OT: Credit card hacked.

Apr 11, 2026 Last reply: 3 months ago 33 Replies

Yes, indeed. I am unfamiliar with that service. I was thinking that it sounded like Amazon España. The whole thing is weird, on the one hand I have no knowledge or record of having any interaction with Amazon.com (USA), but it (or somebody) sent me a charge. My bank refunded me for that and also its international currency charge. Then, Amazon.com confirmed that I had left my non-existent Prime membership, which sounds as though it was a genuine Amazon.com interaction. Maybe it's just a good scammer dotting the Is and crossing the Ts. maybe it's just Amazon getting confused with too many accounts and members. I blame AI. To further complicate matters, I currently have a short-term Amazon (UK) Prime membership, which expires next week, so today's message had me really confused.

I decided to try to ask Amazon.com why it had given me a Prime subscription. I went onto the website, and every attempt to find a way of asking the question was foiled by the system, usually by there not being a suitable menu option. I tried Chat, and it was no better. I gave up.

I tried.

Very recently (a few days ago), someone I know reported their card stolen, and as part of the report/cancel process they (Nationwide) explicitly said that they were also "cancelling any digital tokens" associated with it, i.e. so that if remember-my-card details were stored elsewhere, they were revoked. Perhaps this varies by provider, or might be a new thing gradually being introduced.

#Paul

Some years ago I was issued with a new card, which I left in its envelope because the old one had not yet expired.

To my chagrin, the FT website silently used my *new* card in preference to the old to renew my subscription, meaning I turned up at the supermarket checkout with a card that had been automatically 'expired' due to the new one being used.

Without you activating the new one? Spooky! How did the FT even learn what the new number was?

yes

They apparently had access to it.

That does seem to be a bit naughty. I've found (so far) that a changed credit card number will get me an offended email from someone I had forgotten had it, saying it has been declined. In at least one case, it reminded me to cancel an automatic renewal I didn't realise had happened.

The third time I got caught by a changed Amazon ordering format and accepted a free trial of Amazon Prime, I was immediately told that the card had not been accepted. I hadn't realised they kept the credentials, separate from Amazon itself who had the new card number. I was apparently not able to cancel as they did not have a valid credit card number (!). I was reluctant to give them the new number, and after a year they finally told me the account was closed.

I'm sure a great number of standard practices these days would once have been illegal in the UK. Democracy?

If they had a Continuous Payment Authority, they are allowed to continue charging even if the card is replaced (especially if it hasn't been reported stolen, when typically it's just the expiry date that updates). Otherwise all your subscriptions etc would be interrupted when you get a new card.

Presumably that charge was 'proof' to the bank that you have received the new card and were activating it. They might not be able to tell the difference between the FT using the new card details via their CPA and you making a fresh transaction on the FT website.

As to 'tokens', I assume that relates to things like Apple Pay, which allow you to make payments on the account without using the card. Apple get some kind of authorisation from the bank to allow them, and I wonder if that's a token?

Theo

That was their explanation, yes.

Theo <theom+ snipped-for-privacy@chiark.greenend.org.uk> wrote

ApplePay tokens are one time tokens, deliberately, so the merchant can't deliberately use them more than once to steal from you

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required