(For people outside the US, both Target and later Home Depot got hacked. Many banks proactively replaced their customer cards if they had transactions at those stores, which meant new numbers, expiry and CVC even if no fraud occurred on the card.)
(For people outside the US, both Target and later Home Depot got hacked. Many banks proactively replaced their customer cards if they had transactions at those stores, which meant new numbers, expiry and CVC even if no fraud occurred on the card.)
At least with my banks, when they send me updated cards, only a handful of the digits actually change and most of those changes have tended to be in the last 4 digits — which Stripe lets you see, along with the updated expiry month/year.
At this point, it's just a matter of brute forcing the remaining permutations. Am I misunderstanding something or are there countermeasures to protect against such attacks?
However I have never had a vendor try to rebill an expired card, even though the CVC's and the expiration year are the only data which changed.
We spent a couple of puzzled hours wondering how in the world Google could have possibly gotten that information before concluding that it must have been a service made available to them by the issuing bank -- Navy Federal in our case -- but not having any real way to confirm it.
We'd scoured the paperwork that we did have and found nothing indicating those terms anywhere, and shockingly, this is our first indication that such a service exists.
Note, I did not call the bank.