10 ms·
Here’s an interesting one: when your card is compromised and a new card number is issued, many banks will allow charges to continue using the old card number, p
by davidgh 7y ago
Here’s an interesting one: when your card is compromised and a new card number is issued, many banks will allow charges to continue using the old card number, provided the charges were occurring on an ongoing basis from that same merchant before the compromise. This is designed to prevent disruption of ongoing subscriptions in the event of compromise.
About a month ago I was reviewing my statement and noticed I was being billed by Spotify twice each month. I contacted Spotify to ask why they were billing me twice, and they asked for my account info and indicated my account was only being billed once. They then asked for the first 6 and last four of my car number to search that way, and again indicated I was only being billed once.
I sent them a screenshot of my online account statement at which point they agreed they were billing me twice but could not find the origin of the duplicate charge.
Finally it dawned on me - my bank had sent me a new card a long while back because of a suspected compromise. I’d had that card for a long time, and had the number memorized. I gave the old card number to them and bam - they found the source of the fraudulent transactions.
This means that even though my card number was compromised and cancelled, it can still be used for payment at any merchant for which I’ve had an ongoing subscription. Since these are merchants I do business with, it makes it doubly hard to notice the fraudulent charges as seeing “Spotify” or “Netflix” or whatever does not raise my eyebrow. Only in a careful month by month review did I pick up on the fraudulent transactions.
As a side note Spotify was very quick to reverse the duplicates and appear to have blocked that old card number from being used in their system again. Although a frustrating experience overall, they were very good to work with.
- dhimes 7y agoThis happened to me in a different way: I was giving recurring payments to a .org. I kind of knew how much I wanted to give, but instead of a lump sum I figured I would do recurring for a year. It would give them a little more and seemed to make the guy at my door happy. Now with this organization, you can donate via the website but to cancel a recurring donation requires a phone call. I called a couple of times to try to cancel but didn't reach anybody. I admit- I wasn't too concerned (a good organization overall), but I was a little pissed nevertheless. My credit card was skimmed, and I had it cut off. I figured this would solve my problem with the donations as well. Nope. About two years later my wife (who actually handles the bills in the family) asked me if I wanted to continue those payments. I was pretty shocked- and persisted with the phone calls until I reached somebody to cancel. Surprise! I consider the "signing up can be done on the web, but canceling requires a human" to be a dark pattern.
- wlesieutre 7y ago> I consider the "signing up can be done on the web, but canceling requires a human" to be a dark pattern. And illegal in California as of last year. Hopefully them forcing companies to allow online cancellations will mean it's available for the rest of us too. https://www.cnet.com/news/companies-must-let-customers-cancel-subscriptions-online-california-law-says/ https://www.cnet.com/news/companies-must-let-customers-cance...
- kevinmchugh 7y agoIt's been illegal in Illinois for a couple years as well.
- tialaramex 7y agoYes, this is the correct fix (well, not the part where everybody else has to rely on California but the rule that if you can sign up by method X you can cancel that way too) My ex-employer was surprised that when they were obliged by law to stop routing everybody though a retention call center customer satisfaction improved. Too much of their own Kool Aid had been drunk, they'd persuaded themselves that customers wanted to be reminded of the benefits and offered other deals by a human so much that they'd hate even having the option to just press "Cancel" on the web site and leave that way. It's an old Joel Spoelsky lesson, if you make leaving a pleasant experience that customer may come back some day. If not you're never going to see them again.
- epistasis 7y agoSeveral years ago, that dark pattern caused me to cancel my online NY Times subscription shortly after I started it, because the discovery of that process annoyed me so much.
- ryanmarsh 7y agoWSJ online uses this dark pattern, or did when I cancelled roughly a year ago. I won't ever subscribe again, purely because of this nonsense.
- 7y ago
- pbreit 7y agoThey do this based on decades of near unanimous feedback and in many cases anger so cardholders do not have to change all their billing setups just to block txns to new merchants going forward.
- Silhouette 7y agoFor what it's worth, we've seen that situation from the other side as well. A customer who subscribes with us wants to update their payment details, but in fact creates a new account with a different ID, new card, etc. They don't do anything to close down their old account, we have no way to know that john.smith@example.com is the same as j.smith.1980@example.com and we don't even see their card details, and so of course our system will charge both of them as if they were two different customers. Sometimes customers do get confused by the automatic update mechanisms for card details, but most of the time it seems to be a useful facility that saves hassle for our subscribers and avoids unintended cancellations. I do think the card companies should be much more transparent with both cardholders and merchants about how their systems actually work, though. We've had occasions where something unexpected has happened, a customer has contacted us to ask what is going on, and all we could do was contact our card payment service to ask them because we had no idea either.
- inetknght 7y agoWhat you're saying sounds like you're able to bill a card without being required to verify who you're billing. Surely there's a law against that?
- Silhouette 7y agoIn both cases we're talking about a customer who has deliberately signed up and provided us with their contact and payment details. It just happens to be the same customer twice, but providing different details so we can't automatically determine that they're the same person. In an ideal world, perhaps we would verify exactly who each customer is for legal purposes, but in reality there's no good way to do that, so we accept a fraud risk that is small in practice in return for streamlining the process for both ourselves and our customers. There are systems that will shift that liability if you go through additional authorisation checks at purchase time (and in Europe, use of these systems will become mandatory in most cases later this year) but it is not clear that these are actually helpful, in that they may do more harm than good. As for having a law against anything, I don't see how this is much different to when I buy my shopping from a grocery store and all I need to provide for payment is my card and PIN (and not even the PIN for most low-value transactions these days). Or of course I can pay completely anonymously using cash.
- superhuzza 7y agoI started being charged $17 a month for Amazon Prime. I contacted Amazon and confirmed I didn't have, and had never had Prime. It was a fraudulent third party. I think the scam must rake in huge sums of money, given that it could slip by for months unnoticed. EDIT: Amazon confirmed my card was never used to purchase Prime for me or anybody else. The scammers were just charging my card $17, and hiding the charge under the name 'Prime Subscription'.
- PopeDotNinja 7y agoIt's also super easy to get suckered into signing up for Amazon Prime. It's happened to me a couple times.
- DougN7 7y agoHow did the third party benefit?
- isk517 7y agoThey got $17.
- tk75x 7y agoThey (third party) received all the benefits of prime without having to pay for it.
- superhuzza 7y agoNo, Amazon confirmed my card wasn't even being used for Prime at all. They just charged my card with the name 'Amazon Prime', and were withdrawing money from it.
- evan_ 7y agoAffiliate fraud maybe
- deleted 7y ago[deleted]
- 7y ago
- js2 7y agoI just went through this with Chase. Their criteria is six prior recurring payments for a given merchant to allow payments to continue on the old number from that merchant.
- jzwinck 7y agoI had my credit card number stolen and the thief used it to subscribe to Netflix. 16 times. That's right, they created 16 Netflix accounts in one day using the same credit card details. Apparently a basic sanity check like "Are we already billing this card?" is not implemented at all, and Netflix support admitted as much. I think it's in the merchants' interest to proceed with lackluster sanity checks, knowing that some erroneous charges will make it through. It's got to be a multimillion dollar business collecting fees from the unaware, the scammed, and the dead.
- klyrs 7y ago> ...and the dead. Canceling my dad's cable service was peculiarly cathartic. They wanted to talk to him, not me: "he's dead." They stumbled over points in the script where they're supposed to flip the cancellation into a bigger subscription: "no, he's still dead." They awkwardly prodded about survivors: "none of your business; if anybody wants your service they don't want it under the name of a dead man, will you cancel the service now?" This would have been quite painful if I didn't get so much glee from saying "no" to salespeople...
- evan_ 7y ago> Apparently a basic sanity check like "Are we already billing this card?" is not implemented at all They most likely don’t store your actual card number.
- dgaudet 7y agois there technology around this? i mean i can imagine an API where the CC# itself is only necessary in the first transaction with a new vendor, during which the vendor makes a (signed) request for a vendor-specific token to use for future payments, and can forget the CC# immediately; future payment requests use the same signature chain and the vendor-specific token... making it easy to invalidate any/all of these tokens if the data is compromised, or if the end-user wants to invalidate a specific recurring payment, etc. i'm in fantasy land, right?
- 7y ago
- dontbenebby 7y agoNot just in case of a compromise - many issuers will let things go through to the old # when it expires and a new card is sent out. This can create unforseen problems that aren't fraud related as well. For example, I had to replace my iPhone at one point, and update my 2FA codes. (Even if you back up your iPhone reguarly, 2FA codes in Google Authenticator are not backed up) Unfortunately, I'd lost my recovery code for one service provider. They wanted the last 4 of my CC a one of the points of data in their verification process. Then told me it was incorrect. Luckily, the CC issuer (who sadly, for security reasons I'd rather not name) had some excellent customer service. They realized that they had been billing the previous card number since it was a known re-occurring payment, and were able to work with me to retrieve the last four digits of the old card number via an old statement, enabling access to my account. I've since moved over all my reoccuring payments to that issuer. (And made a document outlining which merchants have which cards on autopay so I can update them when cards are re-issued + backed up my 2FA recovery codes in a secure, offsite, physical location)
- WorldMaker 7y agoThat has become a pet peeve of mine. When the answer to "Can you give us the last four of the CC you used for your last purchase with us?" is "Well, that was a few years ago. I shredded that card when it expired as I always do. This is not information that I have and frankly it isn't even information that you should still have under PII laws."
- thesmok 7y ago2FA codes are backed up when you do iTunes backup. That's how I transferred to a new iPhone.