📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

Highly unusual RBS credit card fraud

In early 2018 I received a replacement credit card, which was issued by RBS who took over the Mint business.  This new card was immediately cut up and returned to RBS, never having being used anywhere.  In fact even I did not take note of the new card number (although I know it was different from the Mint one), let alone expiry date or CVV2.

No purchases were made with the card for 3 years.  Then suddenly in January 2021 a fraudulent Amazon purchase for £28.86 appears on my statement.  Upon querying this RBS hinted that they knew exactly what had happened, and immediately refunded the transaction.

Ignoring the fact that I should have cancelled the card in the first instance...

How can it be possible for a card that was never used "in the wild", and without known expiry or CVV2, to be compromised?  RBS are remaining very tight lipped on the matter stating only "ongoing investigations".


«1

Comments

  • [Deleted User]
    [Deleted User] Posts: 35,242 Forumite
    Part of the Furniture 10,000 Posts Photogenic Name Dropper
    It's not uncommon. Thousands of combinations of numbers are tried until one gets through.

    RBS won't tell you any more.
  • TVAS
    TVAS Posts: 498 Forumite
    100 Posts
    Inside job? Unlikely to have waited for 3 years to commit the fraud. Weird.
  • pcbbc
    pcbbc Posts: 4 Newbie
    First Post
    The card issuers got wise to that game a long time ago.  They not longer issue sequentially incrementing card numbers to successive accounts. So given a valid card number you can't "guess" a set of other valid cards simply by adding 1 and calculating the Luhn.  The search space to hit on a valid card by chance is vast, and then you have to factor in "guessing" of other checks made for online purchases (expiry, CVV2, etc).

    They may try many transactions as you say, but those will all be with known card numbers from some data breach of card numbers (from your local petrol station used to be a favourite).  The interesting thing about this is that only myself and RBS should have had access to the details.
  • TVAS said:
    Inside job? Unlikely to have waited for 3 years to commit the fraud. Weird.

    Yes, my guess is that some inside information must have been provided as the card details should have been known only to myself and RBS.

    So I don't think that this was in any way related to me cutting up and returning the original card 3 years previously.  But the fact that I did raises some very grave concerns about the source of the account details necessary to conduct this fraud.

    Regrettably it seems neither Action Fraud not the ISO are interested in pursuing this further.
  • mustiuc
    mustiuc Posts: 99 Forumite
    Sixth Anniversary 10 Posts Name Dropper
    I have the exact problem. CC been used last time 2 months ago, prior to that unused for more than 6 mths. Found after 4 days from the "transaction" date a payment to "amazon * random numbers and letters". Got in touch with CC customer service, froze my account, issued another card, on going investigation. No one contacted me since - apparently they have 21 days to respond.
    Very weird as the only card to be vulnerable for me would be the debit card/account... Which looks like a war zone, payments after payments everywhere and to anyone (online and/or retail).
    £25.50 been spent, my amazon account/services been used in feb-mar last time. Customer services were still insisting maybe I've done an order and i forgot about it despite telling them multiple times I'm not a fan of amazon shopping and I know exactly what I do in my life and where my money goes each time.
    I won't be surprised to be refunded but no explanation to be given. 
  • born_again
    born_again Posts: 20,726 Forumite
    10,000 Posts Sixth Anniversary Name Dropper
    mustiuc said:
    I have the exact problem. CC been used last time 2 months ago, prior to that unused for more than 6 mths. Found after 4 days from the "transaction" date a payment to "amazon * random numbers and letters". Got in touch with CC customer service, froze my account, issued another card, on going investigation. 
    Most card compromises happen a long time ago. If someone takes a lot of card details, they then sell them on (dark Web) in batches. So in many cases it can be years before a lot surface.
    If they have expired, they just change the exp date, as they are pretty easy to guess. Replacement cards mostly have the same card no. CVV is not used for most fraud.
    Think back to the BA compromise in 2018. We had to cancel Thousands of cards, not one with fraud on it. Started to see in in the security system about a year later. Of course all declined as stopped cards.
    Life in the slow lane
  • phillw
    phillw Posts: 5,665 Forumite
    Part of the Furniture 1,000 Posts Name Dropper
    edited 23 April 2021 at 10:49PM
    pcbbc said:
    and then you have to factor in "guessing" of other checks made for online purchases (expiry, CVV2, etc).


    Has Amazon started requiring CVV yet?

    If you control a large bot net then running random card numbers and expiry dates through amazon should be pretty simple.

  • A_Lert
    A_Lert Posts: 609 Forumite
    500 Posts Third Anniversary Name Dropper
    Bug or glitch in RBS's system is another possibility.
  • Shakin_Steve
    Shakin_Steve Posts: 2,813 Forumite
    Ninth Anniversary 1,000 Posts Photogenic Name Dropper
    Perhaps the expiry date on your card had been reached and a new one posted out. Have you changed your address in the last three years?
    I came into this world with nothing and I've got most of it left.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 351.3K Banking & Borrowing
  • 253.2K Reduce Debt & Boost Income
  • 453.8K Spending & Discounts
  • 244.3K Work, Benefits & Business
  • 599.5K Mortgages, Homes & Bills
  • 177.1K Life & Family
  • 257.8K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.2K Discuss & Feedback
  • 37.6K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.