There’s all kinds of fraud in the miles & points world, as there’s a big underground industry of bartering rewards. While we hear about cases of rewards being stolen all the time, here’s an unusual twist on that, whereby someone managed to get someone else’s rewards credited to their frequent flyer account. I’m not sure what exactly to make of this, so I’d love to hear what others think.
Flight somehow credited to unknown frequent flyer account
An OMAAT reader shared the following experience with me, so let me just post it in full:
I was just organizing some past flights I took last year that I hadn’t credited yet. At the time, I was still deciding where to credit them, as I mainly flew on award tickets and lacked status, but these were long haul business class tickets on CX. I noticed on my boarding passes that the frequent flyer program listed was CX, but when I logged into my account, the miles hadn’t been credited. Since I couldn’t file a claim online because it was beyond the six-month period, I decided to reach out to their WhatsApp customer service team. It was there that I was informed that the flights were credited to American.
As I rarely used AA in the past, I quickly glossed over what the agent said, assuming they had meant “an American airline,” so I logged into my AS account. I found no points there. Then, I reread the message and tried logging into my AA account, and discovered it was locked. It turns out the account was locked since 2022, because someone tried to log in. I never used AA, so I must have missed the email notification and didn’t report the fraud then. However, I also managed to retrieve my AA number.
I reached out to CX to confirm if the agent meant AS or AA, and she said AA, American Airlines. I then confirmed if it was my AA number which I provided to review and they said no, it was credited to [different account number]. I then entered that number into AA’s password reset area and used my name, since they would’ve needed my name to credit the miles. Sure enough, it was associated with a different email address using a bizarre domain. I also did a WHOIS search, which showed that the domain was registered in Beijing last year.
I then called AA and they said it’s bizarre and they’ve never seen a case like this before and they will open a case with Fraud. Fraud then said they need to unlock my account first before they can move onto the next investigation.
What is also surprising is that I listed my CX FFP numbers before and during check-in, my boarding passes reflect this, and the return journeys were nearly three weeks long. I’m not sure how they could have modified the FFP details after flying. The agent at CX was also really not helpful and dismissive about potential fraud and compromised data on their end.
Just in case that isn’t clear (or if you just want the summary), let me simplify it as much as possible. This person had their Cathay Pacific frequent flyer on a reservation, but the flight never credited to the account (which he only found out about later, while “auditing” his accounts). He was informed that the flight was credited to American AAdvantage, which he never requested, and on top of that, it wasn’t the number he uses with the program.
Furthermore, below is the message he received on American’s website when he tried to reset the password for the account this was reportedly credited to, which had the @qmdfcd.com domain.

And then when he looked up that domain, it was linked to being registered in Beijing, China.

Was this an inside job, or how else do you explain this?
While frequent flyer miles are stolen all the time, this is a specific type of fraud I’ve never heard of before. A few thoughts:
- This traveler had a frequent flyer number on the account, and somehow that was switched between check-in and when the flight took place (or something)
- Unless there was some very strange glitch, the flight could only be credited to an account with a matching name, meaning that someone must have set up an American AAdvantage account in this person’s name, with the intent of then quickly redeeming the miles out of that account
- For someone to know the name of the traveler, have access to the ticket, etc., would’ve required either quite the data breach, an inside job, or something along those lines
This is a much more complex and niche scheme than just managing to hack into a frequent flyer account, and then redeeming those miles for someone else for a last minute ticket. It also seems to greatly limit the potential upside, since you’re only racking up (likely) under 10,000 miles this way, give or take, depending on the total distance flown, etc. That’s enough to maybe fly one person on a short haul economy flight within the United States, which also isn’t exactly the target for frequent flyer fraud.
I’m curious if anyone has any theories as to what could explain all of this. Most frequent flyer program fraud is repeated, so I imagine this isn’t a one time thing. I still don’t understand exactly how this could happen, though.

Bottom line
A traveler booked a Cathay Pacific business class ticket and intended to credit the flight to Cathay Pacific, only to find that the flight never posted. He later discovered that the flight was credited to American AAdvantage, but not even to his account (which he never provided), but instead, to an account registered to a @qmdfcd.com domain. Presumably that account was still made in his name, or else the flight wouldn’t have credited.
There’s clearly some fraud here, but I’m struggling to make sense of how this could be possible. For that matter, this seems like one of the fraudulent mileage schemes that’s highest risk and lowest reward.
What do you make of this mileage credit fraud scheme?