We’d like to remind Forumites to please avoid political debate on the Forum.

This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

Giffgaff credit card payment not secure - appear to be storing CVV

Last month while buying a new giffgaff goodybag, I accidentally entered the wrong CVV number because I got mixed up between my credit and debit card. But I wasn't totally sure if I'd entered it wrong, as the payment went through.

Yesterday however, I deliberately put in the WRONG CVV for my credit card and the payment went through!

How has the payment gone through? I've put in the wrong CVV on other websites and payment is rejected instantly. It seems to me the only way the payment could have gone through is if giffgaff have stored my CVV from previous transactions.

I believe that in the UK, online shopping services are not allowed to store the CVV.


What do people think about this? It appears that people have been complaining about this to giffgaff for over a year and nothing has been done.


This is a serious breach of online security isn't it?

Comments

  • peachyprice
    peachyprice Posts: 22,346 Forumite
    Part of the Furniture 10,000 Posts Name Dropper
    I don't know the in's and out's of whether it's legal or not, but if it is and they can't do it how could they take payment for recurring goody bags? You don't put the CVV in every month for that.
    Accept your past without regret, handle your present with confidence and face your future without fear
  • wattc
    wattc Posts: 108 Forumite
    I'm not talking about a recurring goodybag (I assume you accept some terms and conditions for that option), I'm talking about a single transaction purchase of a goodybag. This is a payment like you'd do on any website, so the CVV must surely have to be correct?
  • kimminess
    kimminess Posts: 77 Forumite
    edited 9 November 2012 at 3:11PM
    It isn't illegal for them not to ask for the CV2 number - Most companies have it as a requirement for extra fraud protection, as if a card is used fraudulently the actual cardholder can initiate a chargeback which means the company loses the sale money and the goods.

    From my experience, the merchant services I have used allow you to create "rules" for added fraud protection. This means that if no rules are set up, any payment attempted with a valid card number and expiry date can go through, regardless of whether the CV2 number and the billing address match what is registered at the bank.

    (Which also means they probably aren't storing your CV2 number - They just don't have anything in place to reject the transaction when the data doesn't match!)

    That's really shoddy of GiffGaff not to have anything in place though! Leaving themselves open to a rubbish reputation and losing money!

    HTH :)
    :) LBM October 2011 :)
  • System
    System Posts: 178,365 Community Admin
    10,000 Posts Photogenic Name Dropper
    Have you used that card with giff gaff before and used the correct number?

    If so then they have a proven link between your on-line account and that card so there is no risk to them accepting that card without or with a wrong CVV.

    Neither the OP nor giff gaff will lose money as the account is only linked to the single telephone number anyway so any purchase will only be used by the OP on their phone.
    This is a system account and does not represent a real person. To contact the Forum Team email forumteam@moneysavingexpert.com
  • peachyprice
    peachyprice Posts: 22,346 Forumite
    Part of the Furniture 10,000 Posts Name Dropper
    wattc wrote: »
    I'm not talking about a recurring goodybag (I assume you accept some terms and conditions for that option),

    No, you don't, they just use the card details they hold for normal top-up.
    Accept your past without regret, handle your present with confidence and face your future without fear
  • Even with a single transaction,you can store credit card/debit card details on the Gifgaff site for future use.I have always had to fill out my banks security form when buying a goody bag so it seems as secure as any other site.
  • Why dont you ask them?

    Companies that take Credit /card info have to be PCI Complaint now, and have to fill in an annual return, confirming what information is stored on site, how payment is taken and what is being done to mitigate the risk of a 3rd party getting any information.

    Also (I dont know the site) - it depends on how payment is taken, as there are two main ways with big payment providers like Sagepay, where customers stay on your site whilst they proces the payment, or where you go to sagepay to complete the transaction - the latter is very secure, we use this, and when the payment is completed we have no access to the card details, we get the last 4 digits and type of card (bank) only -
  • PS the rules bit is right, we can set which transactions by value, country, isp etc that we want things to agree, or does not matter if does not match
  • SuperHan
    SuperHan Posts: 2,269 Forumite
    Part of the Furniture 1,000 Posts
    Maybe they just aren't checking CVV, and not storing it at all. Amazon for one do not ask for CVV at all when processing card payments. It's just an extra fraud protector, maybe it's one that GiffGaff are using as a deterrent but in fact not looking at at all.
  • shirley999
    shirley999 Posts: 1,960 Forumite
    Part of the Furniture 1,000 Posts Combo Breaker
    giffgaff took too much money out of my son's account 13 days ago. They acknowledged it was an error 8 days ago but he has still not got his money back. I don't understand how this happened in the first place, let alone why it wasn't immediately refunded. What if he hadn't noticed the extra money had been taken from his account? How many other people could have been affected? This looks like theft to me.
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 351.7K Banking & Borrowing
  • 253.4K Reduce Debt & Boost Income
  • 454K Spending & Discounts
  • 244.7K Work, Benefits & Business
  • 600.1K Mortgages, Homes & Bills
  • 177.3K Life & Family
  • 258.4K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.2K Discuss & Feedback
  • 37.6K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.