Fraudulent Credit Card Transactions - Caused by Data Breach?

I noticed 8 fraudulent transactions on my credit card dating back as far as 26th Sept 2018 and I was wondering if anyone else has had something similar happen?

The reason I ask here is that I make a lot of purchases from deals posted on Ozbargain and I believe there has been a data leak at one of the many places I've made a purchase from.

Comments

  • Where were the fraudulent spends processed and for how much?

    • I'm with Coles Mastercard and once they cancelled the card I no longer have access to the transactions in my online account so I can only access what's in the last statement which is 3 transactions. Grammarly in the US for $42, Playtime Pediatric Den Vancouver Ca for $546 and Designspace in the US $2

      • I don't think it's online thing unless they managed to clone your card and have the cryptography for Coles Mastercard.

        I'll explain it because that the dentist mentioned doesn't have an online payment portal; you might also want to go give them a call to check if they take online payment through some other means. I don't think they do. That's why I think you've been skimmed somewhere.

        • Cryptography???

          Unlikely, usually if your card is skimmed, the fraudsters will just go to an ATM.

          • @John Kimble: They can rebuild the card and then use it without the pin (some places still accept signature overseas). There are also other ways they can do this by using Google Pay but then your statement will show up with a specific identifier next to it to show it was used via Google Pay.

            The CVC is also stored inside the magnetic strip which explains the online transactions that can occur when one has never used their card online. (extra side information, for one of the comments below.)

            • +1

              @[Deactivated]:

              They can rebuild the card and then use it without the pin (some places still accept signature overseas). There are also other ways they can do this by using Google Pay but then your statement will show up with a specific identifier next to it to show it was used via Google Pay.

              Yes, they counterfeit the card and go to an ATM because they have the PIN and they get cash instantly instead of having to purchase goods to sell.

              The CVC is also stored inside the magnetic strip which explains the online transactions that can occur when one has never used their card online. (extra side information, for one of the comments below.)

              ROFL! 100% incorrect. Where are you getting your information from? The CVV is only printed on the card. That's the whole point. The reason the fraudsters have the CVV is because of the data breach…one enters the card number, expiry date and CVV into the website and the fraudster captures/intercepts this.

  • +1

    No

  • What are the merchants? Were they labelled as telecoms?

    • The fraudulent transactions I've listed them above in reply to John Kimble. None of them were telecoms. Or did you mean the merchants that I've made purchases from?

      • The response to John Kimble was what I was looking for. I got some from Telstra and Virgin Mobile spelt incorrectly and some other companies.

  • My Credit Card was also hacked around mid-September with someone from the US using my card to pay for $500 hotel rooms per day. They managed to use my card in two locations. New York and LA. The thing is I have Never used this credit card online only in store. So either someone cloned my credit card while paying for something or it was part of the CBA missing tape.

    • I was hoping to find a merchant in common that Ozbargainers (who have had their CC used fraudulently) have used to find a merchant who may have had a data leak. I've made in store purchases at coles, RACQ, woolworths, supercheapauto, my local pharmacy and McDonalds.

      • Out of those, we had Coles, Woolworths, and McDonalds.

  • Ours also at that time. CBA Mastercard, three transactions in California.

    • I was hoping to find a merchant in common that Ozbargainers (who have had their CC used fraudulently) have used to find a merchant who may have had a data leak. I've made online purchases at Moose mobile, skype, tpg, coles online, woolworths online, supercheapauto online, groupon, amaysim, catchconnect, ovo, uber, muve, kogan and also paypal.

      • Good luck, even banks struggle to find a POC. Smart fraudsters will mix up card numbers from multiple compromises to make it more difficult/near impossible to identify a POC.

        FYI sometimes it's not a specific website, it can be a service provider behind that, eg a payment gateway or similar.

        Also, the fraudsters that stole the card data sometimes sell the data multiple times, so different people use it in different locations.

      • Muve. Got several attempts to charge my card (including one successful) the night after I entered my card details into their app.

  • Grammarly rings a bell with fraudulent monthly charges that started appearing in March. If you're with P&N watch your account closely. They haven't got their pooh together in terms of fraudulent charges. Even after my card was cancelled they (whoever) were still able to make another transaction 7 days later.

    Still don't know where my data was hacked but charges were in $US

  • I found last night transactions from a US netflix account on my wifes CC. Qantas Premier (can't remember who it fulfilled through). These started around the same time.

  • I've had fraudulent transactions on my coles mastercard (same account but two cards, mine and hubby) and they each had a Netflix charge. One was from US and the other from Argentina. Got them refunded but would have no idea where the leak would be from.

    • I cancelled my card (coles) this morning. Had a Netflix charge from Israel on it …
      My card only gets used for insurances, car registration, in-store-shopping and the odd take-away shop. Most online payments go through paypal except amazon stuff …
      No idea how my details got stolen. My credit card was also registered with Google.

      • I hardly ever use my hubby's supplementary card and that was the first one that got breached. Very strange. If it was my own (which happened months later) I would understand as I do buy lots of random stuff everywhere, but from 'secure' websites. If I still didn't have the old Shoppers Protection I would have cancelled all my coles cards.

  • Had a fraudulent charge in September, somebody randomly wired 199 Mexican Pesos from the card. Was an Amex Westpac Black Card that has now been completely cancelled

Login or Join to leave a comment