I always pull up the website and confirm before telling them anything.
I always pull up the website and confirm before telling them anything.
This is one of the related reasons why I finally got my ducks in a row and switched away from Chase three years ago. Their potential-fraud-has-happened outreach department was, in my experience, terrible about this. It didn't help that their potential-fraud-detection department was similarly bad. ("You used your debit card at an AM/PM in Washington State!!!!" Yes, I know, it is about 900 feet from my house; I go there regularly.)
Point being, I got quite a few calls from their (real) fraud prevention department about (supposed) fraud. Each time, the rep who called me would get mad at me for not handing over the last four of my SSN and my complete address to the calling party. I pointed out, each time, that they were the ones who called me so I should be verifying them. "But, sir, WE are the bank and you could be anyone who just answered your phone."
The credit union I now use just presents a message with their name and a request to call back. "We may have detected a fraudulent purchase; please give us a call at the number on the back of your card and reference case number [digits]." Fortunately, their system is much better; I've only heard this message once.
A year ago I had an awful experience with this.
We were on vacation at Big Bend National Park, which is hours away from everything in southwest Texas. When trying to pay for breakfast, our card was denied. I tried to call the card company to tell them that it was OK, but couldn't get through - there was no cell service. Outside the restaurant was a pay phone (remember them?) that I was able to use to call their 800 number.
I learned then that they'd actually flagged my card as stolen, so I could no longer use it at all, and to get it turned back on I needed to receive the code they were sending by SMS and read it back to them. The thing was, we were in a dead cell area, we couldn't get the SMS. And Big Bend is mind-bogglingly huge - 1,252 of square miles of mostly desert (there's a whole mountain ranged entirely contained within the park). As far as I could tell, I didn't have enough gas to drive out of the park to get to cell service to achieve this (the park is so big that it's got its own gas station in the middle, and I'd intended to use this - but without my card, how can I?).
It seemed a perfect trap, there was no way we were going to be able to get out. What eventually saved us was that the hotel manager overheard me shouting at the card people, and came out to give me a map, with the places inside the park that can get SMS text highlighted. Using that I was able to fulfill their requirement.
They never were able to tell me why they flagged the card in the first place. They told me that they advise all card holders to warn them when they plan to go out of state. But I live in Texas, and I was in Texas when the charge triggered. They just shrugged that off.
And when you're in a scrape, you can often barter with all three.
The other thing that sometimes works is entering the digit part of your postal code and padding it out with zeros. Ex: if your postal code was 1A2B3C you'd enter 12300.
Also spare ID and cash. The one time I broke this last rule on a trip I was nearly really screwed. (I lost my license and the hotel didn't want to let me check in. They only relented when I showed other ID and was able to make a just large enough withdrawal from an ATM and pay cash.)
Considering that we could eliminate fraud with a private key chip card, this is really, really sad.
I probably should worry more about muggers, but I just can't get myself to be afraid, so.
Since then I always carry three credit cards when traveling, from three different banks, and each from a different payment system in case if a systemic issue.
Bank of America has an interesting optional feature where they geolocate the transaction, and if it's a certain distance away from your cell phone, it triggers the fraud process.
I think if more banks did this, it could cut down on a certain percentage of these problems.
The downside is that you have to trust your bank enough to let it track your phone 24/7. And having recently gone through the privacy notices of several of my bank apps and web sites, I'm not entirely sure that's a good idea, either.
I dropped Chase after about the 4th time they flagged my monthly payment to my ISP as potential fraud.
There has got to be a word for this and similar behavior. Banks, credit card agencies, mobile phone companies are getting really aggressive with how they handle these sort of transaction based interactions and I'm leaning towards wanting to see them get slapped with regulation for it.
I bring it up because a few years back I fell into some hard times, resulting in missing some payments. In a good faith attempt to get caught back up once I found a new job and could right the ship, I called my creditors immediately and tried to make payments and setup payment plans the first paycheck I got.
None of them failed to ask what I thought was a very annoying and horrifically invasive question: "Why were you late on your payments?"
Each time I rebutted asking if disclosing my living situation was required to make a payment or if I should request an escalation to someone who will just take the money. One creditor kept trying to say "We're asking because we want to do you a favor/we understand things are hard sometimes" and I kept asking them if failure to disclose my life situation would prevent payment until they gave up and took the payment.
It strikes me as an offensive, invasive and utterly worthless question and whenever asked I just hang up and call back. Same thing when some entity calls and immediately starts asking for sensitive info. "Send me a letter in the mail with a phone number and I'll call you back when I'm good and ready, otherwise no I'm not just giving you my SSN because you called me at 7:30 on a Monday evening and asked for it".
Fiduciaries are getting bold, I tell you.
I'm far more likely to respond positively, even if ultimately I decline if they were to say "We have a program in place-if you think you're going to miss a payment that will help keep your account on track, would you like to enroll?"
versus
"Why were you late making this payment?"
Of the two, when I went through that period of long-term underemployment, I only ever heard the latter, never the former. Such a curt and abrupt question to ask that comes across much more invasive than helpful.
"We're asking because we want to do you a favor/we understand things are hard sometimes"
There's more than "a program," creditors have different options/programs, etc. Special options exist for people who were effected by certain natural disasters. They probably would have offered to waive the late fee if you missed a payment because you were in the hospital or something. They were starting a dialog with you about your account status in order to work with you; no need to get all offended about it.
While making their second gas stop, their credit cards were being rejected because Amex erroneously thought it was impossible to legitimately use their credit cards between two locations that quickly.
https://m.youtube.com/watch?v=HkZNddd9Pxc
Supposedly they also track flights worldwide to assess legitimacy of card-present transactions through distance-time bounding.
Nordstrom was actually one of the few places that I’ve encountered who does this. Someone stole my identity and tried to open a credit card at their store. As soon as I verified it’s wasn’t me in the store she asked me to call back immediately. She wouldn’t even give me a call back number told me to go their website and find it.
The method they choose to do that, though, is to ask me for a phone number to which they can send an authentication code. I give them the phone number I'm using - the one they called me on. They ask if I want a text or a voice call. Tempting though it would be to put them on hold while I accept the voice call with the security code, I opt for the text message. Phone buzzes, I read out the number, and they seem happy with the result.
I really hope that when they asked me for a phone number they verified it against a list of known numbers associated with the account, but... it really wasn't clear in the context of the interaction.
A bit of a stretch perhaps :)