OT: Credit card hacked.

Apr 11, 2026 Last reply: 3 months ago 33 Replies

I sometimes use Amazon, and have on occasions taken the free Prime membership for a month, to enable free and next day shipping. The last one of these was cancelled a couple of weeks ago. All Amazon transactions have always been in UK £s. A couple of days ago, I noticed on my daily review of my bank accounts, that my credit card had a new charge on it, for Amazon Prime, charged to Washington State in the US. My bank had added a currency conversion fee to this. I had no idea what this might be about. I went on to my Amazon account, and it confirmed that I do not have an active Prime account. It also showed no sign of the charge that had been taken. I 'phoned Amazon, and talked to a real person, who confirmed these details, and stated clearly that the charge did not come from Amazon. I then called my bank, and it confirmed that the charge was just like an Amazon-registered card, it allowed future charges to be made without any further checking. The conclusion was that my card had been hacked, and so it was cancelled and a new one is hopefully on the way. Today, my bank has issued 'temporary' refunds of both the charge and the fee, which is good.



So far, the process has gone according to plan, I just hope that it runs without interruption for the 60 days needed to confirm that it is all good.



I have no idea who might have hacked the card, maybe it was included in one of those hacking breaches that we read about, where hundreds of card details are vacuumed up and sold.



It is a pity that the cancellation of the card has not resulted in the cancellation of the existing charges on it. Oh well.


The charges go to the *account* not the card. This is why a lot of companies would only allow you to sign up with a credit card. Even if you cancelled the card they could continue milking you.

It's always a good idea to look at how much work companies put into evading statutory protection. Whether that is by not being in the UK, or other such ploys.

I understand what you are saying, and I am certainly not an expert in this, but the charge was explicitly charged to the card, not the account. The bank added its fee to the account. This is what the listings show.

I don't understand how cancelling a card does not stop further charges being made to the account unless re-authorised for the new card.

The bank says it has blocked any future charges for that merchant.

Just be aware that prime is a country specific benefit. So if the charge was actually for Prime from the USA it would not show on amazon.co.uk, only on amazon.com.

I have Prime in the UK but also shop on amazon.es where I don't get Prime benefits, and if I go to my account on there it tries to sell me Prime

No, it never does. In the past I have been given a new account but again the charges were transferred.

Dave

Interesting. I will follow up on that. I have certainly not knowingly had any interaction with Amazon US.

I just checked Amazon.com, and it tried to sell me a Prime membership, so I don't have Prime there either. I'm not surprised, the mysterious charge came from somebody impersonating Amazon.

It was just a thought. You never know...somebody might goof...

In message <10rde2s$1pqca$ snipped-for-privacy@dont-email.me, Davey snipped-for-privacy@example.invalid writes

I got one of these the other day, I don't have Prime:-

Hi snipped-for-privacy@b-howie.co.uk,

Your Amazon Prime Membership is set to renew on Sun, April 12, 2026 2:29 AM. However, we've noticed that the payment method associated with your Prime membership is no longer valid. To update the default payment method or choose a new one for your membership, please click on the button below and follow the on-screen instructions.

The header says "Your Prime membership is Renewing on Sun, April 12,

2026 2:29 AM Reff-62169261 (Contains malware Sanesecurity.Phishing.Fake.32125.UNOFFICIAL)"

Some one who views their e-mail in HTML won't see that.

Brian

On the few occasions when I take up the offer of free Prime membership, I know exactly when it expires, so that I can cancel it before I start to pay for it. So I never owe Prime any money at all. They are out to get you....

What I get, almost every day, is at least one message telling me that my mailbox is full/needs authentication/needs renewal/etc/.

It comes from the "Eager Mail Administrator".

The mail server is two metres to my right.

I have just had this one:

There is no link to click, merely "For more information, visit GOV.UK."

Just in case, I did check, and the vehicle is, as I knew, fully taxed.

What is the point?

Chris

Does your mail client render HTML? Malicious links are often embedded in HTML but not repeated in plain text where the real URL cannot be hidden.

I can see the HTML, but I thought that no links were present. Peering closer, there was faint text against a green stripe inviting me to renew at the URL below.

"

formatting link
"

Chris

I am getting a message from Windows like this -

"Updated Secure boot certificates on this device have not yet been applied to the firmware.Review the published guidnace to complete the update and maintain full protection. This device signature info is included here. deviceAttributes: Blah blah Gigabyte GA-880GM-UDH etc BucketConfidenceLwevel: No Data Observed - Action Required."

This is a 2011 M/B without TPMS, so what is it telling me (apart from get a new PC) ?.

PS. Is there *any* way of cutting and pasting windows error logs ?. The text can be selected with the left button but the right button does nothing. The only option seems to be to send it online to microsoft. It's a pain having to retype it.

Good spot, but it depends on the client. Thunderbird in plain text shows that there is a link (usually coloured font), but the actual URL linked to is only visible in the status bar. Don't know about Forte Agent which CJD uses.

Be careful, though, to look at the URL correctly. A few years ago I nearly got caught by a

formatting link
address! It was "hidden" in a long URL in black font on the grey display of the status bar,and I thought it said
formatting link

Double click on the entry, there is a copy button...

Dave

I do have a webmail server which displays HTML when I really need it {e.g. to print a ticket or barcode) but normally use a client which doesn't have its optional HTML viewer installed, so everything appears as plain text or not at all. Harder to hide things when there aren't fancy fonts or colours available.

If I must see something suspicious which contains HTML, I'll look at the message source and search for http first. But in most cases, the From: or most recent Received: header will show if it's likely to be malware. Or the subject is written in Spanish..

Today, I received a message from Amazon Prime (referred to in the headers as amazon.com and snipped-for-privacy@amazones.com) saying that it was sorry that I had left Prime. Amazon UK has no knowledge of any of this.

Curiouser and curiouser.

Presumably you meant amazonses.com? Which is the Amazon Simple Email Service ...

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required