Wowcher - have I been hacked

I woke up today to read an email from Wowcher confirming I had changed my email address. There was also an email from Paypal for a payment of £127.99 for Wowcher sales. All of this was a surprise and a shock to me. 
I immediately checked my bank account, my Paypal account and tried to contact Wowcher to quesry what this was all about. Contacting Wowcher is annoying, you need to use Whatsapp or email them, not great when a possible fraud and hacking scenario is taking place.

I halted my Paypal automatic payment status to Wowcher ( who knew this was even a thing ) and contacted Chase Bank to report my concerns.

When Wowcher finally replied to my Whatsapp after some nudging they said they would refund me within 3 days. If that happens I'll be relieved. However when I found a way into my Wowcher account by instead using Google login option ( rather than email and password combo ) I found it very strange that I had no history of orders and my email address was reverted to my own in the personal details tab.  

So what exactly had happened here. Was this an Internal hack ?  My password was unique to Wowcher so should not have been copied or guessed from elsewhere ?

Comments

  • km1500
    km1500 Posts: 2,722 Forumite
    1,000 Posts Second Anniversary Name Dropper
    are you sure the email was actually from wowcher
  • There are a huge amount of possibilities. But if someone has hacked the passwords of every Wowcher customer then they'd be more than just you on here taking about it


    1. Both emails are phishing emails to get you to enter all your credentials into fake websites. I guess seeing that PayPal message would tempt you to use links in the Wowcher email to log in and see what had happened

    2. You logged in through a public WiFi recently, someone else on it sniffed your password 

    3. You logged into what you thought was a WiFi but was a hackers WiFi that they called "Starbucks-guest" or something to tempt you

    4. You opened a scam email on your phone/pc and it installed a virus

    5. As above but you visited some "unsafe" websites

    Etc etc 
  • I don't use links in potentially fake emails ( I do work in IT  )  but an update here is that I did have Wowcher customer support send me a password reset link to a different email address. This allowed me to regain access and amazingly the full address of the delivery was still there along with the items ordered.  No coincidence that both addresses of Wowcher HQ and the ordered items are all in Derby.
    My initial suspicion would be an inside job from an employee with access to customer details.
  • I think they will take this extremely seriously.
    You may find it difficult to get through to a fraud department on the usual channels but you may have a right to get the contact details of their data protection officer to report a breach.

    Everything will be logged and audited. You might be a trial run for this fraudster (if that is the case) so quicker the better. Good luck 
  • I had exactly the same thing at exactly the same time I think, a voucher bought close to midnight after not using this account since 2019. Really hard to sort out, as Wowcher only deal with Whatsapp and I don't want to give them any more information if their site has been hacked. Paypal say its definitely their end there's a breach but I changed everything anyway. Really struggling to a) get a refund and b) close the account and reassurance no leaked data. Yet this post suggests many of their accounts and data have been compromised. Is there an agency to report them too? They obviously hold paypal, credit card, address etc details
  • The exact same thing happened to me last night. My bank has cancelled my card, my passwords have been changed for PayPal and I have had my wowcher account deleted. I don’t trust them 

  • leedevee said:
    I had exactly the same thing at exactly the same time I think, a voucher bought close to midnight after not using this account since 2019. Really hard to sort out, as Wowcher only deal with Whatsapp and I don't want to give them any more information if their site has been hacked. Paypal say its definitely their end there's a breach but I changed everything anyway. Really struggling to a) get a refund and b) close the account and reassurance no leaked data. Yet this post suggests many of their accounts and data have been compromised. Is there an agency to report them too? They obviously hold paypal, credit card, address etc details
    They cancelled my account straight away via email and also refunded almost immediately through WhatsApp. My original message to them said that I suspected fraud and I think that scared them a bit and they acted immediately 
  • KateLndn
    KateLndn Posts: 86 Forumite
    Tenth Anniversary 10 Posts Combo Breaker
    edited 10 February 2024 at 4:22PM
    The exact same thing happened to me however my payment method is defaulted to Paypal and when the trasaction was made they emailed me to say they had noticed some unusual activity. At this point I had no notification from Wowcher. As soon as I changed me Paypal details to secure my account I received a notification from Paypal to say I had made a payment to Wowcher. I haven't used Wowcher for over 3 years so I because suspicious. My account login details (name and password) and my email address were not changed but the address the items were being sent to was: 

    Hassall Gill Associates

    According to Companies house this was a family business which has dissolved.

    I contacted Wowcher via Whatsapp like you and they have processed my refund. I have a feeling Wowchers data has been compromised as my login details were unique to Wowcher. 

    Was the address the items were being sent to the same for you

    Adam_GB?
    September 2022: £100 Zoflora BundleAugust 2022: 51st State VIP tickets July 2022: White Claw bundle June 2022: 2 tickets to the World BBoy Championships April 2017: Hotel Chocolat, family ticket to Molly monster premiereMay 2017: Dole smoothie trial.
  • I have been hacked tonight after receiving a PayPal notification saying I had paid £49 to Wowcher. I've raised a dispute with PayPal and contacted Wowcher so will await their response. Is there a way to see where the item is being sent to as I can see the voucher has been redeemed? I've also emailed the company that the voucher is for. 
  • Adam_GB said:
    I woke up today to read an email from Wowcher confirming I had changed my email address. There was also an email from Paypal for a payment of £127.99 for Wowcher sales. All of this was a surprise and a shock to me. 
    I immediately checked my bank account, my Paypal account and tried to contact Wowcher to quesry what this was all about. Contacting Wowcher is annoying, you need to use Whatsapp or email them, not great when a possible fraud and hacking scenario is taking place.

    I halted my Paypal automatic payment status to Wowcher ( who knew this was even a thing ) and contacted Chase Bank to report my concerns.

    When Wowcher finally replied to my Whatsapp after some nudging they said they would refund me within 3 days. If that happens I'll be relieved. However when I found a way into my Wowcher account by instead using Google login option ( rather than email and password combo ) I found it very strange that I had no history of orders and my email address was reverted to my own in the personal details tab.  

    So what exactly had happened here. Was this an Internal hack ?  My password was unique to Wowcher so should not have been copied or guessed from elsewhere ?
    I had the same happen to me yesterday! 2 separate orders were placed through PayPal auto payment to the value of £40, but the 3rd hadn't gone through due to PayPal sending a text message asking to verify the purchase. 
    Then the hacker has changed the email address on the account preventing me from accessing it! 
    I contacted PayPal and was refunded for both purchases today.
    Still trying to sort things out with wowcher to get back access to my account and close it as it has all my personal details. 
    I also think it's an inside job! (Good bit of detective work on your part) 
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 350.3K Banking & Borrowing
  • 252.9K Reduce Debt & Boost Income
  • 453.2K Spending & Discounts
  • 243.3K Work, Benefits & Business
  • 597.8K Mortgages, Homes & Bills
  • 176.6K Life & Family
  • 256.3K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.1K Discuss & Feedback
  • 37.6K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.