# How did my cc get hacked?

**URL:** https://boards.straightdope.com/t/how-did-my-cc-get-hacked/839048
**Category:** In My Humble Opinion
**Created:** [August 22, 2019, 12:26pm UTC](https://boards.straightdope.com/t/how-did-my-cc-get-hacked/839048 "2019-08-22T12:26:59Z")
**Posts on this page:** 20
**Page:** 1

<div class="post-metadata">

### Author: ![kambuckta](https://avatars.discourse-cdn.com/v4/letter/k/53a042/32.png) [@kambuckta](https://boards.straightdope.com/u/kambuckta)
#### Post date: [August 22, 2019, 12:26pm UTC](https://boards.straightdope.com/t/how-did-my-cc-get-hacked/839048/1 "2019-08-22T12:26:59Z")

</div>

Ok, I’m on holidays in Vietnam at the moment, since 10/08. On 15/08 and the 19/08, somebody used my credit card for transactions totalling nearly $1500AUD, apparently as POS stuff at an electronics shop in Singapore. I haven’t been to Singapore.

Also, I haven’t used my card at all for about a month. It’s in one of those protective cases that are meant to be ‘skim proof’, so should be immune to randoms walking past me and getting the card number.

The only time my card details have been shared was to book hotels on [booking.com](http://booking.com). Is it likely that some arsehole there is compromising credit cards and hoping people don’t notice??

---

<div class="post-metadata">

### Author: ![Czarcasm](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/czarcasm/32/4050_2.png) [@Czarcasm](https://boards.straightdope.com/u/Czarcasm)
#### Post date: [August 22, 2019, 12:41pm UTC](https://boards.straightdope.com/t/how-did-my-cc-get-hacked/839048/2 "2019-08-22T12:41:29Z")

</div>

You not only gave your credit card number to booking dot com-you also gave it to all the hotels they passed that number to.

---

<div class="post-metadata">

### Author: ![Shodan](https://avatars.discourse-cdn.com/v4/letter/s/9f8e36/32.png) [@Shodan](https://boards.straightdope.com/u/Shodan)
#### Post date: [August 22, 2019, 12:46pm UTC](https://boards.straightdope.com/t/how-did-my-cc-get-hacked/839048/3 "2019-08-22T12:46:25Z")

</div>

Same thing happened to me, and I don’t know how. Somehow somebody got our CC #s and charged $100 to some cosmetics company (supposedly) and another company I don’t recognize.

The credit card company caught both immediately and refused to pay, and then called us. Unfortunately, I get so many effing robocalls that I blew off the message they left on my answering machine. The Lovely and Talented Mrs. **Shodan** , however, called the customer service number listed on the credit card (NOT the number left on our answering machine), and sure enough, confirmed the bogus charges. They cancelled the card and sent out new ones.

But I cannot figure out how we got hacked. I buy cigars online, fill the car with gas, and do my SDMB subscription via Paypal, but not much else.

Total charged was about $250. Go figure.

Regards,  
Shodan

---

<div class="post-metadata">

### Author: ![Czarcasm](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/czarcasm/32/4050_2.png) [@Czarcasm](https://boards.straightdope.com/u/Czarcasm)
#### Post date: [August 22, 2019, 12:52pm UTC](https://boards.straightdope.com/t/how-did-my-cc-get-hacked/839048/4 "2019-08-22T12:52:37Z")

</div>

I don’t know how trustworthy your cigar buying sites are, but card skimmers at gas stations and ATMs can be a real problem. [This article at pcmag](https://www.pcmag.com/article/328010/how-to-spot-and-avoid-credit-card-skimmers) will show you how to spot and avoid them.

---

<div class="post-metadata">

### Author: ![Shodan](https://avatars.discourse-cdn.com/v4/letter/s/9f8e36/32.png) [@Shodan](https://boards.straightdope.com/u/Shodan)
#### Post date: [August 22, 2019, 1:01pm UTC](https://boards.straightdope.com/t/how-did-my-cc-get-hacked/839048/5 "2019-08-22T13:01:07Z")

</div>

Thanks, I will have a look

Regards  
Shodan

---

<div class="post-metadata">

### Author: ![kambuckta](https://avatars.discourse-cdn.com/v4/letter/k/53a042/32.png) [@kambuckta](https://boards.straightdope.com/u/kambuckta)
#### Post date: [August 22, 2019, 1:02pm UTC](https://boards.straightdope.com/t/how-did-my-cc-get-hacked/839048/6 "2019-08-22T13:02:10Z")

</div>

> [@Czarcasm](#):
>
> You not only gave your credit card number to booking dot com-you also gave it to all the hotels they passed that number to.

So are you saying the hotels themselves are using my card details?

---

<div class="post-metadata">

### Author: ![Czarcasm](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/czarcasm/32/4050_2.png) [@Czarcasm](https://boards.straightdope.com/u/Czarcasm)
#### Post date: [August 22, 2019, 1:04pm UTC](https://boards.straightdope.com/t/how-did-my-cc-get-hacked/839048/7 "2019-08-22T13:04:47Z")

</div>

> [@kambuckta](#):
>
> So are you saying the hotels themselves are using my card details?

I am saying that the longer the line is of people that have access to that number, the greater chance that it will be abused by someone who thinks she/he will be harder to trace.

---

<div class="post-metadata">

### Author: ![mhendo](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/mhendo/32/3159_2.png) [@mhendo](https://boards.straightdope.com/u/mhendo)
#### Post date: [August 22, 2019, 1:06pm UTC](https://boards.straightdope.com/t/how-did-my-cc-get-hacked/839048/8 "2019-08-22T13:06:17Z")

</div>

> [@kambuckta](#):
>
> So are you saying the hotels themselves are using my card details?

I imagine that all it takes is one dishonest employee who also has access to the hotel’s computer reservation system.

---

<div class="post-metadata">

### Author: ![Defensive\_Indifference](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/defensive_indifference/32/6502_2.png) [@Defensive\_Indifference](https://boards.straightdope.com/u/Defensive_Indifference)
#### Post date: [August 22, 2019, 1:11pm UTC](https://boards.straightdope.com/t/how-did-my-cc-get-hacked/839048/9 "2019-08-22T13:11:40Z")

</div>

There’s a trick called “web skimming” where the crooks compromise a website that accepts credit cards and siphon off the numbers from customers. A tool called MageCart is one of the more popular for doing this. I don’t know offhand if [booking.com](http://booking.com) was compromised, but it or another site you’ve used recently may have been.

> **[Web skimming](https://en.m.wikipedia.org/wiki/Web_skimming)**
>
> Web skimming, formjacking or a magecart attack is an attack where the attacker injects malicious code into a website and extracts data from an HTML form that the user has filled in. That data is then submitted to a server under control of the attacker.
> Subresource Integrity or a Content Security Policy can be used to protect against formjacking, although this does not protect against supply chain attacks. A web application firewall can also be used.
> A report in 2016 suggested as many as 6,000 e...

Google MageCart or web skimming and see if any ecommerce sites you’ve been to the past several months have announced being victimized by a web skimmer.

I think **Czarcasm** meant that the hotels you booked may have themselves been compromised, resulting in your CC number getting out that way. I don’t know enough about how [booking.com](http://booking.com) works to say if they share your CC with the hotel or just run your card and bundle payments to their client hotels without passing on the CC numbers.

---

<div class="post-metadata">

### Author: ![Dewey\_Finn](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/dewey_finn/32/4222_2.png) [@Dewey\_Finn](https://boards.straightdope.com/u/Dewey_Finn)
#### Post date: [August 22, 2019, 1:51pm UTC](https://boards.straightdope.com/t/how-did-my-cc-get-hacked/839048/10 "2019-08-22T13:51:29Z")

</div>

> [@mhendo](#):
>
> > [@kambuckta](#):
> >
> > So are you saying the hotels themselves are using my card details?
> 
> I imagine that all it takes is one dishonest employee who also has access to the hotel’s computer reservation system.

Don’t most of those systems obscure the credit card number for almost all users?

---

<div class="post-metadata">

### Author: ![Czarcasm](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/czarcasm/32/4050_2.png) [@Czarcasm](https://boards.straightdope.com/u/Czarcasm)
#### Post date: [August 22, 2019, 2:18pm UTC](https://boards.straightdope.com/t/how-did-my-cc-get-hacked/839048/11 "2019-08-22T14:18:26Z")

</div>

From [here:](https://www.quora.com/Is-sharing-a-credit-or-a-debit-card-detail-on-booking-com-for-a-Bali-hotel-booking-safe)

> [@](#):
>
> [Booking.com](http://Booking.com) does not store credit card information on their servers for a very long time, accommodations can view and access the credit card numbers 5 times before it gets automatically deleted from the system. Payment is processed by the accommodation and not [Booking.com](http://Booking.com).

So, [booking.com](http://booking.com) has it, and then it can then be accessed up to five times by the hotel.

---

<div class="post-metadata">

### Author: ![ZipperJJ](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/zipperjj/32/211_2.png) [@ZipperJJ](https://boards.straightdope.com/u/ZipperJJ)
#### Post date: [August 22, 2019, 2:26pm UTC](https://boards.straightdope.com/t/how-did-my-cc-get-hacked/839048/12 "2019-08-22T14:26:07Z")

</div>

Your card info doesn’t have to have become compromised recently for it to be used recently. The info could have been breached any time since the first time you used it to now. Credit card info is stolen, stored, tested, sold and used daily.

Don’t think too hard about how it may have gotten stolen. Be prepared for it to happen (have additional funding sources). Check your online statements a few times a month. Allow alerts from your credit card company (give them your cell number, and make sure their emails don’t go to the junk box). Don’t use a debit card.

---

<div class="post-metadata">

### Author: ![Defensive\_Indifference](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/defensive_indifference/32/6502_2.png) [@Defensive\_Indifference](https://boards.straightdope.com/u/Defensive_Indifference)
#### Post date: [August 22, 2019, 3:15pm UTC](https://boards.straightdope.com/t/how-did-my-cc-get-hacked/839048/13 "2019-08-22T15:15:35Z")

</div>

> [@Czarcasm](#):
>
> From [here:](https://www.quora.com/Is-sharing-a-credit-or-a-debit-card-detail-on-booking-com-for-a-Bali-hotel-booking-safe)  
> So, [booking.com](http://booking.com) has it, and then it can then be accessed up to five times by the hotel.

Cool, thanks for the information. Now that I’ve fully woken up and had my first pint of coffee, it does make sense that the hotel would need the card numbers. In my morning haze, I was thinking it would be easier for [booking.com](http://booking.com) to do all the processing and keep a cut, but I can see how that would be unwieldy for things like cancellations and would make it a pain for the hotel to charge incidentals.

So, yeah, the [booking.com](http://booking.com) site could have been skimmed, their databasse could have been compromised, one of the hotels could have been compromised, or there might be a dishonest employee somewhere along the chain.

And I second what **ZipperJJ** says as well.

---

<div class="post-metadata">

### Author: ![Mallard](https://avatars.discourse-cdn.com/v4/letter/m/b9bd4f/32.png) [@Mallard](https://boards.straightdope.com/u/Mallard)
#### Post date: [August 22, 2019, 5:17pm UTC](https://boards.straightdope.com/t/how-did-my-cc-get-hacked/839048/14 "2019-08-22T17:17:54Z")

</div>

I’ve had my credit card number stolen 3 different times over the years. As each time it was a chip card and my PIN wasn’t used, I wasn’t stuck with any of the charges. Supposedly gas stations with credit card readers (which is all there is around here anyway) are bad for some kind of device being inserted that can read your card so the credit card company advised me to go inside to pay. At most self serve places, you have to leave a deposit, fill your tank then come in and clear up the charge. Time consuming PITA. (I’ve gone back to using the credit card slot on the pump)

---

<div class="post-metadata">

### Author: ![DPRK](https://avatars.discourse-cdn.com/v4/letter/d/4491bb/32.png) [@DPRK](https://boards.straightdope.com/u/DPRK)
#### Post date: [August 22, 2019, 5:39pm UTC](https://boards.straightdope.com/t/how-did-my-cc-get-hacked/839048/15 "2019-08-22T17:39:09Z")

</div>

If you have the choice, I would use a single-use or virtual credit card number that doesn’t matter if it gets stolen because it’s only valid for a single transaction. That is probably easier to manage for online purchases, though, than with physical transactions, unless the card is a smart card that supports it (I do not have such a card in my wallet at the moment, for instance).

---

<div class="post-metadata">

### Author: ![Enola\_Gay](https://avatars.discourse-cdn.com/v4/letter/e/3ab097/32.png) [@Enola\_Gay](https://boards.straightdope.com/u/Enola_Gay)
#### Post date: [August 22, 2019, 6:22pm UTC](https://boards.straightdope.com/t/how-did-my-cc-get-hacked/839048/16 "2019-08-22T18:22:15Z")

</div>

This happened to me and the authorities actually figured it out. We are really careful with our credit cards, but a few months ago, our visa card (which had never left our possession) was being used in Mexico. And the info that the bank had, was that whoever was using the visa, actually had a CARD and was not just giving the number for a phone or internet purchase. Turned out that some criminals had installed some sort of credit card reader/counterfeiter inside the card reader at a local gas station we frequent. They made a phony visa with all our info on it, and started racking up charges in resort cities in Mexico. Kind of amazing how smart some criminals are. Too bad they use it for evil rather than good.

---

<div class="post-metadata">

### Author: ![Ruken](https://avatars.discourse-cdn.com/v4/letter/r/f475e1/32.png) [@Ruken](https://boards.straightdope.com/u/Ruken)
#### Post date: [August 22, 2019, 8:26pm UTC](https://boards.straightdope.com/t/how-did-my-cc-get-hacked/839048/17 "2019-08-22T20:26:52Z")

</div>

OP’s card most likely wasn’t “hacked”. Neither was **Shodan** ’s.

---

<div class="post-metadata">

### Author: ![kambuckta](https://avatars.discourse-cdn.com/v4/letter/k/53a042/32.png) [@kambuckta](https://boards.straightdope.com/u/kambuckta)
#### Post date: [August 23, 2019, 12:51am UTC](https://boards.straightdope.com/t/how-did-my-cc-get-hacked/839048/18 "2019-08-23T00:51:57Z")

</div>

> [@Ruken](#):
>
> OP’s card most likely wasn’t “hacked”. Neither was **Shodan** ’s.

What do you mean?

---

<div class="post-metadata">

### Author: ![Sunny\_Daze](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/sunny_daze/32/438_2.png) [@Sunny\_Daze](https://boards.straightdope.com/u/Sunny_Daze)
#### Post date: [August 23, 2019, 3:31am UTC](https://boards.straightdope.com/t/how-did-my-cc-get-hacked/839048/19 "2019-08-23T03:31:14Z")

</div>

> [@Czarcasm](#):
>
> You not only gave your credit card number to booking dot com-you also gave it to all the hotels they passed that number to.

Yes. We had a credit card number lifted when we stayed at a hotel. The credit card company told us that it had happened on multiple occasions from that hotel and they were working with management to identify the problem employee.

> [@Ruken](#):
>
> OP’s card most likely wasn’t “hacked”. Neither was **Shodan** ’s.

Are you quibbling over the use of the word “hacked”?

---

<div class="post-metadata">

### Author: ![susan](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/susan/32/17537_2.png) [@susan](https://boards.straightdope.com/u/susan)
#### Post date: [August 23, 2019, 3:41am UTC](https://boards.straightdope.com/t/how-did-my-cc-get-hacked/839048/20 "2019-08-23T03:41:32Z")

</div>

I had several cards spoofed over a couple of years. The card security office said it was probably from running random numbers rather than hacking or skimming.

[Next page](https://boards.straightdope.com/t/how-did-my-cc-get-hacked/839048.md?page=2)
