Deliveroo users are getting defrauded
newstatesman.com
newstatesman.com
That will probably get you a refund quicker (the transactions will likely be held until clarified) and will stop any further fraud.
As for Deliveroo's support team... Not very good in my experience, but that's common. Their competitors are no better.
Besides, I said that I'd only do this if I didn't get a refund through Deliveroo/bank/CC chargeback. I certainly wouldn't start with small claims court.
Who is "most vendors" exactly?
Also heard it with lots of other vendors, but won't name without having something more substantial to back it up with.
I would never touch a company again that did that to me anyway.
If I have a shitty customer service interaction with an Amazon rep, I might have to weigh the chargeback versus the value of my Kindle library, my AWS instances suddenly going dark, etc.
In the case of Uber, I might find myself severely restricted in transit options in an unfamiliar city.
If you're lucky. Otherwise they'll offer you "credit".
Thanks for the downvotes.
Plus the following dialogue: what was your name?...I am reporting you to xyz state attorney general's consumer fraud division is incredibly effective.
I worked in call centers for years and we laughed at people like you for a whole multitude of reasons.
The main reason being once you say this I'm no longer obligated to help you. Since you've decided to make this a legal situation instead of a customer service one you'll now need to talk to our team of lawyers that are on retainer. Anytime you call or email you'll get auto routed to our legal department forever who will go out of their way to not help you.
The reality is that people make legal threats dont actually follow through because they aren't people that understand the law or how it works, if they did they'd be taking actual legal action against us, not making idle threats to people making $19 dollars an hour.
Again I'm not threatening to bring legal action. I'm just letting the 800 lb gorilla know about the situation and they perhaps might want to do something.
Had an old phones screen repaired at a store inside a Walmart. They fixed it but half the screen had no touch capability. They were highly resistant to doing anything about it until I said I would just do a charge back. Tone instantly changed.
Now I personally don't let third parties store my cards, but it's quite common in this day and age of saas everything
Disclaimer: I work for one of those companies, but not on that product.
Which is US only. Is there anything like it for the UK?
https://www.fca.org.uk/consumers/unauthorised-payments-accou...
"In most cases the bank must refund the payment without undue delay and by the end of the business day following the day on which it became aware of the problem, unless it has reasonable grounds for suspecting that you have acted fraudulently."
"When your bank refunds an unauthorised payment it must also refund any charges and interest you have paid because of the unauthorised transaction."
Some providers are interestingly stubborn when it comes to charge backs and can hold on to the (fraudulent) vendors side even if you're clearly right.
Monzo in the UK is a prime example for that. An internet vendor charged me more than he should and refused to void the transaction (basically text-book fraud) and I filled for a charge back with monzo. I was extremely confident that it wouldn't take much however monzo customer service resisted to help.
The monetary value wasn't much however in the end I perfectly understood that this "protection" does not exist on the credit card issuer/bank side of things.
Be careful.
Generally guidance is that you are entitled to a refund from the bank only if you did not authorise a particular transaction.
The Moral of the Story: Money institutes may not cover you like you think they will.
I've learned my lesson.
Again, be -very- careful.
Not if you didn't read your debit card agreement, no. Nothing you've stated wouldn't be clearly spelled out in the agreements I've seen for debit cards. I mean, I can see how this happens: looks like a credit card, must have the same protections as what people online say about credit cards, right? Nope.
If I remember correctly, debit card protections don't exist below £100, so they literally can't do it for a few quid, but they can for larger sums of money.
This isn't an example of Monzo being terrible, this is an example of debit cards being terrible.
It's just that credit cards must offer chargebacks by law.
Banks have a vested interest to work with you for purchases made on credit because it's their money. Debit purchases have no such leverage and thus have lower protections.
If it costs more than £100, use a credit card in the UK as the CC company is jointly liable for any issues, even faulty goods.
U.S. banks, as well. Twice Citi has refunded me within minutes. Chase within hours. It seems the policy is "give the customer the money, and we'll sort it out later."
The point is to not have to need to dispute a charge.
You would get your debit card within a week max. You can transfer limited amount from your original bank account to Monzo account and even on top of that you can set some restrictions on how much amount can be withdrawn and there are some special features like POTS which are very useful.
I am not saying this is the best, but even if someone steals your monzo card details, you can reqeust for a new one and your original bank card details are still safe.
Note: All this works, only if you don't use a credit card.
Edit: although I guess they'd just do it in the middle of the night so doesn't really help.
The very crude answer is to get a prepaid card and load it with enough to cover each purchase, then toss it as soon as it gets misused. Which works, but doesn't sound worth the hassle unless you seriously expect a bad outcome.
https://www.thechangeaccount.com/ > This is basically the sole "feature" of credit cards I value. Any time I'm buying something from
> somewhere that might act poorly, I use a credit card for the free leverage I have in a disagreement.
But without a credit card, they wouldn't even have been able to get your money without authorisation. I don't see how something like this would have been possible with a system that requires explicit authorisation per payment.In this scenario, the bank is jointly responsible for the transaction, and should refund you if the transaction isn't completed satisfactorily
I don't understands your point. Are you saying the ideal scenario would be to fill the cards information each time? The fact that it's a credit card doesn't change that it was prefilled, a debit card or wire transfer is the same. Credit or not, if it's already there, the one that access your account can use it.
With a credit card though, you can do a chargeback, which not only give you your money back, also add a direct cost (and a steep one from what I understood) to the merchant that made the transaction. As far as I know you couldn't do the same with a debit card.
Between the payment and the delivery the company went bust.
I though I was out of the money, but after a brief search I found out that, although there is no legal requirement to do so, VISA in the UK offers (or at least used to) the same chargeback facility to debit cards as for CCs. I visited my bank branch which gave me a phone number to contact, sent in a bunch of paperwork and after about 2 weeks I got my money back. I was very pleased as you can expect.
When I pay with my bank card with an internet payment through my bank, the authorisation is handled by me and my own bank, and nobody else. Nobody else can ever make that kind of payment without access to my password and my 2FA system. That's how it should work.
Their story is about a situation where they gave explicit authorisation. They intentionally paid.
In the Deliveroo case, however, it's the inherent insecurity of credit cards that made that problem possible in the first place. In light of that, the ubiquity of credit cards for online payments where data is so easily copied and leaked, never ceases to puzzle me.
Mostly chargebacks are for actual fraudulent use of the card, and the process also includes getting a new card number.
Lately, most chargebacks I’ve done have actually been issued by the card itself after they detected suspicious activity and sent me a text alert asking about specific charges.
In one case, it was a debit card which I had received in the mail, activated, and never used and had never left the house. That one was particularly bizarre and I let them know something was very wrong there.
Google this: "Account information disputed by consumer, meets FCRA requirements" and you will learn more.
And I suppose that the effect you describe results from abusive requests from charge backs. I doubt you will be refused a mortgaged because you were a victim of theft in the past...
Don't be so certain about this. The credit reporting agencies are evil, nasty blackboxes and it is not transparent how your score is influenced, even by fraudulent stuff.
[1] https://www.wbs-law.de/datenschutz/unternehmen-darf-nicht-mi...
Additionally, you can and should file a police report for fraud when hit with such a scheme, it makes dealing with your card-issuing bank and the CRAs so much easier.
The bank went from "we won't help you" to "oh, we'll fix that" about as soon as I told them I had a crime reference number...
I guess this has something to do with the penalties for making a false police report being much higher (in criminal law terms) than lying to a bank.
But then is there literally any alternative payment method in the US that does not involve a creditcard? It seems like the US banking system has just not invented anything in the last 30 years. Its not rocket science: money from my bank account to Deliveroo's bank account in (near) real time.
Surprisingly the US is much harder to convince. Ask people under 30yo in Aus or the UK when they last wrote a cheque, and the answer "what's a cheque?" is likely the response. Signing for a payment, magstripe, even using a PIN is mostly a distant memory.
I can go weeks without my wallet now, Samsung Pay on my phone works just about everywhere in Australia, and it's great. Banking app even lets me generate a code to get cardless cash from ATMs, should I need notes.
For transactions bigger than ~AUD100 I do have to enter my pin but that's a minor inconvenience.
It's what train companies in the UK send you 3 weeks after you fill a compensation for delay claim...
If a company is prepared to stiff me like that, the convenience of having it fixed right away is not worth the concession of letting them have my money when all is said and done. Is that just me?
It is mentioned in passing in the article itself.
> Of the roughly 40 people I spoke to, not a single one had been refunded by the delivery service; those who did get their money back had got it from their bank.
I have almost always had a full refund (otherwise just partial for what was wrong/damaged) but what I really LOVED was how transparent they are throughout the process.
They message you when your concerns resulted in a ticket opening, when someone picks up your support ticket, when they are working on a resolution, and then when they found a resolution for your issue.
It's very seamless as well - I was experiencing issues on their web platform, DM'd support on Twitter, received info by email and on the UberEat app and at not time was there inconsistencies.
If it wasn't for the quality of their support team - I would have stopped using UberEats a long time ago.
Getting a refund on what you ordered but did not receive is not compensation, it's what they must do.
So, they have good customer support, but suck at the basic function of the business? And you keep using them?
Money-as-a-service (banks) give you the power to do this. But dependence on anything-else-as-a-service gives the provider power to make you think twice.
I discovered recently that drivers are allowed - without penalty - to reject an order when they reach the pickup location if they see the receipt and decide it is too far to travel [1].
As a customer you just see your food go: `Assigning Driver -> Driver En Route to Pickup -> Driver Arrived at Pickup Location -> Assigning Driver`, for two hours on repeat. Eventually your cold food arrives 2 hours later, and you are offered £5 credit for your ruined meal.
I live in Central London (Old Street), and have had this happen repeatedly with restaurants that are not far from me.
[1] = https://www.reddit.com/r/deliveroos/comments/82w97o/riders_o...
I must be missing something about theses services given their popularity. Do you mind explaining why you use them?
Food temperature is a personal preference, some people are really picky about food being hot/fresh, some aren't. I prefer the taste of room temperature food over hot food so "sitting around for 20 minutes" would be a feature for me.
... and then jumping into his new C300 to deliver it.
I'm not sure I can process that. New Mercedes, let's put miles on it delivering fast food...
And some people like really like McDonalds and don't care for the fancy stuff.
It's not for me, but it basically it boils down to "people like different things than me."
I know someone else who can't understand why anyone would ever play video games "its time and effort for zero reward."
Some people enjoy doing work on their car, while others would rather pay someone to do the work for them.
Humans aren't the same.
Justeat delivers from fast food.
Deliveroo costs more because it's providing a delivery service for restaurants that don't normally deliver.
So I'm getting good food. When in a restaurant, things sit in a kitchen for 10 minutes waiting for the rest of your order anyway. 10 minutes in a thermal bag is the same.
"To me this ruins the meal"
shrug, I'm not sure what you're expecting anybody to say. I can't really change your mind on what is hypothetical situation for you. I've ordered plenty, it's generally no worse than the quality I would get in the restaurant (other than the presentation in a bespoke takeaway box not a plate).
Also, what kind of presentation are you expecting for a burger anyway? It's a burger, with some artfully surrounding chips? Ordered to go, it's a burger, with the chips in smaller box instead of surrounding the burger.
But at that point you're basically just objecting to all delivery food ever. Which is fine but, like, you are aware that it is a huge industry and has been for decades and people do like it? Convenience trumps artistry (and optimum temperature) for many people a lot of the time.
Although those things are going out of fashion quite fast.
But even then you would 'understand the appeal' but be opting out of using them.
It's a weird turn of phrase IMHO, as if the person has never heard of food delivery before.
What does having a conscience have to do with whether or not you use a food delivery service?
I'm surprised that this hasn't occurred to you already at least as an issue for someone (not necessarily you, or, for that matter, me). Still, this given that this is a thread where things like "food delivery" need to be explained from first principles, I shouldn't be too surprised.
So they should do something else. Those drivers determined that delivering the food was the best use of their time. I don't think it's right to voluntarily choose this specific job and then make people feel immoral for using the service they signed up to provide.
I live 20 minutes outside of a small town in Norway and the restaurants/kebab shops don't generate enough take-away business to provide this service themselves.
There is another company that does that for them and services all making take-away possible at all.
Now this company actually operates with a time guarantee, that is if the food is not delivered within an hour or if the order is "refused" due to reasons the OP touches on you get your money back.
I've yet to have any that happen to me, possibly because it would actually be bad for those delivering.
I could drive and pick it up myself, but sometimes you just want to be a couch-potato and be lazy!
I want food, I can't be bothered to cook or go out?
Are you seriously struggling to understand food delivery? Or if you mean what's the benefit over e.g. ordering direct from a restaurant, is you have a lot more choice and it's much higher quality than traditional take aways (you get proper restaurant food)
You're not going to get a gourmet steak hot from the grill with precisely placed edible flowers laid delicately in it. But a bag of fries and a carton of fried chicken does not require eggs-in-space-shuttle level cushioning
"Old-fashioned"? Nice try, Grandpa. I'm approaching retirement, and delivery of restaurant food has been a thing since before I was born. Hell, Domino's was founded in 1960.
Hey, I quoted you accurately. :-) But fair enough. My counter would be that if your bar has fallen to fast food territory, perhaps warmth and presentation isn't an issue at that point for some folks. But I haven't been part of the fast food demographic for decades, so what do I know?
I would even prefer KFC bucket with 25 chicken wings delivered to me, not pizza (which is mostly bread)
I do use Instacart for grocery delivery (Chicago), but I really dislike grocery stores and willing to pay the premium (avg +30% in my exp) to avoid that trip. Honestly, If I was in the suburbs, with a vehicle, I might be better incentivized to personally make the trip.
All my own opinion though.
Or they have different priorities than you and value convenience over taste, price, and quality. There's even an entire industry built on this premise, "convenience stores."
When you are severely hungover and your fridge is empty, food delivery is godsend, even if it is fastfood (and proper food is just priceless).
Recent McD commercial in NZ even focused on this particular case -- zombie-like people who celebrated NY 2019 all night long are getting some food delivered to their door. Dont have link right now but you can google.
People love to talk about these services as if they're only for young, single, hipsters but a significant portion of their use come from people with some kind of life limitation (same as the Whole Foods peeled oranges in a plastic box that people love to make fun of. These are a godsend for people with poor motor skills).
I live in Taiwan, where Deliveroo gives you about $3.50 off your first order, and delivery is factored into the price. A friend of mine ordered a $6 pizza that she ate half of and brought the rest of to work the next day. All told, she paid $2.50 for two lunches, and didn't even have to leave the office.
That doesn't sound better than the alternative to you?
That's pretty bad!
You would need to speak Portuguese, and prove an effective tie to portugal, for example participating in Portuguese cultural activities, groups or organizations
Do humans really have such low morality and ethics? I just can't picture a person who does this to another human being...
I fail to see how the citizen in this case is harming the non-citizen.
Going as far as circumvent legal regulations and even pay to be able to do such a job is a good indicator that the person doing it is desperate for income.
Many people believe wealth should be shared, that everyone deserve happiness, and that no one should spend their lives slaving away just to survive, those same people would not try to profit off of someone desperate for income and willing to work hard and would consider what OP is talking about immoral.
It proposes a false dichotomy where the worker has to either be in well paying and fulfilling employment (which obviously is not an option given their circumstances) or alternatively, they must be saved from the tyranny of their employer (usually through enactment of regulations which will leave them jobless).
Either way all it achieves is to deprive the worker of income, experience and the agency that comes with being able to make their own employment decisions. Your comment, despite seeming conscientious, gives little consideration to utility of the worker and the pragmatic decisions they face.
A sense of moral outrage towards a company (or individual) for perceived exploitation of their employees might be justified, but is not sufficient grounds for limiting the freedom of exchange.
A former PM (Gordon Brown) was fined when it was found that his cleaner had used good forged papers.
Various modern slavery and gangmaster laws also come to mind.
There have been well documented cases of modern slavery where disadvantaged people like this have been abused and effectively turned into slaves.
Because it's a ridiculously naive statement at best. More likely just some sanctimonious BS you decided to post to signal how much of a good person you are.
Like seriously, what world do you live in where you can't picture a person doing something to take advantage of another person? Have you read literally anything in history?
Because it's a ridiculously smug statement at best. More likely just some sanctimonious BS you decided to post to signal how much of an intelligent person you are.
Like seriously, what world do you live in where you can't picture a person thinking that it's sad that a person takes advantage of another person? Have you read literally anything in history?
To me, as someone who worked in this industry before, this simply seems like a ploy by Deliveroo to escape absorbing the chargeback cost. Because, that is exactly what would happen if you called your credit card's bank/company and ask them to initiate a charge back for the fraudulent transactions instead of begging Deliveroo - the money will first be refunded to you almost immediately (varies from bank to bank) and then an investigation will be opened against the merchant in question (in this case, Deliveroo) and when you prove your credit card company valid proof that you're innocent by sharing logs, screenshots, etc. the dispute would be settled and the bank will side with you, the customer and thus this will lead to a loss on the merchant to bear the fraudulent transacted amount.
It seems, Deliveroo may be doing EXACTLY this to avoid letting the customer becoming eligible for a refund later through their banks by pushing them past the chargeback window. This is actually criminal in some countries, and grounds for a class action suit, which I hope someone sues them for if they are found guilty of this.
The other reason for the elongated resolution timelines is because Deliveroo actually benefits from these transactions - think about it, they earn for each transaction and in some markets, if I'm not wrong, the larger the transaction, the more they earn. So, why would they do something fast that affects their revenues negatively.
Anyway, my personal experience with Deliveroo also has never been positive and don't recommend them at all.
https://www.theguardian.com/business/2017/oct/28/deliveroo-d...
That's the thing. It isn't. Every franchise, big or small, has wildly different quality of ingredients and preparation (and even send the correct damn drink and remember the dip) among outlets, and if I order from that one, I want that one to prepare my food.
> You aren't led to believe the food is coming from somewhere it isn't.
I think we have different definitions of what being 'led to believe' is.
So yeah, I think it's shady and dishonest.
Sure, if a restaurant allows their brand to be used for such shenanigans they deserve all the bad press they may get.
Disclaimer: I use the Fat Duck as an example. I'm pretty sure they don't do home deliveries, let alone - Deliveroo.
That's not to say that their current response (or lack thereof) isn't bad, it's more that I'm not sure what would be a good response in this situation.
I'm also not sure how Deliveroo could be considered liable if the breach is on the user's side (phished password) rather than a server-side vulnerability. If I offer an online service and one user gets their password stolen, would I be liable for that? If so, what should I do if somebody claims that their account was stolen? What if they're actually lying to get access to a legit account?
The real story is that Deliveroo does not handle fraud properly. This is a much lesser crime than what they are being accused of.
The author wants to make it seem like Deliveroo has had a data leak and are trying to hide the fact. There is no evidence of this, but if it did turn out to be true then the author would be able to claim that they broke the story.
Deliveroo are responsible for the data you give them. If they fuck up and allow unauthorized people access to that data, they're in breech of the GDPR.
If they haven't informed ICO (and equivalent in any country within GDPR rules) within 72 hours of each breech, they're in even deeper shit. First, they have to be clear about the scale of the breech and what exactly has gone wrong. They've got to be able to demonstrate the steps they've taken to mitigate the issue and prevent it happening in future. If people are complaining on a regular basis for months, they've not done that.
However, I do agree that Deliveroo needs to do more to protect users against this. 2-factor authentication, email confirmation from a new IP, re-entry of card details when ordering to a new address are all simple ways to handle this. Deliveroo has not prioritised this because their main priority is growth.
"A personal data breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data."
The key part being "unauthorised disclosure of, or access to, personal data."
So does credential stuffing qualify - In my opinion yes, as it is unauthorised access to personal data.
They then go on to say "When a personal data breach has occurred, you need to establish the likelihood and severity of the resulting risk to people’s rights and freedoms. If it’s likely that there will be a risk then you must notify the ICO;"
And again, the ability to place orders and deliver them to a new address charging the existing credit card I think qualifies as a severe and likely risk.
https://ico.org.uk/for-organisations/guide-to-data-protectio...
Edited to add: In the absence of any legal precedent I’d challenge you to find any lawyer who’d confidently say that credential stuffing definitely doesn’t meet the criteria.
It will ultimately come down to a test case, but as I said before, you will be hard pressed to find a lawyer who would tell a company that they definitely won’t be liable.
But even so I struggle to think of a definition where accessing someone else’s account without their permission or authority wouldn’t be classed as unauthorised.
Permission or authority from who though?
If someone steals a key and unlocks a lock, is that considered "unauthorized access?" From the perspective of the person whose key was stolen, absolutely. From the perspective of the lock, no, the access was authorized.
We define terms in statutes and contracts for a damn good reason.
I would never but one of my two housemates was very confused why they couldn’t have my password so that they could look at the menu and each add their option to the order. (The third housemate was also a developer so he was surprised that I could remember it and I got sermoned about 1Pass over pizza.)
I also have heard of cases of close (female) friends who know each other’s password; when one had a health incident (miscarriage), the other took upon herself to order for the first one, to comfort her. She tried from her own account but failed (couldn’t remember the name of the restaurant), so connected to her grieving friend’s account, changed it to use her debit card. It was fully appreciated, but a surprise.
“Authorised” in that sense falls somewhere between:
- I know who those people are;
- we are part of the same household;
- I know that they can have access to my account;
- they made sure that I know they are on my account;
- I actively allowed them to be on my account right now;
- the device is shared.
- is it illegal to not have 2FA; I’m not against that, but it feels… excessive;
- every website, including small irrelevant ones, with a password (like HN) needs to crawl the darker internet to check for leaked lists of email/passwords; that would make those unsavoury forums crawl with solution vendors; it would also make it illegal to not find the most obscure ones; in other words, a non-option;
- ban the use of any password listed on https://haveibeenpwned.com/Passwords which feels more manageable, but… does the service offer an API?
Which one feels the most likely to happen in the short term?
"establish the likelihood and severity of the resulting risk to people’s rights and freedoms. If it’s likely that there will be a risk then you must notify the ICO;"
So if it's a small irrelevant website, there isn't likely to be a high or severe risk to that "breach", so they should be ok.
In terms of options, I think there are more, mostly around sites getting more sophisticated at defending against credential stuffing attacks - treat logins as more suspicious if they are from a new device, new ip, use a password that you know is in a breach list (have i been pwned), etc. and put in place a 2nd factor like email confirmation of the login even if they haven't turned on 2FA. Or at least restrict access to sensitive parts of your site if the login was suspicious until you can verify it was an authentic login.
To be clear, no website, depending on passwords alone, can know if an access was authorized by the person who is the subject of the account. Therefore, it would seem that the only sites that can use password-only authentication without risk are those that hold no personal information about their customers. According to your own interpretation of the law, some of your proposed mitigations would not be sufficient to eliminate the risk, if any personal information is held.
Look, I am not a laywer, and I am happy for someone to correct me here, but this is the wording of the law:
"A personal data breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data."
Is there anything in that sentence that means a successful credential stuffing attack would not fit the criteria?
Remember GDPR is specifically concerned with "A personal data breach" The original breach that led to the password being leaked was likely also a personal data breach (unless the only thing the hackers managed to access was the username/password database - and even then email address can constitute personal data in some cases), but there is definitely a personal data breach as a result of the credential stuffing attack (in the Deliveroo case, more than likely full home address, possibly other addresses too like work, possibly name, some level of credit card data, order history, etc.).
>> b) the credential stuffing attack itself is authorized access (because from the site's perspective, the user provided the correct username and password), not unauthorized access.
It's certainly authenticated access, but I think you'll struggle to convince a lawyer that it was authorised.
Well, the distionction can be as easy as someone hacking the company vs. guessing your password. What is the company to do to protect against the latter?! After all, the password is the authorisation, so I would even claim it's not unauthorised access...
> This is despite the company not asking customers to enter a Card Verification Value 2 (CVV2) code when making orders, a card security system designed to ensure that someone ordering something online has physical possession of the card used to pay for it.
More info on an article from November 2016: https://nakedsecurity.sophos.com/2016/11/25/fraudsters-eat-f...
BBC's Watchdog documentary: https://www.bbc.co.uk/programmes/articles/3ZMjkWFfDZQ8zFYQJL... (with response from Deliveroo)
So this Tech Journalist uses the same password on every site?
It seems to me like the corruption or fraud is within Deliveroo.
All of these services can give you a push notification every time a transaction is made on your account so that you are immediately made aware and are able to cancel them. You can block the card from within the app immediately.
1. http://join.monzo.com/r/vrlkxvo (Using this link gives us both £5)
2. https://www.tandem.co.uk/credit-card/
3. https://www.imaginecurve.com/ (Sign up with WAI91 and we both get £5)
Do any UK credit card companies offer consumer and fraud protection above the norm? Amex would immediately side with me if I showed them the Deliveroo communication. Another Citi VISA I had offered 18 months warranties on laptops and other electronics if I used the card.
Thanks for letting me know about Amex doing this. Might provide better customer service and many places do accept it.
I saw my mangers amex get declined when they tried to pay for a team meal (15 people) a few years ago
[1]https://www430.americanexpress.com/mrec/mersearch/index?intc...
Those rules mostly don't apply to Amex (they were not considered part of the Visa-MC duopoly).
There's some interesting background here: https://www.headforpoints.com/2018/02/08/american-express-eu...
Edit: apparently they stopped doing this for average cardholders 15 years ago and it's a corporate-card-only thing now called 'Amex Go'
I should note I have a "Starwood Preferred Guest" Amex card, but that is not a corporate card. It may be that the SPG card has additional features that a regular card would not.
I've been using Revolut for the past year. Just 2 weeks ago, they detected a potential fraudulent transaction with - you guess it - Deliveroo, for an amount of £25 (I don't live in the UK). The transaction, as well as my card, was immediately blocked. I then received a push message asking me to confirm whether the transaction was fraudulent - pushing "Confirm" triggered the expedition of a new card to my address. In contrast to legacy banks for which it is still recommended you call on the phone to notify you're going abroad, this is excellent service.
I don't use their app. If they suspect a fraudulent transaction, they block it and call me.
Yeah! Blame it on your customers! Way to go!
Sigh! Another gig economy service I'm damn sure never to use.
The catch is, you'd have to store the pairs together which then makes you a target, so in practice the best you can really do is what's on offer already -- check that the password hasn't been leaked (and maybe if the email address has a high HIBP leak count).
That solution would seem to force people into password managers and random high-entropy passwords or passphrases...
It's conceivable that the fraud is on the merchant side, with a restaurant faking a large order to an existing address, but in that case Deliveroo still has responsibility for allowing bad merchants into the system.
I must be missing something here.
"Address given is not registered as a restaurant or food outlet" (aka: they're not registered with the local council).
I've gotten into the habit of checking 'Scores, just because of the sheer number of poor quality food places on Deliveroo, Just Eat and so on.
If that's not the case you can't resell takeaway food, so no easy way to turn it into cash.
I've heard of people getting deliveries to the middle of the park in summer, or even to a boat waiting beside a road bridge...
We'd only deliver to an actual numbered street address or apartment.
1) People pay the fraudster for "discounted" food.
2) The fraudster places the order using the stolen account.
3) The fraudster tells the people who paid them: "Go to the pub car park at 9pm and wait for the Deliveroo driver. If he asks, your name is John Smith."
4) Profit.
it's also pretty hard to imagine it's worth the effort, you still need to advertise so people know about your service! the service would have suspiciously similar dishes advertised in menus corresponding to original restaurants etc... the unsuspecting customer gets to open the door for a Deliveroo person! there's just so many ways this would go wrong in the real world that it doesnt make sense to invest time and effort in MitM'ing Deliveroo from a limited set of compromised accounts...
This all indicates the fraud is happening from within Deliveroo
Why would they ever sell it at a loss? Everyone needs food, so they get the value by consuming it themselves.
This is how the market for stolen gas works anyway, I'd imagine stolen cola and beer would be similar.
What they may do is:
Order items that aren't as perishable such alcohol & ice cream (e.g. Ben & Jerries) and then resell those via partner off-license shops.
Not even that hard to investigate because there’s a complete paper trail after a fraud is reported of what was ordered, who delivered it, and where it was delivered.
That's how the cop would describe it of course. Anyone with half a brain knows they always throw the book but the whole book never sticks.
What sticks will probably wind up being some sort of fraud and the punishment will probably be something like fine and probation.
To me all this suggests the fraud is happening within Deliveroo, at a level above the delivery people.
The only credential fraud outside of Deliveroo I can envision is if the black hat hackers contact the restaurants to conspire, the food is then never made but the profit is shared...
Eat it.
When I was in college if the pizza guy was in the lobby (invariably trying to call someone who wasn't picking up their phone) very long it was customary to ask him what he was delivering and buy it if you wanted it.
However the article is unnecessarily sensationalist in banding around GDPR data breaches. Much of the article intimates there has been a Deliveroo data breach, whereas in fact the most likely explanation is attackers reusing passwords leaked from other breaches. This is acknowledged towards the end of the article but quickly glossed over.
If consumers are reusing exposed passwords this makes life tricky for Deliveroo. Maybe they should be using Troy Hunt's "Pwned passwords" to protect new user signups:
https://www.troyhunt.com/ive-just-launched-pwned-passwords-v...
https://deliveroo.engineering/2017/09/05/improving-password-...
"Therefore, from today, we will be informing our customers when we determine that the password which they use for Deliveroo is publicly known in some way. We will contact the impacted customers to request that they change their password, and advise that they also change that password at other sites where it is also used."
It sounds like their engineering time might be better spent on fraud detection algorithms.
Not surprising their whole business is like this.
I am a user of NoScript, AdBlockPlus (still using 2.9.1), with its "Element Hiding Helper for Adblock Plus".
My NoScript had already blocked 24 domains, which I guess I have added in the years before. I proceeded to block another 6-7. When the site reloaded, and was perfecly visible, the count was "Untrusted (13)". Which means the original 6-7 that I 'just' blocked were loading at least another 12.
And then companies are wondering why Noscript, uBlock, etc. are so popular and complain about when we care about our privacy!
Either the fraud is within Deliveroo (dig deeper!), or locating the served customer will result in the discovery of some kind of weird low-usage "stolen credential delivery of Deliveroo foods" service (dig deeper!)
This is not properly fleshed out IMHO... but yeah lets market and compare credit and debit cards and point systems and pffff
Does it not use credit cards? It should then be very easy to dispute the charge with the bank.
Then just make sure you both have access to the online account so you can both view the balance at any time. There's a small amount of extra friction in that you'll have to coordinate a bit to ensure the card is always paid off equitably, but it probably wouldn't be too big a hassle.
It's not so much for splitting the bill (I pay the most of what goes in there), but it makes putting it in our accounting system much easier :)
If deliveroo's own analysis is correct (and that is admittedly an 'if', but if you come out and say 'we hash our passwords, and you can quote me', let's assume they aren't complete morons in thinking that nobody on their staff would ever leak it if they didn't), then the problem is not that there has been a security breach over at deliveroo. The problem is merely that
[1] Their handling of a breach of account info that they weren't the cause of is very bad, both not investigating / blocking the recipients of the food orders (clearly 'whitewashing' fronts), or even trying to take it seriously,
and
[2] doing a bad job at enabling (or even motivating) their users to have good account security. Anywhere from scanning such credentials lists out in the wild and autoblocking any user/pass combo that is also a valid deliveroo login, to offering TOTP.
Both are, to be clear, very bad. Deliveroo deserves all the scorn they are getting. But neither of these issues is something you can be fined for, at least, not via GDPR.
On the topic of this story it seems like a case of credential stuffing so it's not a breach in Deliveroo's systems. Do the requirements as a "Data Controller" still apply in such as case? Regardless Deliveroo seems to be handling this poorly.
I don't believe Deliveroo is obligated to tell you who they send such information to. They are however obligated to tell you that they gather such information and, should they share it with a third party, ensure that said third party is GDPR compliant and sign a data processing agreement with them.
Deliveroo doesn't mention Braze directly by name in their privacy policy (https://deliveroo.co.uk/privacy), but they do let you know that they disclose "information they collect" to, among others, "Marketing and advertising partners".
They also mention in the same privacy policy that they "also collect technical information about your use of our services through a mobile device, for example, carrier, location data and performance data".
Braze themselves does appear committed to GDPR. That isn't especially surprising, it's a huge selling point for marketing companies towards enterprise customers. https://www.braze.com/product/data-agility-management/regula...
IANAL but I don't believe Deliveroo is in breach of GDPR. The best you can probably do is make a case that they do not have a reasonable justification to collect such highly-accurate location data for that particular use case, and should tone it down to, say, 5km instead of 1m accuracy. If you email dpo@deliveroo.com with such a request, there's a decent chance you could get the change done.
> As we wrote before consent is one of the six conditions for the lawfulness of processing personal data as stipulated in Article 6 of the GDPR text.
> Again, there are other conditions for the lawfulness of processing personal data.
If you're referring to the bit about "special categories of data" per Article 9, location is not such a category.
That said, location data is sensitive, so there certainly are questions that can be asked about how and why they use this data. You can ask them for details.
To add to what detaro was saying; even if explicit consent were required for sharing your location data, Deliveroo most likely got it; they after all need it to know where your order is going to go. When such functionality is core to the app, an opt-out is not necessary.
What they might not have gotten, or at least not clearly, is your consent to send that data to a third party, explicitly and exclusively for marketing purposes. I don't know how this would play out.
Realistically, GDPR and its enforcers err on the side of caution (you need good justification to gather the data and share it, including consent and a reason to gather it in the first place). So if you care about this and wish to see it corrected, as I said an email to their dpo@ will likely go a long way. In case it doesn't, your national enforcement agency may be interested. Extremely-accurate location data is pretty creepy, especially if they get it very often and doubly so if they store it for a long time.
The #1 thing I would look at here is what they actually need it for. They may need it for security reasons (eg. anti-fraud measures) and happen to be storing it in Braze which is probably okay if Braze respects GDPR and Deliveroo signed a DPA with them (you'd be surprised the amount of companies storing security data in GA).
But you wouldn't have a very hard time making a case that they're using this for marketing purposes and are gathering an unreasonable amount of accuracy. So now the question is, do you care about this enough to follow up on it? :)
Per GDPR[0] consent must be specific. i.e. aquiring constent for a legitimate feature of an app and then also using the data for marketing purposes, what seems to be happening here, is not legal. Of course it could be the case that Deliveroo uses Braze for all their push notifications and thus consider it an essential part of their product. IANAL, but as I read the GDPR giving an app location access required for legitimate functionallity is not a carte blanche for the app to use location data for any purpose without obtaining consent for each specific usage.
In any case, like you say it's extremely creepy and the level of accuracy is worrying.
I've seen this pattern quite often: The opt in/out flag is stored somewhere and companies invalidate the data they have based on that in the marketing tooling itself; collection still happens regardless. I've not used it but it's even possible Braze has information on the optin/optout and the ability to immediately reject data about optouts.
The reality is that, while the clean and intuitive privacy practices we're talking about are compliant, they're not required for compliance. Companies go the least-effort route. Deliveroo has clearly done a GDPR pass on their practices so I highly doubt they're using the data in question for marketing (even if they're collecting it).
But I'm still encouraging you to go and talk to them about it. I promise you if you're polite and clear about what and where the issue is, you can likely get some changes done. It's pretty fulfilling, too :)
Sounds like an issue to me.
https://gdpr-info.eu/art-6-gdpr/
Specifically, section 1 (b) and all of section 4. Deliveroo clearly needs location data; that they happen to be sending it to Braze is fine if they signed a DPA. So the question is, is the data sent to Braze exclusively for marketing? More critically: If it is collected regardless of consent, does processing still follow consent? (Collecting and processing of data are two different things)
As I said there's probably a good case to be made that the data sent is too accurate.
I'll note that I'm a bit cynical here since these are fairly minor issues compared to the much more egregious shit GDPR sets out to fix. There's definitely a potential cleanup there, but like, every single company has nasties like these hiding under the carpet. The regulation itself doesn't help these cases much unless people act on them and demand the cleanup.
I'm not sure you're actually disagreeing with me. See -
> Actually, under the GDPR, they must gain permission to process your information for any marketing purposes.
> Although what Spotify has done, or failed to do, by handing over data to whoever is logged in on an account, could be considered irresponsible, it is in no way illegal – and, in all likelihood, is generally the norm.
The author's experience is not uncommon and seems sensationalised to create a Twitter storm and garnering sympathy, which is uncharacteristic for a journo, who writes about 'tech and digital culture'. It would have been more apt to go into triage mode i.e. stop the bleed of finances and dispute transactions immediately, before entering into communications with the delivery firm. After a resolution, choose to go turbo and further explore the implications of GDPR, then write about your experience in detail.
The article does not leave the reader any more informed or equipped to deal with such a fraud. It does not even pretend to offer any piecemeal advice e.g. don't use/re-use easily guessed passwords, use 2FA, use credit cards or virtual/disposable cards, contact your bank/issuer first, don't bother contacting low-level support via social media, explore data protection laws after a resolution etc.
Even if it does exit -- EU will have incredible influence over the UK and can effectively enforce GDPR on most companies over a certain size as those companies will have to create entities and corporate structers in the EU for varying reasons -- mostly tax minimisation for exporting.
Little sole traders with no amibition of expanding outside the UK will probably have the benefit of not having it enforceable on them.
Again this presumes the UK chooses not to implement it's own data protection laws.
full article for whose whom want to read it but not be tracked:
Deliveroo users are getting defrauded – and it could be fined millions for it
Scammers are using the delivery service to clear out bank accounts, and the company’s response may be in breach of GDPR regulations. By Sarah Manavis Follow @@sarahmanavis Getty Images
On Friday morning, I woke up late, rushed to the tube, tapped in with Apple Pay, only to discover a few minutes later that my payment had been declined because I had insufficient funds. Figuring, “Well, it’s January”, I went to check my bank balance.
But rather than seeing an overspend or a direct debit I’d forgotten about, I saw three enormous charges from the food delivery service Deliveroo from the night before. They weren’t mine.
I immediately called Deliveroo to say that it wasn’t, in fact, me who ordered £100 worth of food in the space of ten minutes in three separate orders; and told them that the fraudsters had changed my email address, so I couldn’t even get into my account to look at where it was sent. I was told that they would investigate, and I would be sent an email asking for more information immediately.
I was not. After an hour, I rang again, to find that actually the email had been sent to the new email address – the one the fraudsters plugged in – so that they had presumably been alerted to the investigation. I complained, got the email re-sent to me, and was then met by radio silence for the rest of the day. When I eventually rang again, the company said it couldn’t actually tell me whether or not I would get my money back, adding that I might not hear from them for nearly a week before they let me know either way.
By 5pm, I was getting fed up, so I did what any journalist with a modest Twitter following would do, and tweeted. What I thought would happen was that my case would be bumped on the list, and maybe I’d get my money back sooner (or, indeed, at all). What actually happened was that my replies, DMs and email were all immediately flooded with people who had been a victim of the same fraud, saying, yes, this had happened to them too and no, Deliveroo had never refunded them. Of the roughly 40 people I spoke to, not a single one had been refunded by the delivery service; those who did get their money back had got it from their bank. The people tweeting the account claimed to have experienced fraud ranging from the low hundreds of pounds, like my case, to, in some cases, thousands. One person tweeted me to say that a friend of his was fraudulently charged £3,500 on his account. “Deliveroo offered him a £40 credit as a gesture.”
More shockingly, nearly half of these people told me that their cases were still technically “under investigation” by Deliveroo, some for over two months. Most of those who had been waiting for more than a week to hear about their case told me Deliveroo had simply stopped responding to their calls.
This problem is not actually new. In 2016, the Telegraph ran an expose of rampant fraud on the food-delivery service, and reported on customers’ shock at Deliveroo’s poor handling of the situation. The same day, a BBC Watchdog programme did a feature on Deliveroo fraud, in which Deliveroo claimed that “instances of fraud on our system are rare”.
But dating back several years, Deliveroo’s customer service Twitter account, @DeliverooHelp, has responded to claims of fraud nearly every day – often, in recent months, multiple times a day. They may represent only a small percentage of Deliveroo’s wider customer base, but it’s not at all obvious this is “rare”.
However, help for customers – and fines for the delivery service – could be coming from Brussels. Laura Irvine, a regulatory lawyer and Partner at Davidson Chalmers, tells me that Deliveroo may have breached the GDPR regulations introduced last year on multiple counts.
The General Data Protection Regulation (GDPR), which became European law on 25 May 2018, made sweeping changes to data protection rules across the EU: now, companies are more liable for protecting the data they hold on customers than ever before.
Irvine tells me that Deliveroo appears to have breached these regulations three times over. The sixth principle of Article 5, for example, requires companies to have “appropriate security in place to keep your financial and other personal data secure”, she notes. The firm also appears to have breached Article 32, “which provides more detail about what is expected in terms of data security – namely encryption, which appears not to have been in place”.
Lastly, there’s Article 34, which requires the “data controller” – that’s Deliveroo – to tell “anyone who may be affected by a data breach about it without undue delay. This applies when the breach is likely to result in a high risk of an impact on the individual. Getting your bank account emptied would, I suggest, meet that threshold.”
So what fines could Deliveroo face, if it were to be found guilty of these data breaches? “It could be millions of pounds,” Irvine says.
She emphasised that this is a big “could” – the millions of pounds they could be fined would be the upper end of the spectrum. But it is entirely possible, especially given the criticism the Information Commissioner’s Office (ICO) has faced for the small size of its fines in the past. “They were criticised for the small fine imposed on Facebook – £500,000 which was the maximum under the old law,” she tells me. “So I think they will want to use their powers. And they need to keep up with the other regulators,” she adds, noting that Google recently faced a €50m fine in France for breaching GDPR.
That said, there are some things that could spare Deliveroo from this fate: if, say, Deliveroo had told the ICO about the data breach within 72 hours, the threshold for fines would be lowered. But, Irvine says, the high volume of incidents and the reported response from Deliveroo suggest they aren’t informing the ICO of their data protection problems.
“They may blame other parties, but at the end of the day if you give them your data then they remain responsible – in most cases,” she says. “I am not sure how the bank would stop this.”
I put all this to Deliveroo. A spokesperson told me: “Deliveroo takes online security very seriously. Sadly fraudsters rely on the fact that people reuse the same passwords on multiple online services to try and gain entry to different accounts across the web.”
Ultimately, though, fines are not the only problems that data leaks of this sort pose to firms like Deliveroo. “Soon people will stop using companies based on how responsible they are with data,” she says. “Particularly financial data – but even your address being out there can be uncomfortable or dangerous for some people.” If she’s right, then this, for Deliveroo, could be just the beginning.
Midway through writing this story, I got my money back, by the way – and from Deliveroo itself. Other victims have not been so lucky.
The journalist and the 40+ People were victims of a credential stuffing attack which means they used the same password on multiple sites.
Had they used a password manager to roll a new password per site and had deliveroo had proper rate limiting, this attack would have been mostly mitigated.
There’s not much excuse for this behavior.
This article only exists because the Journalist was affected. If anyone would contact the this paper saying company X has fraudsters leveraging their service (which is not uncommon), this article would never have been written.
That aside, I've been on the other side, resolving cases like this. Sometimes cases are complex, take months to figure out while involving multiple stakeholders (police, banks, payment processors, etc), and you have no idea who to trust on the other side of a phone line (it can be a victim, it can be the fraudster).
> If anyone would contact the this paper saying company X has fraudsters leveraging their service (which is not uncommon), this article would never have been written.
You don't know that. The New Statesman is an excellent magazine and has run plenty of investigations in its time.
If the article would be about the growing problem of online fraud (which is growing quite steadily), and not only about Delivaroo, I would be happy.
Yes, I do know that, because as I said I've been on the other side and the number of articles covering individual companies being targeted by fraudsters is low compared with the number of cases.
Regardless of the motives that sparked the article, it still brings attention to the topic, which is positive.