Credit cards automatically providing updated card info to subscribing merchants
cbc.ca
cbc.ca
About a month ago I was reviewing my statement and noticed I was being billed by Spotify twice each month. I contacted Spotify to ask why they were billing me twice, and they asked for my account info and indicated my account was only being billed once. They then asked for the first 6 and last four of my car number to search that way, and again indicated I was only being billed once.
I sent them a screenshot of my online account statement at which point they agreed they were billing me twice but could not find the origin of the duplicate charge.
Finally it dawned on me - my bank had sent me a new card a long while back because of a suspected compromise. I’d had that card for a long time, and had the number memorized. I gave the old card number to them and bam - they found the source of the fraudulent transactions.
This means that even though my card number was compromised and cancelled, it can still be used for payment at any merchant for which I’ve had an ongoing subscription. Since these are merchants I do business with, it makes it doubly hard to notice the fraudulent charges as seeing “Spotify” or “Netflix” or whatever does not raise my eyebrow. Only in a careful month by month review did I pick up on the fraudulent transactions.
As a side note Spotify was very quick to reverse the duplicates and appear to have blocked that old card number from being used in their system again. Although a frustrating experience overall, they were very good to work with.
Now with this organization, you can donate via the website but to cancel a recurring donation requires a phone call. I called a couple of times to try to cancel but didn't reach anybody. I admit- I wasn't too concerned (a good organization overall), but I was a little pissed nevertheless.
My credit card was skimmed, and I had it cut off. I figured this would solve my problem with the donations as well. Nope.
About two years later my wife (who actually handles the bills in the family) asked me if I wanted to continue those payments. I was pretty shocked- and persisted with the phone calls until I reached somebody to cancel.
Surprise!
I consider the "signing up can be done on the web, but canceling requires a human" to be a dark pattern.
And illegal in California as of last year. Hopefully them forcing companies to allow online cancellations will mean it's available for the rest of us too.
https://www.cnet.com/news/companies-must-let-customers-cance...
My ex-employer was surprised that when they were obliged by law to stop routing everybody though a retention call center customer satisfaction improved. Too much of their own Kool Aid had been drunk, they'd persuaded themselves that customers wanted to be reminded of the benefits and offered other deals by a human so much that they'd hate even having the option to just press "Cancel" on the web site and leave that way.
It's an old Joel Spoelsky lesson, if you make leaving a pleasant experience that customer may come back some day. If not you're never going to see them again.
I've just decided to let the customer pre-pay for up to the limit I'm willing to guarantee that I'll keep running the service, even at a loss (two years at the moment). I figure if the service isn't worth a user's time to click once to re-subscribe every few years, then I probably shouldn't be taking their money.
I admit this might be a bit naive from a business perspective :)
The first is used for re-occuring bills (Netflix, Phone, internet etc).
The second is for everyday spending (Amazon, groceries, sundries etc). The second has an extremely low threshhold for alerts and emails about pretty much every transaction.
If something were to set itself to autopay, I'd notice very quickly since card 1 pings me, and card 2 only should have <10 merchants per month for easy auditing.
(Paying in cash for entertainment expenses also makes auditing easier. Having every cup of coffee or burrito clogging your statement makes it hard to spot double charges and other small frauds)
The existence of this pattern is the sole reason why I'm using PayPal.
Sometimes customers do get confused by the automatic update mechanisms for card details, but most of the time it seems to be a useful facility that saves hassle for our subscribers and avoids unintended cancellations. I do think the card companies should be much more transparent with both cardholders and merchants about how their systems actually work, though. We've had occasions where something unexpected has happened, a customer has contacted us to ask what is going on, and all we could do was contact our card payment service to ask them because we had no idea either.
In an ideal world, perhaps we would verify exactly who each customer is for legal purposes, but in reality there's no good way to do that, so we accept a fraud risk that is small in practice in return for streamlining the process for both ourselves and our customers. There are systems that will shift that liability if you go through additional authorisation checks at purchase time (and in Europe, use of these systems will become mandatory in most cases later this year) but it is not clear that these are actually helpful, in that they may do more harm than good.
As for having a law against anything, I don't see how this is much different to when I buy my shopping from a grocery store and all I need to provide for payment is my card and PIN (and not even the PIN for most low-value transactions these days). Or of course I can pay completely anonymously using cash.
Isn't a user required to enter their name and address information for you to be able to charge the card? Doesn't that have to match the card?
> I don't see how this is much different to when I buy my shopping from a grocery store and all I need to provide for payment is my card and PIN (and not even the PIN for most low-value transactions these days).
Your card provides name and address information. PIN provides "security" (for some definitions of security...).
> Or of course I can pay completely anonymously using cash.
If a user is somehow paying for services with cash online... doesn't that rather necessitate that they can't enroll in automatic billing? So, how does that have anything to do with the topic at hand: automatically billing against cards which are no longer valid.
No and no.
There is a certain amount of basic checking of some parts of an address that can optionally be done. It's nothing like as comprehensive as you seem to be expecting, though.
Your card provides name and address information.
Not necessarily, at least not that the merchant can see in full. Again, just because the card issuer has such information, that doesn't mean the merchant necessarily does.
If a user is somehow paying for services with cash online... doesn't that rather necessitate that they can't enroll in automatic billing? So, how does that have anything to do with the topic at hand: automatically billing against cards which are no longer valid.
The point was that you don't necessarily have to know someone's identity definitively to trade with them lawfully.
I think it's in the merchants' interest to proceed with lackluster sanity checks, knowing that some erroneous charges will make it through. It's got to be a multimillion dollar business collecting fees from the unaware, the scammed, and the dead.
Canceling my dad's cable service was peculiarly cathartic. They wanted to talk to him, not me: "he's dead." They stumbled over points in the script where they're supposed to flip the cancellation into a bigger subscription: "no, he's still dead." They awkwardly prodded about survivors: "none of your business; if anybody wants your service they don't want it under the name of a dead man, will you cancel the service now?" This would have been quite painful if I didn't get so much glee from saying "no" to salespeople...
They most likely don’t store your actual card number.
i'm in fantasy land, right?
Now that's currently only online, but they're releasing a point of sale product soon too. But even with that, you connect to their card reader and receive a token that you can use.
In fact Stripe and Braintree (and I'm sure others) have systems where the implementing service doesn't get the credit card number at all- the payment information is sent directly to the processor from the client and the implementing service only gets a vault token.
I think the scam must rake in huge sums of money, given that it could slip by for months unnoticed.
EDIT: Amazon confirmed my card was never used to purchase Prime for me or anybody else. The scammers were just charging my card $17, and hiding the charge under the name 'Prime Subscription'.
They were probably just trying to confirm the card is active. Stuff like gas stations and vending machines can set off alerts since they're common vectors. (Ex: my issuer called me immediately after I first got a card and bought gas for it, because someone who previously didn't buy gas doing so in an area far from home was a common fraud pattern)
If the small charge works they can try bigger items.
This can create unforseen problems that aren't fraud related as well.
For example, I had to replace my iPhone at one point, and update my 2FA codes. (Even if you back up your iPhone reguarly, 2FA codes in Google Authenticator are not backed up)
Unfortunately, I'd lost my recovery code for one service provider. They wanted the last 4 of my CC a one of the points of data in their verification process.
Then told me it was incorrect.
Luckily, the CC issuer (who sadly, for security reasons I'd rather not name) had some excellent customer service.
They realized that they had been billing the previous card number since it was a known re-occurring payment, and were able to work with me to retrieve the last four digits of the old card number via an old statement, enabling access to my account.
I've since moved over all my reoccuring payments to that issuer. (And made a document outlining which merchants have which cards on autopay so I can update them when cards are re-issued + backed up my 2FA recovery codes in a secure, offsite, physical location)
This is why cards like The Apple Card, which allows you to generate cards on the fly, is better for consumers. Just generate a card for LA Fitness and delete it when you close your account. This would eliminate a big chunk of fraud (including the shady shit LA fitness does) when your card details are sitting in many databases (some of which are not encrypted in anyway).
I’m not saying Apple card is great, just that feature of it.
Note that with the Apple Card, while you can regenerate the number, it shouldn't be used in the same way as Privacy/other virtual card services. See this TC article[0]:
> Card numbers are manually regenerated only, and do not automatically rotate. There is, currently, no single-use number support or single-merchant number support.
Also, it is very likely the "regenerate" function will send your new card to Visa/Mastercard's card updater service.
Consumers have routinely ignored this feature. Like so many security things, it's just not sexy enough for them to care and take on the hassle of older clunky solutions. The rise of digital payments and the movement away from a plastic card is making this much easier on people, by embedding the virtualization in the flow automatically instead of making users take steps to generate and manage.
But those who cared could always do this. It's just that so few cared.
I would never trust them to handle anything more complex like virtual card numbers.
Glad that its a bigger thing than beyond Apple, so I'm wondering if it is a case of it being a customer ignored feature, or case of it and it's virtues being bestowed upon the customer. I can't say how customer relations and usage of such features and how the customer is informed in America. I am aware though that credit card usage in America is more prevalent than the UK. Least that was the case years ago, may of changed. Certainly debit cards are more utilised in the UK and may of become more common in America.
Though it does make a credit card more palatable for me again, so thank you for making me aware of this, shame all those credit card spam and junk mail offerings never mention such a feature, but I'll shall enquire.
Capital One has a browser plugin called "Eno" that allows one to do something very similar to what you're saying.
Good luck winning that in small claims.
Issuers (banks) have to provide the details of these new cards to Visa/Mastercard, and the systems are certainly capable of updating the details of debit cards. It sounds like TD had a bug where they sent updates for cards which they shouldn't have. ie: TD broke their own rule about only enrolling credit cards.
Card details which do not automatically update are really frustrating for customers – especially on services like Uber. In nearly all cases the customer is going to go and give the merchant their new card details anyway. My understanding is that if card is compromised (as opposed to being lost) then banks should not provide the new details. There isn't really much _additional_ privacy or security risk here beyond those posed by merchants/acquirers holding onto card details already – provided banks do it right.
Though zooming out a little, long-lived payment tokens shared among every merchant a user shops with being the way things are still done is crazy. How long it has took to roll out EMV (chip cards), especially in the US, shows how hard it is to effect change in vast, three+ sided marketplaces like card networks.
[1] https://developer.visa.com/capabilities/vau
[2] https://developer.mastercard.com/product/automatic-billing-u...
Disclosure: I work for a bank.
You could end up with the subscription not ending but just accruing as a debt, which the vendor could then sell on to a debt collector at a later point.
If you just let a card expire you’re generally relying on the good will of the vendor to treat it as a cancellation.
- Unsubscribing was phone only - Limited operating hours - Long telephone queues
And then they told me they would have to charge the next three months subscription, and that there was no technical way to remove me early.
Surprisingly, when I cancelled the card and they didn’t get the money my account managed to get turned off somehow!
Of course issuing banks may even approve charges on a closed account too. In other words, relying on the bank to end payments has all kinds of failure modes.
Just because the charge was declined when you were billed doesn’t mean you don’t owe the money.
I'm not advocating against choice of automatic updates... but shouldn't you come up with a different way to kill off subscriptions you don't care about? My VISA doesn't expire till 2023
For gyms, it's pretty well known you either don't agree to said contract to begin with, or suck it up and show up in person if you did.
And gyms have a valid contract and will likely continue accruing debt on your account which they could pursue if they wanted to.
This is not ideal which is why whenever I can I setup autopay through my bank's website.
What!?
I have been shopping online all over the place since the time Amazon was only a bookstore (read: decades ago) and this has never happened to me once.
Are you sure nothing is wrong with your bank? Do you use your credit card in shady places?
https://www.nbcnews.com/business/business-news/target-settle...
Or Adobe
https://krebsonsecurity.com/2013/10/adobe-to-announce-source...
Or British Airways
https://www.theguardian.com/business/2018/sep/07/ba-british-...
Credit card details get leaked or compromised all of the time and are a dime a dozen on the dark web.
https://www.amazon.com/gp/help/customer/display.html?nodeId=...
There are lots of ways to make this better, but it exists because the consumer complaints when banks didn't do this outweighed the few who wish to have payment vehicles actually expire.
Banks could do a better job of listing the recurring billers, companies could do a better job of making it easier for you to update payment info (en masse), and networks could stop hiding behind issuers and big TV ads and provide direct-to-consumer controls even for banks that don't choose to offer them.
Disclosure: at the time of this comment, I work for a bank.
Although, I’d love to see a show of hands from anyone IT related that hasn’t witnessed an outage caused by an expired card/billing account issue. Oh the SSL certs, exchange servers, SaaS apps, domains, etc I’ve seen go up in flames temporarily because of billing issues over the years.
You are the bank's customer. They don't need to protect the ability of vendors to bill you. I've had this argument before. "If canceling this subscription/ability to bill causes a dispute or debt or contract issue with the vendor, that's on me. I don't need you being 'helpful', or worse, _refusing_ to remove unauthorized transactions."
To me this makes perfect sense to be Opt Out. I would hazard a guess that 90% or more of consumers absolutely want their merchants to all keep going as expected when they for example lose their credit card on a trip and call to get a new one sent to them.
Keep in mind that the average consumer (at least in my observation) saves ALL of their credit card information for easier purchases in the future, a practice that probably has a much smaller overlap with the traditional HN crowd.
"After initially telling Go Public it got Acuña's information from the "account update services," PayPal backtracked a few days later, saying the account updater service "doesn't apply" in Acuña's case.
So, how did PayPal get her new expiry date? It won't say, citing customer confidentiality — even though Acuña agreed to waive confidentiality to allow the company to answer Go Public's questions."
I do also recall there was a problem when 3D Secure / Verified by Visa was involved - IIRC while the Continuous Authority transaction type allowed an indefinite length of reuse, 3D Secure / VByV only allowed up to 90 days (may have changed or may be a detail of the spec I'm forgetting).
The point is, don't assume cancelling your card will result in cancelling of any recurring debits or allow you to get out of a contract. You have to cancel them with the merchant to make sure they don't continue to charge your new card.
By having Amex between me and a whole host of recurring-billing vendors, I have a kind of firewall. Amex is on my side reflexively if there's some kind of disagreement or dispute, and will reverse the charge.
If it were my debit card in play, or bank-to-bank transfer, the money would actually be GONE until I was able to convince the merchant, or the merchant's bank, to give it back.
But this is a double-edged sword. There is always a cost to this kind of scheme, and one way or another it is always going to be passed on to the customer. There is also an inherent risk in this kind of scheme, in that some quasi-judicial process is making decisions about who gets to keep the money in the event of a dispute, and if it goes the wrong way in one party's view then the result is either losing out on money they think belongs to them or taking more expensive action to recover it, possibly via the courts.
Ultimately I think everyone has to learn to be more responsible about these transactions. Of course it shouldn't be possible for a merchant to take money from a customer without authorisation, but equally it shouldn't be possible for a customer to arbitrarily reverse a payment several months later even if the merchant has done nothing wrong, or to cancel the payment authorisation as some sort of informal proxy for cancelling a legal contract with a merchant.
Aside from the excessive time periods for challenging payments retrospectively, I think the direct debit schemes tend to be better at this sort of thing than the card schemes. Typically, you have a specific payment authorisation (which can be cancelled from the customer's side) and you also have a requirement to give advance notice of recurring payments so there is time for the customer to act if they don't agree with them for any reason.
>But this is a double-edged sword.
No, it's really not.
Yes, I pay Amex an annual fee for the level of card I carry. I've done the math, and I get a good value back for this fee -- especially given the level of customer service AX provides. Paying for a service does not make this a double-edged sword; there's no downside for me here.
>There is also an inherent risk in this kind of scheme, in that some quasi-judicial process is making decisions about who gets to keep the money in the event of a dispute, and if it goes the wrong way in one party's view then the result is either losing out on money they think belongs to them or taking more expensive action to recover it, possibly via the courts.
This is true in literally any transaction, at some level. I mean, even in a cash-on-the-barrelhead scenario there's the possibility of bad faith or swindles, so I have no idea what your point is.
>Ultimately I think everyone has to learn to be more responsible about these transactions.
This is one of those things that sounds true and wise, but is actually just noise.
>Of course it shouldn't be possible for a merchant to take money from a customer without authorisation,
It will perhaps surprise you that it ISN'T, and that the disputes in discussion are generally over overbilling or billing after permission has been revoked.
>but equally it shouldn't be possible for a customer to arbitrarily reverse a payment several months later even if the merchant has done nothing wrong, or to cancel the payment authorisation as some sort of informal proxy for cancelling a legal contract with a merchant.
Truly, the merchants are fortunate to have such a wise defender in Silhouette!
>I think the direct debit schemes tend to be better at this sort of thing than the card schemes.
You have not even APPROACHED explaining why you think this, or why anyone should agree with you.
As long as there are automated billing systems, there will be errors.
In the scenario I outline, Amex functions as an intermediary, so a screwup doesn't literally take money from my account. This is objectively preferable to your scenario, where that's precisely what would happen.
There are direct debit schemes that are widely used.
Fast-forward a year after that t-shirt campaign and now I'm seeing a charge for the shirt. Um ... no? I call the bank and they immediately reverse the charge. But oddly (I thought at the moment) the agent on the phone mentions how they'll let previously used merchants continue to charge on the old number.
I contacted support for the t-shirt folks, and they acknowledged that they'd re-initiated the campaign, found they had enough takers, charged folks, printed shirts and were sending them out. I asked about email notification. Oh, yes, of course they sent email notifications. The date on the email I finally received (four days later) was dated two days after the charge appeared.
I still received a t-shirt and the charge didn't reappear.
They really nailed the UX of generating and managing virtual CC numbers per use case.
It's nice after a stolen card number to know recurring charges will continue automatically.
https://community.monzo.com/t/monzo-labs-share-card-replacem...
There should be a way to lock a card completely, in a way that prevents ongoing charges.
Bad security theater and lack of understanding of computer security. I'm sure there's a PCI reason in there as well.
https://www.paypal.com/uk/smarthelp/article/how-do-i-change-...
and their T&c's say: "3.1 Linking your Funding Source. You can link or unlink a debit card, a credit card, a pre-paid card (in certain cases), a bank account and/or PayPal Credit as a Funding Source for your Account. Please keep your Funding Source information current (i.e. credit card number and expiration date). If this information changes, we may update it at our sole discretion without any action on your part, according to information provided by your bank or card issuer and third parties (including but not limited to our financial services partners and the card networks). If you do not want us to update your Funding Source information, you may contact your bank or card issuer to request this or remove the Funding Source in your Account Profile. If we update your Funding Source information, we may retain any preference setting attached to it.
You may choose to confirm your card or bank account, so that we can verify that the card or bank account is valid and that you are its owner. We may allow you to do this by following the Link and Confirm Card process (for cards) or the Bank Confirmation process (for bank accounts) or other processes which we may notify to you or which we may publish from time to time."
https://www.paypal.com/uk/webapps/mpp/ua/useragreement-full
Intersetingly, it says "If you do not want us to update your Funding Source information, you may contact your bank or card issuer to request this" so I assume you can ask the bank to not share updated details with anyone.
Seems there is also an API that banks could use to let customers know which retailers received the updated details - that would be nice, would also help to see wwhat services that are no longer used still have card details on file.
https://developer.visa.com/use-cases/identify-merchants-rece...
I wonder if this is something that Stripe et all would ever implement on their side, so that it could be an opt-out per service - ie they just ignore the update for a particular card and service implementation?
Your personal information is so valuable that some governments fiercely protect it, it's why the GDPR is popular in the area it covers.