I just got an email from Hilton letting me know about my points redemption.... only I hadn't made a points redemption. I logged in and found that someone had reserved a Hampton Inn in China (I'm currently in the U.S.) for today. It was pretty brazen, they added themselves (one Maorui Wu) as the guest and used their credit card, although I suppose Maorui Wu might be a victim as well of a cheap hotel room sold by a "travel agency". I called Hilton immediately and they returned the points, but it sounds like they freeze your account until they complete an investigation, although if you need to redeem points for an upcoming stay they'll do that for you on the phone before they freeze your account.
Bottom line is that Hilton may have been hacked (I haven't had any other accounts broken into lately) and if you see a redemption email from Hilton that you didn't make, it pays to check immediately because it's probably for that day, and call Hilton to get it taken care of. Might be worth proactively changing you HHonors password just to be safe.