Scam or mistake? Need I worry?

I got three emails, sent within a 15 minute window, from Costco. The oldest one changed my Costco payment method (to a card held by someone with a different name), the next confirmed my order from costco.com; the newest one said the order was cancelled. Costco’s help screen on order cancellations says that it was very likely due to a problem with the credit card.

This caused me some consternation since I do have an order with Costco Travel for 2 weeks from now. I really don’t want to have to scramble to reorder my rental car at what will probably be a lot more money.

However, a little investigation showed that the order was not one I made but was for 2 Xbox gift cards. The name/delivery address on the order were mine, although the cards were supposed to be digitally downloaded. The name on the order was mine, but the billing address was in another state. The member number and email address are mine, but the payment method for this order is for the credit card my payment method was transferred to.

So what’s going on? I can understand someone getting into my account and ordering stuff, but if it’s a scam I’d think they’d want it charged to me. Also, if the cards are supposed to be digitally downloaded, wouldn’t even an incompetent scammer change the email address associated with the account? All this says someone made a mistake – but somehow they did get into my account, meaning they had my membership number and password. And any order for gift cards suggests a scam.

I changed to payment info back to my Costco Citi card. I did online chat with a Costco agent. Changed my password. Anything else I need do?

Look very carefully at the URLs in the email messages. They may say “costco.com” in blue, but where do the links actually go? One common scam is for email to pretend to be from a merchant or bank with a link to a page where you’re asked to login to your account.

Thanks!

Entering costco.com on my browser and going to my orders shows the cancelled order.