back
137 comments
Here’s an interesting one: when your card is compromised and a new card number is issued, many banks will allow charges to continue using the old card number, provided the charges were occurring on an ongoing basis from that same merchant before the compromise. This is designed to prevent disruption of ongoing subscriptions in the event of compromise.

About a month ago I was reviewing my statement and noticed I was being billed by Spotify twice each month. I contacted Spotify to ask why they were billing me twice, and they asked for my account info and indicated my account was only being billed once. They then asked for the first 6 and last four of my car number to search that way, and again indicated I was only being billed once.

I sent them a screenshot of my online account statement at which point they agreed they were billing me twice but could not find the origin of the duplicate charge.

Finally it dawned on me - my bank had sent me a new card a long while back because of a suspected compromise. I’d had that card for a long time, and had the number memorized. I gave the old card number to them and bam - they found the source of the fraudulent transactions.

This means that even though my card number was compromised and cancelled, it can still be used for payment at any merchant for which I’ve had an ongoing subscription. Since these are merchants I do business with, it makes it doubly hard to notice the fraudulent charges as seeing “Spotify” or “Netflix” or whatever does not raise my eyebrow. Only in a careful month by month review did I pick up on the fraudulent transactions.

As a side note Spotify was very quick to reverse the duplicates and appear to have blocked that old card number from being used in their system again. Although a frustrating experience overall, they were very good to work with.

This happened to me in a different way: I was giving recurring payments to a .org. I kind of knew how much I wanted to give, but instead of a lump sum I figured I would do recurring for a year. It would give them a little more and seemed to make the guy at my door happy.

Now with this organization, you can donate via the website but to cancel a recurring donation requires a phone call. I called a couple of times to try to cancel but didn't reach anybody. I admit- I wasn't too concerned (a good organization overall), but I was a little pissed nevertheless.

My credit card was skimmed, and I had it cut off. I figured this would solve my problem with the donations as well. Nope.

About two years later my wife (who actually handles the bills in the family) asked me if I wanted to continue those payments. I was pretty shocked- and persisted with the phone calls until I reached somebody to cancel.

Surprise!

I consider the "signing up can be done on the web, but canceling requires a human" to be a dark pattern.

For what it's worth, we've seen that situation from the other side as well. A customer who subscribes with us wants to update their payment details, but in fact creates a new account with a different ID, new card, etc. They don't do anything to close down their old account, we have no way to know that john.smith@example.com is the same as j.smith.1980@example.com and we don't even see their card details, and so of course our system will charge both of them as if they were two different customers.

Sometimes customers do get confused by the automatic update mechanisms for card details, but most of the time it seems to be a useful facility that saves hassle for our subscribers and avoids unintended cancellations. I do think the card companies should be much more transparent with both cardholders and merchants about how their systems actually work, though. We've had occasions where something unexpected has happened, a customer has contacted us to ask what is going on, and all we could do was contact our card payment service to ask them because we had no idea either.

I had my credit card number stolen and the thief used it to subscribe to Netflix. 16 times. That's right, they created 16 Netflix accounts in one day using the same credit card details. Apparently a basic sanity check like "Are we already billing this card?" is not implemented at all, and Netflix support admitted as much.

I think it's in the merchants' interest to proceed with lackluster sanity checks, knowing that some erroneous charges will make it through. It's got to be a multimillion dollar business collecting fees from the unaware, the scammed, and the dead.

They do this based on decades of near unanimous feedback and in many cases anger so cardholders do not have to change all their billing setups just to block txns to new merchants going forward.
I started being charged $17 a month for Amazon Prime. I contacted Amazon and confirmed I didn't have, and had never had Prime. It was a fraudulent third party.

I think the scam must rake in huge sums of money, given that it could slip by for months unnoticed.

EDIT: Amazon confirmed my card was never used to purchase Prime for me or anybody else. The scammers were just charging my card $17, and hiding the charge under the name 'Prime Subscription'.

I just went through this with Chase. Their criteria is six prior recurring payments for a given merchant to allow payments to continue on the old number from that merchant.
Not just in case of a compromise - many issuers will let things go through to the old # when it expires and a new card is sent out.

This can create unforseen problems that aren't fraud related as well.

For example, I had to replace my iPhone at one point, and update my 2FA codes. (Even if you back up your iPhone reguarly, 2FA codes in Google Authenticator are not backed up)

Unfortunately, I'd lost my recovery code for one service provider. They wanted the last 4 of my CC a one of the points of data in their verification process.

Then told me it was incorrect.

Luckily, the CC issuer (who sadly, for security reasons I'd rather not name) had some excellent customer service.

They realized that they had been billing the previous card number since it was a known re-occurring payment, and were able to work with me to retrieve the last four digits of the old card number via an old statement, enabling access to my account.

I've since moved over all my reoccuring payments to that issuer. (And made a document outlining which merchants have which cards on autopay so I can update them when cards are re-issued + backed up my 2FA recovery codes in a secure, offsite, physical location)

This very program by visa allowed LA Fitness to steal several hundred dollars from me after I thought I had unsubscribed (they are also known for being unscrupulous about customer subscriptions). I thought I had cancelled my account, and was unworried about them continuing to charge me because I had recently gotten a new card number anyway. Well, unfortunately WF/Visa had given them my updated card info without my knowledge at a time when I didn't check my statements for several months (I audit charges MUCH more regularly now). They had kept my account active because I hadn't realized how convoluted their "unsub" process was and hadn't jumped through all of their over-the-phone hoops. Long story short I was out several hundred dollars over the course of almost a year, and the CC people were unwilling to help because the charges went undisputed for many months. A very angry visit back to the LA Fitness location was the only thing that remedied the continuing subscription, but I never got my money back. Caveat Emptor.
I worked for a small local company that stored credit card details in plain text. Including CVV. I brought it to there attention and the owner just hand waived me off. “The working system was working”.

This is why cards like The Apple Card, which allows you to generate cards on the fly, is better for consumers. Just generate a card for LA Fitness and delete it when you close your account. This would eliminate a big chunk of fraud (including the shady shit LA fitness does) when your card details are sitting in many databases (some of which are not encrypted in anyway).

I’m not saying Apple card is great, just that feature of it.

Gyms always run unsubscribe scams like this. It's rife here in the UK. After getting screwed similarly I said fuck it and just run around the local park.
Is there something like a small claims court you could take this to? The case seems decent - they have a convoluted unsubscription process on purpose which misled you into thinking you unsubscribed, and you didn’t use their services after that.
This isn't new and has existed for nearly 20 years. Visa's implementation is called VAU (Visa Account Updater[1]) and Mastercard's is ABU (Automatic Billing Updater[2]).

Issuers (banks) have to provide the details of these new cards to Visa/Mastercard, and the systems are certainly capable of updating the details of debit cards. It sounds like TD had a bug where they sent updates for cards which they shouldn't have. ie: TD broke their own rule about only enrolling credit cards.

Card details which do not automatically update are really frustrating for customers – especially on services like Uber. In nearly all cases the customer is going to go and give the merchant their new card details anyway. My understanding is that if card is compromised (as opposed to being lost) then banks should not provide the new details. There isn't really much _additional_ privacy or security risk here beyond those posed by merchants/acquirers holding onto card details already – provided banks do it right.

Though zooming out a little, long-lived payment tokens shared among every merchant a user shops with being the way things are still done is crazy. How long it has took to roll out EMV (chip cards), especially in the US, shows how hard it is to effect change in vast, three+ sided marketplaces like card networks.

[1] https://developer.visa.com/capabilities/vau

[2] https://developer.mastercard.com/product/automatic-billing-u...

Disclosure: I work for a bank.

I prefer to be able to choose whether my card details are updated. By default I do not want updates. I will definitely give Uber my new card, but I like how card expiration kills subscriptions I don't care about without me having to do anything.
It sounds convenient for things like Uber, but should still be opt-in. Since the vendor can apply charges arbitrarily, having your new CC details shared without your knowledge doesn't feel right. I've never seen this anywhere, usually you get a warning that 'your payment method will expire' a few weeks in advance. Might be a US only practice?
It's not just uber, think of all the utility companies and quarterly/annual billers who you put on your card to get rewards points. Who even knows how to change those, or which ones to change? Will you go through a year of statements?

There are lots of ways to make this better, but it exists because the consumer complaints when banks didn't do this outweighed the few who wish to have payment vehicles actually expire.

Banks could do a better job of listing the recurring billers, companies could do a better job of making it easier for you to update payment info (en masse), and networks could stop hiding behind issuers and big TV ads and provide direct-to-consumer controls even for banks that don't choose to offer them.

Disclosure: at the time of this comment, I work for a bank.

I guess the solution is to switch to another bank, VISA can't automatically figure this out.
I don’t think it’s that crazy. Has worked exceedingly well for 75 years. Can’t say that about too many systems.
I’m personally on the side of opt-in/choice, maybe due to the traditional nature of controlling your credit card.

Although, I’d love to see a show of hands from anyone IT related that hasn’t witnessed an outage caused by an expired card/billing account issue. Oh the SSL certs, exchange servers, SaaS apps, domains, etc I’ve seen go up in flames temporarily because of billing issues over the years.

This has been happening in the US for a long while. Several years ago I had significant trouble terminating an Xbox Live Gold account. Exasperated, I canceled my card and got a new one. The next two months the charge was still on my bill. I eventually discovered the problem related to two separate accounts linked to my email address with and without a period in it, with Google considering the addresses identical and Microsoft considering them different.
In the United States, you can also work directly with your credit card company (or bank, in the case of a debit card) to stop a recurring charge. This is possible due to the Fair Credit Billing Act [1]. You might also be refunded for recent charges, if you have evidence that you contacted the vendor and attempted to terminate the service and were billed anyway.

1. https://en.wikipedia.org/wiki/Fair_Credit_Billing_Act

Yep, I think it was started in 2009 or 2010. I remember being called by the banks trying to sell us this new "updater" service and I remember they eventually rolled one out where even if you got a new card number they would update it depending on what category of merchant you were.
Same happened to me circa 2007, I filled a chargeback with my bank and strangely Microsoft didn't bother to ban me as a result - just degraded me to silver as they should have.
Google and Microsoft both consider those to be different addresses. They just lead to the same inbox.
This is clearly a valuable service that just makes sense. To me the only viable argument here is the age old Opt In versus Opt Out argument that the United States and Europe can never agree on.

To me this makes perfect sense to be Opt Out. I would hazard a guess that 90% or more of consumers absolutely want their merchants to all keep going as expected when they for example lose their credit card on a trip and call to get a new one sent to them.

Keep in mind that the average consumer (at least in my observation) saves ALL of their credit card information for easier purchases in the future, a practice that probably has a much smaller overlap with the traditional HN crowd.

Read the article, the credit card company didn't provide PayPal the info. As the story unfolded, we find out that the update was done through PayPal shenanigans that they refuse to explain:

"After initially telling Go Public it got Acuña's information from the "account update services," PayPal backtracked a few days later, saying the account updater service "doesn't apply" in Acuña's case.

So, how did PayPal get her new expiry date? It won't say, citing customer confidentiality — even though Acuña agreed to waive confidentiality to allow the company to answer Go Public's questions."

As other comments have pointed out - the facility to update the details of an expired or cancelled card has been available to merchants / payment providers for years if not decades. I do recall that the type of transactions had to be specifically marked as so at the initial authorisation stage ("Continuous Authority" IIRC) and that would allow the initial auth code to effectively be reused. Visa and Mastercard would then provide a service that allowed you to update card details for those that required it (I can't remember if it was push or pull though).

I do also recall there was a problem when 3D Secure / Verified by Visa was involved - IIRC while the Continuous Authority transaction type allowed an indefinite length of reuse, 3D Secure / VByV only allowed up to 90 days (may have changed or may be a detail of the spec I'm forgetting).

The point is, don't assume cancelling your card will result in cancelling of any recurring debits or allow you to get out of a contract. You have to cancel them with the merchant to make sure they don't continue to charge your new card.

Even without an updater service, obtaining the new expiry date isn't too difficult, as alluded by this HN comment from 2011: https://news.ycombinator.com/item?id=2502530
I renewed two credit cards recently, and both included a new CVC number in addition to the expiry date.
It's been around for a few years https://developer.visa.com/capabilities/vau
I wish I had this with my web clients in past, I had to recover their micro sites many times because they had forgotten providing new payment information to the provider.
This is a well known feature in the SaaS billing world - most large gateways and billing systems (think Stripe, Recurly, Zorua, etc...) have supported this for years. In a recurring revenue model MOST clients are paying via credit card and even when you are a small company, credit cards expiring creates a significant challenge. The auto updating of cards at the gateway / payment processor level help mitigate the impact.
Do we still need the credit card schemes for payments? Could move to a world of bank account to bank account payments, stripping out the payment layers?
I had a similar problem with a website that sells t-shirts. I signed up for a particular t-shirt campaign, providing my credit card number. The campaign didn't get enough joiners, so was cancelled. A few months later, I have to get a new number because of fraud elsewhere.

Fast-forward a year after that t-shirt campaign and now I'm seeing a charge for the shirt. Um ... no? I call the bank and they immediately reverse the charge. But oddly (I thought at the moment) the agent on the phone mentions how they'll let previously used merchants continue to charge on the old number.

I contacted support for the t-shirt folks, and they acknowledged that they'd re-initiated the campaign, found they had enough takers, charged folks, printed shirts and were sending them out. I asked about email notification. Oh, yes, of course they sent email notifications. The date on the email I finally received (four days later) was dated two days after the charge appeared.

I still received a t-shirt and the charge didn't reappear.

This happened to me with an oil company. The refilled my tank when it was 3/4 full and charged me a couple hundred for the privilege and acted like they were doing me a favor. I had just gotten a new card and they complained that they weren't able to charge me. Two weeks later they charged me anyways.
I highly recommend virtual card numbers through capital one's chrome extension called Eno: https://chrome.google.com/webstore/detail/eno®-from-capital-...

They really nailed the UX of generating and managing virtual CC numbers per use case.

For years AmEx has allowed recurring charges to continue after a number or expiration date change. But I'm pretty sure they don't share new information with the merchant as part of that.

It's nice after a stolen card number to know recurring charges will continue automatically.

I believe Monzo (Fintech bank) are starting to implement this. Sounds useful really.

https://community.monzo.com/t/monzo-labs-share-card-replacem...

I reported a card lost and got a new number to avoid SiriusXM. They're still billing!

There should be a way to lock a card completely, in a way that prevents ongoing charges.

This has happened to me for many online purchases: Steam games, Amazon, GOG, etc. kind of useful, but also little confusing and a sketchy.
it's so annoying. Is there any card which can give me something like notification on the mobile app before subscription will occur? Maybe like ones per day with all tx will go to happen and I manually can cancel undesirable part of them. Sort of 2FA for all transaction, where the second authenticator is the mobile app. that's would be ideal for me.
Why do credit cards have expiration dates?
I kind of like that when my card dies, in theory, so do any charges / card data that someone might have ...
This happened to me as well, just a month ago. Also a Visa Debit user; I'm based in Europe however.
Related question - Are there any services offering virtual credit cards in Australia presently?
In their FAQs: "Visa and Mastercard expiry dates will automatically update in your PayPal account using the Visa and Mastercard update feature offered to all card holders."

https://www.paypal.com/uk/smarthelp/article/how-do-i-change-...

and their T&c's say: "3.1 Linking your Funding Source. You can link or unlink a debit card, a credit card, a pre-paid card (in certain cases), a bank account and/or PayPal Credit as a Funding Source for your Account. Please keep your Funding Source information current (i.e. credit card number and expiration date). If this information changes, we may update it at our sole discretion without any action on your part, according to information provided by your bank or card issuer and third parties (including but not limited to our financial services partners and the card networks). If you do not want us to update your Funding Source information, you may contact your bank or card issuer to request this or remove the Funding Source in your Account Profile. If we update your Funding Source information, we may retain any preference setting attached to it.

You may choose to confirm your card or bank account, so that we can verify that the card or bank account is valid and that you are its owner. We may allow you to do this by following the Link and Confirm Card process (for cards) or the Bank Confirmation process (for bank accounts) or other processes which we may notify to you or which we may publish from time to time."

https://www.paypal.com/uk/webapps/mpp/ua/useragreement-full

Intersetingly, it says "If you do not want us to update your Funding Source information, you may contact your bank or card issuer to request this" so I assume you can ask the bank to not share updated details with anyone.

Seems there is also an API that banks could use to let customers know which retailers received the updated details - that would be nice, would also help to see wwhat services that are no longer used still have card details on file.

https://developer.visa.com/use-cases/identify-merchants-rece...

I wonder if this is something that Stripe et all would ever implement on their side, so that it could be an opt-out per service - ie they just ignore the update for a particular card and service implementation?

Has anyone considered that your information is uniquely yours and it has value so unless you have given permission for it to be used the people paying for it and/or selling it owe you a royalty ?