Get all your news in one place.
100's of premium titles.
One app.
Start reading
inkl
inkl

A Ukrainian Truck Driver Found a Security Gap in America's Biggest Truck Stop Loyalty Programs And Chose to Report It

Vitalii Budnyk

When Vitalii Budnyk noticed that anyone with a phone number could spend another customer's rewards balance at Pilot and Love's, he had a choice: exploit the vulnerability like others have done with fuel cards, or report it. He chose the second path and got an official acknowledgement from Love's confirming the issue exists.

Recent news coverage has focused on a series of fraud cases in America's trucking industry. Several individuals were arrested for exploiting a fuel card vulnerability at Love's, reportedly draining hundreds of thousands of dollars worth of diesel over several years before the pattern was noticed. Additional cases involving similar schemes surfaced shortly after. These stories create a public perception that is difficult to shift once it takes hold.

Vitalii Budnyk, a Ukrainian who came to the United States through the Uniting for Ukraine (U4U) program and worked as a long-haul truck driver, took a different approach. After identifying what appears to be a systemic security weakness in the loyalty programs of both Pilot and Love's, he sent formal letters to both companies explaining the problem, proposing solutions, and stating that he had not used the weakness for personal gain.

What He Found at the Cash Register

The vulnerability relies on a straightforward mechanism. Customers in the rewards programs at Pilot and Love's can pay for purchases using accumulated points, which convert at roughly 100 points per dollar. Long-haul drivers who fuel regularly can accumulate 300 to 700 dollars in rewards value per month.

The problem is redemption. At the register, a customer can either scan the physical rewards card or state the phone number linked to the account. Based on Budnyk's observations across multiple locations in Washington, Florida, Illinois, and other states, the phone number method requires no identity verification — no SMS confirmation, no PIN, no ID check, no notification to the account holder.

"I stood at the counter, gave a colleague's phone number, and paid for a purchase using his rewards balance," Budnyk explained in his letter to Love's. "The cashier processed the transaction without asking me to confirm my identity. When I asked for a receipt, it showed the remaining balance on that account. That means anyone standing in line behind me could have done the same thing."

Phone numbers of other account holders are also accessible. Every commercial truck displays its DOT and MC numbers on the cab. Public databases in the United States allow anyone to look up the company owner and contact details using those identifiers. A phone number can then be extracted and tested at any Pilot or Love's location. A match with an active rewards account leaves the account's balance exposed to unauthorized redemption.

The Math Behind the Risk

Both Pilot and Love's operate hundreds of locations nationwide, serving millions of professional drivers. At 100 points per dollar, a 10,000-point balance equals 100 dollars; one million points equals 10,000 dollars. Drivers on the road for years, using the same fuel networks, can accumulate balances that would surprise casual observers. A single compromised account could translate into hundreds or thousands of dollars in unauthorized redemptions before the account holder notices anything unusual.

Budnyk also described how such vulnerabilities scale. A single person using the phone number method across multiple accounts and locations would generate losses distributed thinly enough to avoid detection for months or years. This is the same pattern that eventually led to the arrests in the fuel card cases — the exploitation continued for years before the numbers triggered an internal audit.

Vitalii Budnyk

The Response From Love's

Budnyk sent detailed letters to both companies in the fall of 2025, describing the vulnerability, proposing specific technical solutions, and stating that he was reporting in good faith without seeking compensation.

The response from Love's came relatively quickly. In an official email, the company confirmed the issue, acknowledging that its current system does not require any text message verification when a phone number is used in place of the card number to redeem points. The representative noted that Budnyk's feedback would be escalated to the appropriate teams for review, with the possibility of additional security measures being implemented in a future update.

A follow-up message thanked Budnyk for his detailed feedback and acknowledged the practical solutions he had proposed, including SMS verification, one-time codes, mobile app approvals, QR code verification, and optional PIN protection. The company also pointed out that the Love's app currently allows customers to enable two-factor authentication through the profile settings, though this remains an opt-in feature.

Pilot has not responded to Budnyk's letter to date.

Why He Chose to Report the Issue

Budnyk is an industrial electrical engineer with over a decade of experience on high-complexity manufacturing sites in Europe. He spent five years at LG Chem's facilities in Wrocław and Oława, Poland, where he led installations of high-voltage cabinets and automation systems for electric vehicle battery production. His subsequent projects included electrical work at PepsiCo food production facilities, where systems must meet strict hygiene and continuity standards, and at PCC Rokita's chemical manufacturing operations, where he handled installations in ATEX-classified explosion-hazard zones. During his time at LG Chem, he supervised a multinational team of up to twenty electricians from Ukraine, Poland, South Korea, Vietnam, Georgia, and India. This engineering background provided the pattern recognition to identify the vulnerability in the truck stop loyalty systems during his work as a long-haul driver.

"I decided to report this issue because I believe it is important to help companies improve the security of their services and protect their customers," Budnyk wrote. "I have not used this system weakness for personal gain and have not taken any actions intended to benefit from it. My sole purpose is to inform the company of a potential risk and help prevent possible misuse."

Speaking about his motivation, Budnyk emphasized the professional responsibility he felt as a technical specialist observing a systemic weakness. 'When you spend years working with industrial control systems, you develop a certain sensitivity to security gaps,' he said. 'I saw the same pattern in a consumer-facing system, and I felt it was my responsibility to inform the companies. This is what technical professionals should do when they identify risks that affect other people.

Beyond the Security Report

The letters included two additional suggestions unrelated to security. Budnyk proposed installing pull-up bars, parallel bars, treadmills, or stationary bicycles in driver rest areas. Long-haul drivers spend 10 to 11 hours per day behind the wheel, and access to minimal physical exercise infrastructure could improve cardiovascular health and reduce fatigue-related accidents.

He also mentioned an ongoing engineering project — a body-drying system called BM-Smart-Dry, designed to replace towels in shower facilities at truck stops. The concept emerged from personal experience using shower facilities at fuel stops during cold weather, where the transition from hot shower to cold corridor often left drivers vulnerable to respiratory illness. The project is at the concept stage with completed engineering calculations, awaiting investment for prototype development.

The Broader Question

Love's response confirms that the vulnerability is real and that any fix will require corporate prioritization through standard product development cycles. Loyalty programs have historically been treated as marketing infrastructure with lower security requirements than payment systems, on the assumption that per-transaction amounts stay small enough to avoid attracting sophisticated attackers.

That assumption may be outdated. The aggregate value of rewards liabilities at major national chains now runs into significant amounts, and the mechanisms for identifying account phone numbers are increasingly accessible through public data sources.

For professional drivers, the practical takeaway is worth noting. Love's rewards members can currently enable two-factor authentication in the company's mobile app, which provides the strongest available protection for their account. Pilot has not yet introduced a comparable in-app option, leaving its rewards accounts more exposed. Enabling it takes a few minutes and removes the phone-number-only vulnerability for a specific account.

For the companies, the question is whether they will implement default security improvements across the entire user base or continue relying on opt-in measures. Customer notification of point redemption (a simple SMS or push notification whenever points are spent) would be a low-cost, high-impact improvement deployable without waiting for a larger system overhaul.

Whether the companies will implement the fixes he suggested remains an open question.

Whether his story reaches enough of an audience to counter the negative headlines about Ukrainian fraud cases is another.

Sign up to read this article
Read news from 100's of titles, curated specifically for you.
Already a member? Sign in here
Related Stories
Top stories on inkl right now
One subscription that gives you access to news from hundreds of sites
Already a member? Sign in here
Our Picks
Fourteen days free
Download the app
One app. One membership.
100+ trusted global sources.