There is a thriving, shadowy market for trading loyalty points. We hear about hacked accounts and stolen miles constantly. But there is a darker, more intricate twist. Someone intercepted a traveler’s flights. They got the miles credited to an account they created. The victim didn’t even know it happened until months later.
This isn’t just a glitch. It’s a deliberate scheme. I first covered this story yesterday. But new details have emerged. We now understand better how these intercepts happen. And why Cathay Pacific passengers are specifically targeted.
The Discovery
An OMAAT reader shared a chilling experience. He was organizing past flights from last year. He hadn’t credited the miles yet. He was flying long-haul business class on Cathay Pacific. Award tickets. No elite status.
He looked at his boarding passes. The frequent flyer program listed was Cathay Pacific. So he logged into his account. No miles.
He checked the six-month window for filing claims online. It had passed. So he tried WhatsApp customer service.
Here is where it got strange.
The agent told him the flights were credited to “American.” The traveler assumed this meant an American airline. American Airlines. Alaska Airlines. He checked his Alaska Mileage Plan account. Nothing.
He re-read the message. American Airlines. He tried his AA account. It was locked.
The account had been locked since 2022. Someone had been trying to log in. He never used AA. He must have missed the security alerts. Or ignored them. He finally retrieved his AA number.
He called Cathay Pacific again. The agent confirmed. The miles went to American AAdvantage. Not his number. A different account number.
The traveler tested that new number. He used the password reset tool on American’s site. He entered his own name. The fraudsters would need the matching name to credit miles, right?
It worked. The account existed.
But the email? A bizarre domain: @qmdfcd.com.
He did a WHOIS search. The domain was registered in Beijing. Last year.
He called American Airlines. They called it “bizarre.” They said they’d never seen anything like it. They opened a fraud case. But first? He had to unlock his own account.
Cathay Pacific’s agent? Dismissive. Unhelpful. No concern about compromised data.
Let’s simplify. This person’s Cathay Pacific miles were diverted. To an American Airlines account he didn’t control. An account linked to a shell domain in China.
Why This Matters
Most mileage theft involves hacking an account. Stealing miles. Redeeming them for last-minute tickets. The traveler often doesn’t know until the airline cancels the booking. It’s lucrative. A hacker gets a million miles.
This scheme? Less obvious. You can only credit miles to a matching name. Usually. So you can’t just dump them in a void. The volume per ticket is small. Not worth millions.
But look at the bigger picture. This is common. Much more common than I thought.
How does it work?
Often an inside job. An airline employee. A contractor. They see a ticket without a frequent flyer number. Or one they can change. They swap the number. They intercept the miles.
Or they pick up used boarding passes. No FF number printed. They add their own.
They create accounts. Matching the passenger’s name. To bypass validation checks. Then they cash out. Maybe not for a first-class ticket. But for merchandise. Or gift cards. Or cash-back options. It adds up.
This is particularly bad for Cathay Pacific. The airline recently changed rules. Stopping passengers from switching frequent flyer numbers after check-in. Late 2025.
I thought it was about elite perks. Earning miles in one program, spending them in another. Turns out, the primary motivation is likely fraud prevention. Stopping intercepts.
The Red Flags
Notice the domain. qmdfcd.com. It looks random. It was registered in Beijing.
The account was locked for years. The fraudster was testing credentials. Waiting.
Cathay Pacific didn’t flag the mismatch immediately. Or they did, and ignored it.
The traveler had to dig through months of data to find the discrepancy. Most people never check. They assume miles post. They don’t.
What Can You Do?
If you fly Cathay Pacific, or any airline with lax post-checkin rules, monitor your accounts.
Check your balances regularly. Don’t wait for a reminder email.
If miles don’t post within the window, act fast. Before the six-month limit hits.
If you see an account you don’t recognize? Contact the airline’s fraud department. Not just customer service. Demand an investigation.
Don’t trust agents who dismiss your concerns.
The miles are gone if you wait. And sometimes, the airline employee involved has a vested interest in keeping quiet.
This isn’t about one bad actor. It’s about a system that allows interception. A loophole in loyalty programs that rewards the sneaky.
The traveler got his miles back. Maybe. With effort.
Most people don’t fight that hard.
They just lose them.
So, do you trust the airline to protect your miles? Or are you on your own?
The answer, apparently, is no. Not really.
You have to be the detective. You have to watch. Every flight. Every receipt.
Because they are watching too.
From Beijing. Or wherever. Waiting for a missed notification. A lapse in attention. A window of opportunity.
The miles are out there. Waiting to be caught.
























