Cyber Incident Victim: jö Bonus Club
Date:
Oct 2022
Location:
Austria
Summary
Cybercriminals attempted unauthorized access to a loyalty program's customer accounts using 2.3 million stolen email-password combinations obtained from external sources, succeeding in 18,000 instances where members reused credentials across multiple platforms. The attackers conducted fraudulent purchases totaling approximately €4,000 in rewards currency at partner businesses across 75 compromised accounts. The organization detected the intrusion through routine monitoring of anomalous login activity and immediately implemented countermeasures, including password resets for affected users. No sensitive data was accessed during the incident, and the program voluntarily reimbursed stolen rewards as a goodwill gesture. Members were advised to create unique passwords exclusively for their accounts to prevent future credential-stuffing attacks.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On or around October 1, 2022, the jö Bonus Club loyalty program experienced a credential-stuffing attack in which cybercriminals attempted to access customer accounts using stolen email addresses and passwords obtained from unrelated third-party sources. The attackers leveraged 2.3 million compromised credentials to systematically attempt logins across the platform's 4.3 million customer accounts. This attack was detected internally by the jö Bonus Club's IT security team through ongoing system monitoring, which identified anomalous login patterns indicative of automated access attempts. The organization promptly implemented countermeasures, including a forced password reset for all affected accounts, requiring users to establish new credentials upon their next login attempt. Forensic analysis confirmed successful unauthorized access in 18,000 instances where customers had reused identical email-password combinations across multiple online platforms.

The attackers monetized compromised accounts in 75 confirmed cases by making fraudulent purchases totaling approximately €4,000 at partner merchants using stolen "Ös" loyalty points. No sensitive personal or financial data was accessed during the breach. jö Bonus Club absorbed the financial impact as a goodwill measure, reimbursing all fraudulently spent loyalty points to affected customers. The organization issued renewed security advisories emphasizing the criticality of password hygiene, specifically instructing customers to create unique passwords exclusive to their jö accounts and avoid credential reuse across digital services. System functionality was fully restored following containment measures, with all transactional capabilities reinstated by the date of the public notification.
