Loyalty fraud prevention in Australia: Set clear eligibility rules for points earning and redemption.; Review unusual activity against order history and account events.; Protect member data with privacy-compliant breach protocols.
Image: Loyalty Marketing Guide

Loyalty Fraud

Loyalty fraud and abuse

Map loyalty abuse risks across signup, earning, redemption and staff access, then investigate unusual activity without treating alerts as proof.

Protect a loyalty programme by tracing how value enters, moves through and leaves member accounts. Set clear eligibility rules, restrict balance changes and review unusual activity against orders and account history. An unusual pattern warrants investigation; it does not prove wrongdoing.

Map the risks

PathQuestion to ask
JoiningCan someone claim a one-time incentive repeatedly?
EarningCan one order, referral or manual action create value more than once?
RedeemingCan points be spent after an unexpected account change or through an ineligible transaction?
Staff accessWho can view or change balances, and who reviews those actions?

Each path needs a different response. Reconcile a duplicate order event; check eligibility for repeated signup claims; an unfamiliar redemption may mean an account was compromised; an unexplained manual credit calls for an access review. Calling every anomaly ‘member fraud’ can hide the cause and blame the wrong person.

Include consumer trust in the risk map

Fraud controls are not the only programme risk. The ACCC’s 2019 draft report flagged concerns about advertised benefits, unilateral changes to scheme terms and poor disclosure of how consumer data is used or shared. Consumers also reported not earning, keeping or redeeming points as expected.

Almost nine in ten Australian adults belonged to a loyalty scheme, and the average Australian carried four to six loyalty cards. Some popular schemes reported more than 10 million members.

Set rules and controls

State who qualifies for each incentive, when points become available, whether rewards can be transferred and what happens after a cancellation or refund. Write member-facing terms plainly and keep technical checks in operating procedures.

Link each points award to its qualifying event so duplicate credits can be found. Record corrections separately. Require a case reason for manual adjustments, limit staff permissions to their duties and review access when roles change. These controls also help resolve honest balance disputes.

Key Controls for Loyalty Programme Integrity

  • Link each points award to its qualifying event
  • Record corrections separately
  • Require case reason for manual adjustments
  • Limit staff permissions to duties
  • Review access when roles change

Balance prevention with member impact

A 2025 global survey of hundreds of e-commerce merchants by Ravelin found 77% reported a year-on-year rise in fraud and 54% said refund abuse had increased. The survey also found 38% cited friction and customer churn as major obstacles to prevention.

The same survey found 66% of merchants considered customer loyalty and brand reputation more important than stopping refund abuse. This warns against either extreme: ignoring losses can affect revenue, while broad restrictions can burden legitimate members. Use the risk and evidence in each case to guide the response.

Fraud Control Balance: Prevention vs. Member Experience

Risk of ignoring fraud
Revenue loss, brand damage, increased abuse
Risk of over-restricting
Customer friction, churn, reduced loyalty
Recommended approach
Use risk and evidence to guide response; avoid extremes

Review alerts fairly

A review queue might flag rapid redemptions, repeat incentive claims or clusters of manual adjustments. Compare activity with relevant reward types and promotions before drawing conclusions. Check ledger entries, order status and account events; campaign traffic, delayed processing and legitimate high use can all affect a pattern.

Address the immediate risk with the narrowest practical response. If a reward needs a temporary hold, record why, tell the member what is affected and review the hold promptly. Give members a secure route to report unfamiliar activity. Preserve the transaction history needed to reconstruct the balance.

If a case involves personal information or suspected unauthorised access, apply the privacy and data-breach guidance below.

Close each case with a recorded outcome, such as a confirmed rule breach, account compromise, processing error, legitimate activity or insufficient evidence. Correct errors and review both losses and wrongful restrictions.

Responding to Unusual Activity Alerts

  1. Check ledger entries, order status and account events
  2. Compare activity with reward types and promotions
  3. Address risk with narrowest practical response
  4. Record hold reasons, inform member, review promptly
  5. Preserve transaction history for reconstruction

Keep privacy and breach decisions distinct

For organisations covered by APP 3, the OAIC says personal information may be collected only where reasonably necessary for the organisation’s functions or activities, and by lawful and fair means. Sensitive information has extra requirements: collection generally needs the individual’s consent unless an exception applies. These collection rules are separate from deciding whether a loyalty transaction is suspicious.

A loyalty case involving unauthorised access does not automatically mean the Notifiable Data Breaches scheme applies. The OAIC’s quick reference guide describes coverage for entities with Privacy Act obligations: businesses and not-for-profits with annual turnover above $3 million, private health service providers, credit providers and some small business operators. Check the entity’s obligations when assessing a suspected data breach.

Collecting Personal Information for Loyalty Fraud Checks

Pros
Supports fraud detection, verifies identity, improves security
Cons
Must comply with APP 3; sensitive data requires consent; breach risk increases

Understand external reporting pathways

Members can report misleading behaviour to the ACCC, which says it uses reports to inform its education, compliance and enforcement work. The ACCC does not investigate individual complaints, so do not present a report to a member as a route to individual case resolution. Keep the programme’s own review and response process clear while treating external reporting as a separate option.

In this guide

  1. Identifying unusual reward redemption patternsBuild a review queue for unusual reward redemptions using traceable events, relevant comparisons and checks for ordinary explanations.
  2. Preventing repeated signup incentivesDefine one-time eligibility, prevent duplicate reward issues and review repeat-signup signals without rejecting legitimate members.
  3. Reviewing employee access to member balancesAudit who can view or change loyalty balances, review sensitive actions and remove permissions that staff no longer need.
  4. Investigating suspected abuse without wrongly penalising a memberPreserve evidence, check ordinary explanations, limit temporary holds and give members a clear review path when loyalty abuse is suspected.

More from Loyalty Fraud