MSE News: Credit cards cancelled after mystery online shopping 'data breach'

Options
135

Comments

  • I_luv_cats
    I_luv_cats Posts: 14,441 Forumite
    First Anniversary Name Dropper First Post
    Options
    I had a potential fraud letter from 'Capital one' in one envelope AND a new card in another.

    (new end date and 3 digit number)


    They say they are being precautionary by issuing a new card.



    (only store card on Nowtv/HungryHouse/Tesco.com/Paypal)

    Use Amazon one session at time, no storing.
  • Steamrunner
    Options
    My card was cancelled today by Tesco, however I have only used it for Evernote, Audible and Ocado Smart subscriptions. It hasn't been used to buy anything for over a year, probably even two. Not pay at pump, not Dartford, nothing. I've cancelled the account anyway as I don't need it any more.

    I'm wondering if it's actually a payment processor that's been breached- worldpay or something like that, maybe.
  • reclusive46
    reclusive46 Posts: 2,698 Forumite
    Options
    Two work colleagues had their corporate Amex cards cancelled today for the same reason. So it must be a retailer that takes Amex. It also rules out the payment processor theory as Amex transactions don't touch any payment processors.
  • KevinLawry
    Options
    My AmEx issued through MBNA was cancelled due to a fraudulent payment on the night of the 4th as well - the fraud attempt was a purchase at House of Fraser in London, I use many online sites so it could be any of them that were compromised
  • megaginge
    Options
    Must be Tesco..
    Hello There. :beer:
  • tgroom57
    tgroom57 Posts: 1,431 Forumite
    First Anniversary Name Dropper First Post
    edited 7 February 2016 at 1:36PM
    Options
    So far, I'm not affected. But I did have a *lot* of trouble with a payment page this week that just happens to belong to an online-only retailer on the Clubcard Boost list.

    Did the Tesco cardholders use any of the retailers in Clubcard Boost?
  • Monty_Mouse_2
    Options
    I received a text message this morning for my MBNA card stating it was at risk and they were sending me a new card.

    I phoned the customer service number on the back of the card to check this was a genuine message, I had my card cloned a few weeks back so I am a bit sensitive about it at the moment.

    MBNA customer service confirmed that a retailer had suffered a release of credit card details involving a large number of customers and that as a precaution they were identifying those exposed and contacted them. They refused point blank to tell me the retailer.

    On the one hand I am happy that MBNA seem to be on the ball, but I am seriously not happy that they will not tell me who has released my personal details. These are my details after all and I was under the impression that anyone holding credit card information had to meet PCI standards to ensure the details are safe and secure. I don't want to do business with a company that fails to do this.
  • montys
    Options
    I also received a text from MBNA saying my card had been compromised. If it is an online retailer I can narrow it down as I always use my Amex card where possible, so it's not a retailer than accepts Amex. My wife also has an MBNA card and also got the text so it has to be an online retailer that we've both used, which narrows it down even further. The only three companies that I believe match are :
    John Lewis Insurance
    Craghoppers
    DVLA (for pay Car Tax).
  • King_Of_Fools
    Options
    montys wrote: »
    John Lewis Insurance
    Craghoppers
    DVLA (for pay Car Tax).
    Have never use the first two and have never paid DVLA with a credit card. I wonder if the DVLA use the same payment processing as the Dartford Toll.
  • Monty_Mouse_2
    Options
    I've just logged a complaint with the Information Commissioners Office regarding MBNA refusing to provide me details of who has breached my personal data as these are after all my details, so I have a right to know, and without any information regarding the breach I don't know what appropriate action I need to take to.

    I've also asked whether they are aware of what sounds like a major breach of DPA and PCI and what they are doing to investigate it. I'm interested to see what they come back with, sadly there is a 30 day response time.
This discussion has been closed.
Meet your Ambassadors

Categories

  • All Categories
  • 343.2K Banking & Borrowing
  • 250.1K Reduce Debt & Boost Income
  • 449.7K Spending & Discounts
  • 235.3K Work, Benefits & Business
  • 608.1K Mortgages, Homes & Bills
  • 173.1K Life & Family
  • 247.9K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 15.9K Discuss & Feedback
  • 15.1K Coronavirus Support Boards