About a month ago I was reviewing my statement and noticed I was being billed by Spotify twice each month. I contacted Spotify to ask why they were billing me twice, and they asked for my account info and indicated my account was only being billed once. They then asked for the first 6 and last four of my car number to search that way, and again indicated I was only being billed once.
I sent them a screenshot of my online account statement at which point they agreed they were billing me twice but could not find the origin of the duplicate charge.
Finally it dawned on me - my bank had sent me a new card a long while back because of a suspected compromise. I’d had that card for a long time, and had the number memorized. I gave the old card number to them and bam - they found the source of the fraudulent transactions.
This means that even though my card number was compromised and cancelled, it can still be used for payment at any merchant for which I’ve had an ongoing subscription. Since these are merchants I do business with, it makes it doubly hard to notice the fraudulent charges as seeing “Spotify” or “Netflix” or whatever does not raise my eyebrow. Only in a careful month by month review did I pick up on the fraudulent transactions.
As a side note Spotify was very quick to reverse the duplicates and appear to have blocked that old card number from being used in their system again. Although a frustrating experience overall, they were very good to work with.
Now with this organization, you can donate via the website but to cancel a recurring donation requires a phone call. I called a couple of times to try to cancel but didn't reach anybody. I admit- I wasn't too concerned (a good organization overall), but I was a little pissed nevertheless.
My credit card was skimmed, and I had it cut off. I figured this would solve my problem with the donations as well. Nope.
About two years later my wife (who actually handles the bills in the family) asked me if I wanted to continue those payments. I was pretty shocked- and persisted with the phone calls until I reached somebody to cancel.
Surprise!
I consider the "signing up can be done on the web, but canceling requires a human" to be a dark pattern.
Sometimes customers do get confused by the automatic update mechanisms for card details, but most of the time it seems to be a useful facility that saves hassle for our subscribers and avoids unintended cancellations. I do think the card companies should be much more transparent with both cardholders and merchants about how their systems actually work, though. We've had occasions where something unexpected has happened, a customer has contacted us to ask what is going on, and all we could do was contact our card payment service to ask them because we had no idea either.
I think it's in the merchants' interest to proceed with lackluster sanity checks, knowing that some erroneous charges will make it through. It's got to be a multimillion dollar business collecting fees from the unaware, the scammed, and the dead.
I think the scam must rake in huge sums of money, given that it could slip by for months unnoticed.
EDIT: Amazon confirmed my card was never used to purchase Prime for me or anybody else. The scammers were just charging my card $17, and hiding the charge under the name 'Prime Subscription'.
This can create unforseen problems that aren't fraud related as well.
For example, I had to replace my iPhone at one point, and update my 2FA codes. (Even if you back up your iPhone reguarly, 2FA codes in Google Authenticator are not backed up)
Unfortunately, I'd lost my recovery code for one service provider. They wanted the last 4 of my CC a one of the points of data in their verification process.
Then told me it was incorrect.
Luckily, the CC issuer (who sadly, for security reasons I'd rather not name) had some excellent customer service.
They realized that they had been billing the previous card number since it was a known re-occurring payment, and were able to work with me to retrieve the last four digits of the old card number via an old statement, enabling access to my account.
I've since moved over all my reoccuring payments to that issuer. (And made a document outlining which merchants have which cards on autopay so I can update them when cards are re-issued + backed up my 2FA recovery codes in a secure, offsite, physical location)
This is why cards like The Apple Card, which allows you to generate cards on the fly, is better for consumers. Just generate a card for LA Fitness and delete it when you close your account. This would eliminate a big chunk of fraud (including the shady shit LA fitness does) when your card details are sitting in many databases (some of which are not encrypted in anyway).
I’m not saying Apple card is great, just that feature of it.
Issuers (banks) have to provide the details of these new cards to Visa/Mastercard, and the systems are certainly capable of updating the details of debit cards. It sounds like TD had a bug where they sent updates for cards which they shouldn't have. ie: TD broke their own rule about only enrolling credit cards.
Card details which do not automatically update are really frustrating for customers – especially on services like Uber. In nearly all cases the customer is going to go and give the merchant their new card details anyway. My understanding is that if card is compromised (as opposed to being lost) then banks should not provide the new details. There isn't really much _additional_ privacy or security risk here beyond those posed by merchants/acquirers holding onto card details already – provided banks do it right.
Though zooming out a little, long-lived payment tokens shared among every merchant a user shops with being the way things are still done is crazy. How long it has took to roll out EMV (chip cards), especially in the US, shows how hard it is to effect change in vast, three+ sided marketplaces like card networks.
[1] https://developer.visa.com/capabilities/vau
[2] https://developer.mastercard.com/product/automatic-billing-u...
Disclosure: I work for a bank.
There are lots of ways to make this better, but it exists because the consumer complaints when banks didn't do this outweighed the few who wish to have payment vehicles actually expire.
Banks could do a better job of listing the recurring billers, companies could do a better job of making it easier for you to update payment info (en masse), and networks could stop hiding behind issuers and big TV ads and provide direct-to-consumer controls even for banks that don't choose to offer them.
Disclosure: at the time of this comment, I work for a bank.
Although, I’d love to see a show of hands from anyone IT related that hasn’t witnessed an outage caused by an expired card/billing account issue. Oh the SSL certs, exchange servers, SaaS apps, domains, etc I’ve seen go up in flames temporarily because of billing issues over the years.
To me this makes perfect sense to be Opt Out. I would hazard a guess that 90% or more of consumers absolutely want their merchants to all keep going as expected when they for example lose their credit card on a trip and call to get a new one sent to them.
Keep in mind that the average consumer (at least in my observation) saves ALL of their credit card information for easier purchases in the future, a practice that probably has a much smaller overlap with the traditional HN crowd.
"After initially telling Go Public it got Acuña's information from the "account update services," PayPal backtracked a few days later, saying the account updater service "doesn't apply" in Acuña's case.
So, how did PayPal get her new expiry date? It won't say, citing customer confidentiality — even though Acuña agreed to waive confidentiality to allow the company to answer Go Public's questions."
I do also recall there was a problem when 3D Secure / Verified by Visa was involved - IIRC while the Continuous Authority transaction type allowed an indefinite length of reuse, 3D Secure / VByV only allowed up to 90 days (may have changed or may be a detail of the spec I'm forgetting).
The point is, don't assume cancelling your card will result in cancelling of any recurring debits or allow you to get out of a contract. You have to cancel them with the merchant to make sure they don't continue to charge your new card.
Fast-forward a year after that t-shirt campaign and now I'm seeing a charge for the shirt. Um ... no? I call the bank and they immediately reverse the charge. But oddly (I thought at the moment) the agent on the phone mentions how they'll let previously used merchants continue to charge on the old number.
I contacted support for the t-shirt folks, and they acknowledged that they'd re-initiated the campaign, found they had enough takers, charged folks, printed shirts and were sending them out. I asked about email notification. Oh, yes, of course they sent email notifications. The date on the email I finally received (four days later) was dated two days after the charge appeared.
I still received a t-shirt and the charge didn't reappear.
They really nailed the UX of generating and managing virtual CC numbers per use case.
It's nice after a stolen card number to know recurring charges will continue automatically.
https://community.monzo.com/t/monzo-labs-share-card-replacem...
There should be a way to lock a card completely, in a way that prevents ongoing charges.
https://www.paypal.com/uk/smarthelp/article/how-do-i-change-...
and their T&c's say: "3.1 Linking your Funding Source. You can link or unlink a debit card, a credit card, a pre-paid card (in certain cases), a bank account and/or PayPal Credit as a Funding Source for your Account. Please keep your Funding Source information current (i.e. credit card number and expiration date). If this information changes, we may update it at our sole discretion without any action on your part, according to information provided by your bank or card issuer and third parties (including but not limited to our financial services partners and the card networks). If you do not want us to update your Funding Source information, you may contact your bank or card issuer to request this or remove the Funding Source in your Account Profile. If we update your Funding Source information, we may retain any preference setting attached to it.
You may choose to confirm your card or bank account, so that we can verify that the card or bank account is valid and that you are its owner. We may allow you to do this by following the Link and Confirm Card process (for cards) or the Bank Confirmation process (for bank accounts) or other processes which we may notify to you or which we may publish from time to time."
https://www.paypal.com/uk/webapps/mpp/ua/useragreement-full
Intersetingly, it says "If you do not want us to update your Funding Source information, you may contact your bank or card issuer to request this" so I assume you can ask the bank to not share updated details with anyone.
Seems there is also an API that banks could use to let customers know which retailers received the updated details - that would be nice, would also help to see wwhat services that are no longer used still have card details on file.
https://developer.visa.com/use-cases/identify-merchants-rece...
I wonder if this is something that Stripe et all would ever implement on their side, so that it could be an opt-out per service - ie they just ignore the update for a particular card and service implementation?