the average traveler, the "Ghost Account" scam serves as a wake-up call. The days of treating frequent flyer accounts as "set it and forget it" repositories are over. To protect your loyalty currency, consider the following:
- Regular Audits: Do not wait for your miles to post. Check your accounts weekly, especially if you have recently completed a flight.
- Unique Credentials: Use unique, complex passwords for your loyalty accounts. If an airline doesn’t support MFA, use a password manager to ensure your credentials aren’t recycled from other breached sites.
- Monitor PNRs: If you have an upcoming trip, periodically check your reservation on the airline’s official website (not just the travel agent’s portal) to ensure your frequent flyer number hasn’t been altered.
- Report Discrepancies Immediately: If you notice a flight hasn’t posted, or if your account is locked, report it to the airline’s fraud department immediately. Do not accept a dismissive answer from a front-line customer service representative.
The "Ghost Account" phenomenon is a sophisticated evolution of cybercrime that exploits the very systems designed to make our travel easier. As long as loyalty miles continue to function as a form of currency, they will remain a target. The burden of security, for now, remains largely on the shoulders of the passenger—making vigilant account management the most effective defense against the growing industry of mileage theft.
