We'd like to remind Forumites to please avoid political debate on the Forum... Read More »
Beware Scam Websites

Walesnum1
Posts: 18 Forumite

Hello, all. I thought I'd share my story so others won't fall into the same silly subscription based scam that I did.
Initially, I found a spa online through a fake profile on Instagram (DO NOT BOOK ON THIS WEBSITE) - https://luscioustouchspa.com/booknow/726/index.html. The website uses the iFrame method where they hide the terms and condition where you enter your credit card. After looking at the source code for the website, I found a hidden link. After clicking on it, this appears on the webpage under where you add you card details:
The spa website states they would only charge $2.99 for a card payment and no other charges would be taken until after the treatment. After Googling the website detailed in the item description from my bank statements (e.g. mkpdfg.com), I came across the website that confirmed I'd been duped into a subscription scam. These separate websites ask for the first 6 and last 4 digits of your credit card to unsubscribe. So far I've done this for payments that have already gone from my account, I've contacted my bank who've either blocked any future payments or deactivated my card. I've also reported the matter to ActionFraud and ReportFraud.
Initially, I found a spa online through a fake profile on Instagram (DO NOT BOOK ON THIS WEBSITE) - https://luscioustouchspa.com/booknow/726/index.html. The website uses the iFrame method where they hide the terms and condition where you enter your credit card. After looking at the source code for the website, I found a hidden link. After clicking on it, this appears on the webpage under where you add you card details:
By pressing 'Click Here For Access', I certify that I have read and agree to the complete terms of membership and billing and that the card entered above is my credit card. Your access to LocalSexFriends includes a 2 day free trial promo to You're My Reason To Love. If you choose to remain a member of You're My Reason To Love beyond the trial period, your membership will renew at thirty nine ninety nine (notice the lack of a currency here). Your membership to LocalSexFriends will be Free for Lifetime. You will also receive a free membership to InboxPartners.
Your IP Address has been logged for fraud protection.
Charges made to your credit card will appear under "mkpdfg.com (888)496-1427", operated by Staffordish Limited, an eCommerce Merchant located in Cyprus.The spa website states they would only charge $2.99 for a card payment and no other charges would be taken until after the treatment. After Googling the website detailed in the item description from my bank statements (e.g. mkpdfg.com), I came across the website that confirmed I'd been duped into a subscription scam. These separate websites ask for the first 6 and last 4 digits of your credit card to unsubscribe. So far I've done this for payments that have already gone from my account, I've contacted my bank who've either blocked any future payments or deactivated my card. I've also reported the matter to ActionFraud and ReportFraud.
1
Comments
-
Haven't you already shared it once?
https://forums.moneysavingexpert.com/discussion/6255995/subscription-fraud/p1
0 -
Why have you opened another thread on this when you already have one on the topic subscription Fraud?Time is a path from the past to the future and back again. The present is the crossroads of both. :cool:0
-
dr_adidas01 said:Why have you opened another thread on this when you already have one on the topic subscription Fraud?0
-
Walesnum1 said:The website uses the iFrame method where they hide the terms and condition where you enter your credit card.
Iframes are used to allow payment card data to be entered in a secure way by keeping the payment window fully segregated from the rest of the website, thereby minimising the risk of cards being compromised. Naturally this means that such frames don't contain content relating to the rest of the site, but this is by (desirable) design rather than a weakness.Walesnum1 said:
the new information about the iFrame method is an important part of the puzzle on how the scam works.
If you're saying that Ts & Cs aren't displayed anywhere then that's a different matter, but citing their absence from the payment iframe misses the point....2 -
eskbanker said:Walesnum1 said:The website uses the iFrame method where they hide the terms and condition where you enter your credit card.
Iframes are used to allow payment card data to be entered in a secure way by keeping the payment window fully segregated from the rest of the website, thereby minimising the risk of cards being compromised. Naturally this means that such frames don't contain content relating to the rest of the site, but this is by (desirable) design rather than a weakness.Walesnum1 said:
the new information about the iFrame method is an important part of the puzzle on how the scam works.
If you're saying that Ts & Cs aren't displayed anywhere then that's a different matter, but citing their absence from the payment iframe misses the point....0 -
Walesnum1 said:eskbanker said:Walesnum1 said:The website uses the iFrame method where they hide the terms and condition where you enter your credit card.
Iframes are used to allow payment card data to be entered in a secure way by keeping the payment window fully segregated from the rest of the website, thereby minimising the risk of cards being compromised. Naturally this means that such frames don't contain content relating to the rest of the site, but this is by (desirable) design rather than a weakness.Walesnum1 said:
the new information about the iFrame method is an important part of the puzzle on how the scam works.
If you're saying that Ts & Cs aren't displayed anywhere then that's a different matter, but citing their absence from the payment iframe misses the point....
Do they have a registered UK address and contact no.
What does the whois information say about the website, where it was registered, who owns it and when was it set up.
For the site you listed it has no postal address listed, it's contact email is a gmail account.
Website registered nine months ago in Iceland and ownership/administration/abuse contacts are all hidden.
It also quotes prices is dollars.
More than enough red flags on those simple starter points to not go any further.1 -
Walesnum1 said:dr_adidas01 said:Why have you opened another thread on this when you already have one on the topic subscription Fraud?
The scam works because people are stupid and don't seem to do any due diligence before they hand their card details over to random websites on the internet. This subform, the credit cards one and the consumer rights ones are all littered with people handing card details over to some of the ropiest websites on the internet. Until people start to show just an ounce of common sense before they hand their details over, these "scams" won't go anywhere.
I don't even know how this is supposed to work even if it was genuine. There's no information at all on the page on where this spa is located. Wouldn't you at least want to know that before you parted with your money?2 -
kaMelo said: Simple rules for using any website.Do they have a registered UK address and contact no.
What does the whois information say about the website, where it was registered, who owns it and when was it set up.
For the site you listed it has no postal address listed, it's contact email is a gmail account.
Website registered nine months ago in Iceland and ownership/administration/abuse contacts are all hidden.
It also quotes prices is dollars.
More than enough red flags on those simple starter points to not go any further.0 -
Batesy1976 said:It's not "an important part of the puzzle on how the scam works."
The scam works because people are stupid and don't seem to do any due diligence before they hand their card details over to random websites on the internet. This subform, the credit cards one and the consumer rights ones are all littered with people handing card details over to some of the ropiest websites on the internet. Until people start to show just an ounce of common sense before they hand their details over, these "scams" won't go anywhere.
I don't even know how this is supposed to work even if it was genuine. There's no information at all on the page on where this spa is located. Wouldn't you at least want to know that before you parted with your money?0 -
Walesnum1 said:Batesy1976 said:It's not "an important part of the puzzle on how the scam works."
The scam works because people are stupid and don't seem to do any due diligence before they hand their card details over to random websites on the internet. This subform, the credit cards one and the consumer rights ones are all littered with people handing card details over to some of the ropiest websites on the internet. Until people start to show just an ounce of common sense before they hand their details over, these "scams" won't go anywhere.
I don't even know how this is supposed to work even if it was genuine. There's no information at all on the page on where this spa is located. Wouldn't you at least want to know that before you parted with your money?3
Confirm your email address to Create Threads and Reply

Categories
- All Categories
- 349.7K Banking & Borrowing
- 252.6K Reduce Debt & Boost Income
- 452.9K Spending & Discounts
- 242.7K Work, Benefits & Business
- 619.4K Mortgages, Homes & Bills
- 176.3K Life & Family
- 255.6K Travel & Transport
- 1.5M Hobbies & Leisure
- 16.1K Discuss & Feedback
- 15.1K Coronavirus Support Boards