Card fraud - but how?!
Discussion
Mrs D had a fraud alert on one of her current accounts... She dug out the number for the bank and rang it (never dial the number in an SMS!) and sure enough it was genuine. The fraud prevention people confirmed that someone had tried to use the card details on a couple of websites but as Mrs D has never used this card at all, it was flagged and no money left her account.
So, here are facts:
1) It's a debit card.
2) The card has never been used at all; it's still stuck to the piece of paper it arrived on.
3) Mrs D produced it from a locked safe, so no-one has had access to it apart from Mrs D and me.
4) The card number, CVC and date were all correctly entered by the fraudster (according to the bank)
5) The account the debit card links to has been sat untouched for a year or so (Mrs D used it for a one-off, specific purpose and hasn't got round to emptying and closing it).
6) The websites the card was attempted on do not appear to be related in any way, and are not something dodgy (perhaps used to test details before they do a big withdrawal or transfer).
So, emphasising that this card has never been used at all (by which I mean never in a shop, never in an ATM, never online, never over the phone etc), is the only explanation that the information must have come from the bank (through a data breach, leak, or criminal employee)? Or is there some checksum that would have allowed fraudsters to reverse engineer her details?
So, here are facts:
1) It's a debit card.
2) The card has never been used at all; it's still stuck to the piece of paper it arrived on.
3) Mrs D produced it from a locked safe, so no-one has had access to it apart from Mrs D and me.
4) The card number, CVC and date were all correctly entered by the fraudster (according to the bank)
5) The account the debit card links to has been sat untouched for a year or so (Mrs D used it for a one-off, specific purpose and hasn't got round to emptying and closing it).
6) The websites the card was attempted on do not appear to be related in any way, and are not something dodgy (perhaps used to test details before they do a big withdrawal or transfer).
So, emphasising that this card has never been used at all (by which I mean never in a shop, never in an ATM, never online, never over the phone etc), is the only explanation that the information must have come from the bank (through a data breach, leak, or criminal employee)? Or is there some checksum that would have allowed fraudsters to reverse engineer her details?
This is indeed an odd one. Is it a VISA or MasterCard debit card?
The card number can be "created" programmatically and expiry dates for batches of cards will be similar, according to issuer policy (2/3 years typically). What is really interesting is the CVV2 which is unique to the issued card being correct. Does the issuer, assuming VISA or MasterCard, use the out-of-band verification (e.g. 3D Secure)? Because that's where things get interesting.....
Most card issuers outsource the creation of the cards so the problem could be there. In theory if they are credit card-derived cards, the PAN should not be stored where someone can get at it (PCI-DSS requirement).
But do rest assured that the issuers do have very robust (and very interesting eFraud teams and processes). And that saved you lots of hassle. They will also be investigating how the card details could have become known, assuming you informed them of the details above.
The card number can be "created" programmatically and expiry dates for batches of cards will be similar, according to issuer policy (2/3 years typically). What is really interesting is the CVV2 which is unique to the issued card being correct. Does the issuer, assuming VISA or MasterCard, use the out-of-band verification (e.g. 3D Secure)? Because that's where things get interesting.....
Most card issuers outsource the creation of the cards so the problem could be there. In theory if they are credit card-derived cards, the PAN should not be stored where someone can get at it (PCI-DSS requirement).
But do rest assured that the issuers do have very robust (and very interesting eFraud teams and processes). And that saved you lots of hassle. They will also be investigating how the card details could have become known, assuming you informed them of the details above.
donkmeister said:
Thanks all - unless our cat has learned how to crack a safe it seems like a dodgy postal worker somewhere in the system is the most likely culprit then... Just fortunate that the anti-fraud picked it up.
. You said the card is over a year old?So unsuspecting that a postman did it.
Most likely a security breach from the computers or mobile phones you've used to spend money with the card. Plenty of computer viruses will do this and can be surprisingly easy to get - a link or email from a friend out of the blue. Clicked an attachment. Nothing opened. Thought nothing of it.
It is possible a security breach from the website(s) previously used to make a purchase on, but these days security is very easy to do right so unlikely.
I'd say the postman idea is very far behind, great mystery though. Its a shame we can't ever find out the facts behind things like these later on!
What bank was it? I had very similar with a Barclaycard credit card a year or so ago. New account and it arrived with a ridiculous £250 credit limit. I put it in a drawer and thought no more about it. Six months later someone went on a spending spree (well, a less than £250 spending spree) with it in London. I received a load of warnings that I was trying to exceed my credit limit.
I reported all the bogus transactions and got them reversed. I also told Barclays that the offender could only have got the card details from themselves, but they didn’t seem interested.
I reported all the bogus transactions and got them reversed. I also told Barclays that the offender could only have got the card details from themselves, but they didn’t seem interested.
320d is all you need said:
. You said the card is over a year old?
So unsuspecting that a postman did it.
Most likely a security breach from the computers or mobile phones you've used to spend money with the card. Plenty of computer viruses will do this and can be surprisingly easy to get - a link or email from a friend out of the blue. Clicked an attachment. Nothing opened. Thought nothing of it.
It is possible a security breach from the website(s) previously used to make a purchase on, but these days security is very easy to do right so unlikely.
I'd say the postman idea is very far behind, great mystery though. Its a shame we can't ever find out the facts behind things like these later on!
Agree not postman, but OP said card never used So unsuspecting that a postman did it.
Most likely a security breach from the computers or mobile phones you've used to spend money with the card. Plenty of computer viruses will do this and can be surprisingly easy to get - a link or email from a friend out of the blue. Clicked an attachment. Nothing opened. Thought nothing of it.
It is possible a security breach from the website(s) previously used to make a purchase on, but these days security is very easy to do right so unlikely.
I'd say the postman idea is very far behind, great mystery though. Its a shame we can't ever find out the facts behind things like these later on!
I’ve recently just had the same with a virgin credit card that has never been used. It was the additional card in my partners name and either card hasn’t been used and were only ever obtained for a balance transfer. A couple of small amounts attempted but the number on the card didn’t match the name or something and so was flagged up.
It could be internal fraud in the bank especially if their IT and / or customer service is abroad.
I gave up using one credit card company after the third time their card was used for multiple purchases (so new card isssued each time). One of the episodes the scammers had got currency at a bank and bought flight tickets which are both pretty brazen. What alarmed me most was the card company didn't seem in the slightest bothered.
I gave up using one credit card company after the third time their card was used for multiple purchases (so new card isssued each time). One of the episodes the scammers had got currency at a bank and bought flight tickets which are both pretty brazen. What alarmed me most was the card company didn't seem in the slightest bothered.
NickCQ said:
donkmeister said:
card ... in a locked safe
stichill99 said:
debit card ... locked in safe and never used
Is this a normal thing to do?In the past have hD accounts for balance transfer and never used and now have a blank account only used for online, so the card is never used and is still stuck to the letter it came on.
I had the same with Barclaycard, each time I got a new card it was used before I even received it,
The last one I picked up from the branch, and by the time I got home they was calling to say someone was trying to use it in a jewellers in london,
And as for not using accounts, I opened an account with a bank when I got a mortgage with them but never used it,
The last one I picked up from the branch, and by the time I got home they was calling to say someone was trying to use it in a jewellers in london,
And as for not using accounts, I opened an account with a bank when I got a mortgage with them but never used it,
donkmeister said:
Mrs D had a fraud alert on one of her current accounts... She dug out the number for the bank and rang it (never dial the number in an SMS!) and sure enough it was genuine. The fraud prevention people confirmed that someone had tried to use the card details on a couple of websites but as Mrs D has never used this card at all, it was flagged and no money left her account.
So, here are facts:
1) It's a debit card.
2) The card has never been used at all; it's still stuck to the piece of paper it arrived on.
3) Mrs D produced it from a locked safe, so no-one has had access to it apart from Mrs D and me.
4) The card number, CVC and date were all correctly entered by the fraudster (according to the bank)
5) The account the debit card links to has been sat untouched for a year or so (Mrs D used it for a one-off, specific purpose and hasn't got round to emptying and closing it).
6) The websites the card was attempted on do not appear to be related in any way, and are not something dodgy (perhaps used to test details before they do a big withdrawal or transfer).
So, emphasising that this card has never been used at all (by which I mean never in a shop, never in an ATM, never online, never over the phone etc), is the only explanation that the information must have come from the bank (through a data breach, leak, or criminal employee)? Or is there some checksum that would have allowed fraudsters to reverse engineer her details?
Could mrs D have entered the card details into a cashback / rewards website or app?So, here are facts:
1) It's a debit card.
2) The card has never been used at all; it's still stuck to the piece of paper it arrived on.
3) Mrs D produced it from a locked safe, so no-one has had access to it apart from Mrs D and me.
4) The card number, CVC and date were all correctly entered by the fraudster (according to the bank)
5) The account the debit card links to has been sat untouched for a year or so (Mrs D used it for a one-off, specific purpose and hasn't got round to emptying and closing it).
6) The websites the card was attempted on do not appear to be related in any way, and are not something dodgy (perhaps used to test details before they do a big withdrawal or transfer).
So, emphasising that this card has never been used at all (by which I mean never in a shop, never in an ATM, never online, never over the phone etc), is the only explanation that the information must have come from the bank (through a data breach, leak, or criminal employee)? Or is there some checksum that would have allowed fraudsters to reverse engineer her details?
Criminals infiltrate banks by either getting hired themselves or paying off/blackmailing people to access details that are then compromised. It's happening a lot in other sectors too - legal firms for example. If you think about it, humans are the weakest link in a lot of chains and much easier to bribe/blackmail a lower paid worker than trying to hack security in a bank or other large business.
NickCQ The 4 partners in the business each had a visa debit card for the business account but as my father was not taking an active part at that time in his life he never needed to use the card so his was put in the safe, Myself,brother and mother all used ours(family business) but fathers was never used.
Gassing Station | Finance | Top of Page | What's New | My Stuff


