We're aware that some users are experiencing technical issues which the team are working to resolve. See the Community Noticeboard for more info. Thank you for your patience.
📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

MBNA - How did the fraudster get my card details

Options
135

Comments

  • Brute force attack with autogenerated card number. You will find a lot similar stories on the forum. Card never used anywhere, never left drawers and still there was a fraud. In my cause it was Deliveroo on Barclaycard. We don't even use Deliveroo. Bank refunded money and sent new card which is back into the same drawer.
  • born_again
    born_again Posts: 20,456 Forumite
    10,000 Posts Fifth Anniversary Name Dropper
    At one time there were groups in China who did nothing but keep typing 16 digit card numbers into websites till they found one that worked.
    Are you saying that Visa/Mastercard were able to put a stop on that activity ?

    No.
    Security checks are down to you bank. Visa/Mastercard only supply the rights to issue the cards. They take no part in anything else other than raking in money...

    It stopped as it became less cost effective to the groups doing it. As banks security systems picked up on what they were doing as they were so predictable with the sites used, that it was easy to stop.
    Life in the slow lane
  • brianposter
    brianposter Posts: 1,526 Forumite
    Part of the Furniture 1,000 Posts Name Dropper
    born_again said:
    It stopped as it became less cost effective to the groups doing it. As banks security systems picked up on what they were doing as they were so predictable with the sites used, that it was easy to stop.
    You seem to be suggesting that there is some difficulty in preventing brute force attacks. One would have thought such attacks would be easily prevented because it is, in principle, obvious when someone is repeatedly presenting incorrect data.

  • born_again
    born_again Posts: 20,456 Forumite
    10,000 Posts Fifth Anniversary Name Dropper
    born_again said:
    It stopped as it became less cost effective to the groups doing it. As banks security systems picked up on what they were doing as they were so predictable with the sites used, that it was easy to stop.
    You seem to be suggesting that there is some difficulty in preventing brute force attacks. One would have thought such attacks would be easily prevented because it is, in principle, obvious when someone is repeatedly presenting incorrect data.

    Security systems do not work in that way.

    There is no effect way to stop them. 
    Life in the slow lane
  • You seem to be suggesting that there is some difficulty in preventing brute force attacks. One would have thought such attacks would be easily prevented because it is, in principle, obvious when someone is repeatedly presenting incorrect data.

    Security systems do not work in that way.

    This seems to be a very odd answer. Surely any secure system will have a procedure for dealing with repeated incorrect requests ?

  • born_again
    born_again Posts: 20,456 Forumite
    10,000 Posts Fifth Anniversary Name Dropper
     Picking them up is easy via security systems.

    The issue is how do you stop them,




    Life in the slow lane
  • The issue is how do you stop them,
    30 second delay in response to suspect enquiries ?

  • Brute force attack with autogenerated card number. You will find a lot similar stories on the forum. Card never used anywhere, never left drawers and still there was a fraud. In my cause it was Deliveroo on Barclaycard. We don't even use Deliveroo. Bank refunded money and sent new card which is back into the same drawer.
    Same happened to me. I live alone and my card never left the drawer but someone made a purchase on Amazon. I called the bank and Amazon, so got a refund and a new card (which is also back in that same drawer). Glad this thread was posted as I always wondered how my card details were pinched in this way.
    "The problem with Internet quotes is that you can't always depend on their accuracy" - Abraham Lincoln, 1864
  • born_again
    born_again Posts: 20,456 Forumite
    10,000 Posts Fifth Anniversary Name Dropper
    The issue is how do you stop them,
    30 second delay in response to suspect enquiries ?

    Which does exactly what?

    How many online purchases have you made & watched the spinning wheel while it's checked?

    They can pump hundreds of card numbers through in minutes via programs. Most will not be valid, the odd one will be. That is what they are looking for the valid numbers.
    Some maybe stopped by retailers as they check the card fits the valid numbers. Others will be stopped as banks security.

    Other times they set up their own charity and process the numbers through that. 
    They are easy to pick up at banks end.
    Life in the slow lane
  • brianposter
    brianposter Posts: 1,526 Forumite
    Part of the Furniture 1,000 Posts Name Dropper
    They can pump hundreds of card numbers through in minutes via programs. .
    But can they do this whilst making it look as if each number is coming from a different source ?

Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 351K Banking & Borrowing
  • 253.1K Reduce Debt & Boost Income
  • 453.6K Spending & Discounts
  • 244K Work, Benefits & Business
  • 598.9K Mortgages, Homes & Bills
  • 176.9K Life & Family
  • 257.3K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.1K Discuss & Feedback
  • 37.6K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.