Each of our Debit cards used fraudulently one day after another. DH had never used his.

I think I was able to set very low POS limits on at least some of the cards. I might have had to phone in. Of course if the card is reissued you have to do it all over again.
 
yes; unfortunately not all banks issue ATM only. I keep my card locked -- not much risk. Rarely used even for ATM.
You have to ask... and even insist... they have them but want to make it seem that you have to have their debit card...
 
I have a throw away debit card at Schwab that I use for cash at ATMs when needed. This is rare and I usually only use it when traveling, since it reimburses fees. The account never has that much cash and it’s the only account I maintain at Schwab (thank you Schwab!).

I have a virtual debit card for an account in Europe, which I sometimes need to use since some local sites don’t accept non-local debit/credit cards. When I enter that debit card number for the transaction, I get prompted on my smartphone to validate the transaction. I thought that was clever. I have no idea what would happen if there was a physical card with that number. I would hope it would be denied, since a physical card for that account doesn’t exist.
 
These fraudulent charges probably didn’t have a physical card. That’s a lot of trouble and expense to create. You don’t need a physical card for online purchases.

You can lock your Schwab debit card online. It’s kind of hidden, you see it when you go to add a travel notice. Locking the card immediately denies any transaction.

One weird thing about using a debit card online in my experience is that they don’t request a PIN, they need an expiration date and maybe the CVC. In other words it acts like a credit card for online purchases.
 
You have to ask... and even insist... they have them but want to make it seem that you have to have their debit card...
I definitely had to insist on the ATM card at my primary credit union. When they asked why, my answer:

I prefer the lower risk level of an ATM card. It has a cash withdrawal limit and video record of ATM transactions. Plus, I already have credit cards.
 
I definitely had to insist on the ATM card at my primary credit union. When they asked why, my answer:

I prefer the lower risk level of an ATM card. It has a cash withdrawal limit and video record of ATM transactions. Plus, I already have credit cards.
Smart!

I assume they acquiesced. I did the same years ago though I no longer use an ATM card (or debit card).
 
I have ATM only bank cards with Citi and BoA, no debit. I've used these all over Europe and South America to withdraw cash with no issues. My mother's BoA card had a fraudulent charge, even though it lives in my drawer. I had it reissued and put a lock on it.

I get emails of all charges > $1 on my credit cards and $10 (the minimum) on my Amex, so I know immediately if they are compromised. When fraudulent activity occurs, it's often small charges to see if they can get away with it. My son was mugged and he forgot about one card. The muggers used it at a convenience store. It went through, but I saw it and called and cancelled it. There were 8 other transactions the thieves tried immediately after that were rejected. The police were able to catch them because of CCTV when they used the credit card.
 
Similar thing happened to me with our two debit cards. Mine was hacked, then a week later my wife’s and she had never used hers. Bank said the thieves randomly generate card numbers and try them online to see if they work.
 
The account number for all credit cards and debit cards are actually designed to be entered into a mathematical algorithm. If the result of this algorithmequals specific numbers, it passes the initial validity check. This is why whenyou put in your CC/debit number, it comes back stating whether it is Visa, MC, AmEx, etc.
The algorithm that each company set up is supposed to be secret but scammers found out. So they were able to craft CC/Debit numbers that satisfied that algorithm. So chances are this is what happened. The scammers used your debit number to make a purchase (that they made up) but did not have your name or security code. This is why you now put in your zip code when you buy gas, etc.
 
Similar thing happened to me with our two debit cards. Mine was hacked, then a week later my wife’s and she had never used hers. Bank said the thieves randomly generate card numbers and try them online to see if they work.
I’m skeptical. I think you need more than just the number. You need an expiration date and maybe also a CVC number. I don’t think an online purchase would work without at least the correct expiration date.

Some online purchases ask for the billing address for the card as well.
 
The newer ATMs let you pick denominations but nothing smaller than $10.
Actually, Chase ATMs (newer) will dispense $1,$5,$10,$20 & $50s. Wife has shoulder problems and goes to friends salon once a week to get hair washed/blown by apprentices. $27 cash each time, includes tip. So I get 2 months worth in cash out from the Chase ATM, and she has exact amount for them each visit. We also pay our biweekly maid in cash.
 
The "bad guy" here is using a simple program. Take a number + 1, run it. If it works charge a small AMT. Now you have a valid credit card account that you can sell on the black market. They just keep it up, over and over., day after day. I don't know why but BOA is either a favorite target or the only company that bothers to notify you. When it happened to me, they contacted me. Sent me a new card with a new number. Which is a total pain because they all look alike and I get them mixed up, what happened to the day when you could pick a picture for the card! I did notice they quickly erase all signs of the incident. Never shows up on the statement, not paper or electronic after resolved. When it happened a second time I felt the name was the same, a coffee place, when I went to verify everything was gone. Also worth mentioning but sort of off topic, when I disputed a charge, the company refunded but keep $15. Which just pissed me off, BOA just gave me the $15 rather than fight with the scumbag insurance company!
 
The "bad guy" here is using a simple program. Take a number + 1, run it. If it works charge a small AMT. Now you have a valid credit card account that you can sell on the black market. They just keep it up, over and over., day after day. I don't know why but BOA is either a favorite target or the only company that bothers to notify you. When it happened to me, they contacted me. Sent me a new card with a new number. Which is a total pain because they all look alike and I get them mixed up, what happened to the day when you could pick a picture for the card! I did notice they quickly erase all signs of the incident. Never shows up on the statement, not paper or electronic after resolved. When it happened a second time I felt the name was the same, a coffee place, when I went to verify everything was gone. Also worth mentioning but sort of off topic, when I disputed a charge, the company refunded but keep $15. Which just pissed me off, BOA just gave me the $15 rather than fight with the scumbag insurance company!
Ours is still on the record in terms of charge reversed. And when we set up the replacement cards we put the old no good ones in the shredder. Why would you keep an old one around to confuse you?
 
So this happened to me. My Credit Union decided they wouldn't issue ATM-only cards. Have to have a debit card. Got it 2 months ago. Used it once at the drive-in ATM right at the window of the CU.

Fast forward 4 weeks. Within a matter of seconds, both my Debit card and Credit card from this CU were attempted to be used fraudulently. Their algorithm rejected all the attempts on both cards. Attempts were to onlyfans.com, which it determined correctly is out of norm for me.

So now I got to get two new cards, and if I want to use the ATM, a card I don't want.

The fact that both cards were used within seconds of each other screams some sort of internal data breach at the CU or some processor.

This is really a PITA.

Coda: my automatic charges on the credit card are going through fine. I guess they get updated information these days. Someone up-thread mentioned that the transfer agent that does this is subject to breaches too.
 
Having only debit cards were another reason I closed the CU account... tried to get an ATM only from Schwab but unsuccessful... I keep it because they reimburse ATM charges that we will be getting when overseas...
 
It’s very easy to lock debit cards online these days. It doesn’t mean that they won’t be compromised, but charges will be blocked.

We keep our Schwab and Fidelity debit cards locked unless we take them traveling.
 
My debit card was fraudulently used a day after we opened our bank account. We had a new one issued. We never use them and don’t even remember the pin. Our two banks we drive by all the time. We get cash by doing it the old fashioned way by writing a check at the bank. We keep cash stashed on hand so it’s not too inconvenient. We very rarely have to deposit a check and when we do we just go inside and do it. We know the tellers and usually have take longer talking about where they or us are going or have been lately.
 
All the way back to the OP where a card that was never used got used by a bad guy....

That happened to my wife a few weeks ago. They had to have the CVV, and the processors are smart enough not to let them try 000 through 999, so it was a breach by the credit union or possibly a bad guy somewhere between the card maker and our mailbox. The world we live in.
 
Went to the CU today and closed most of my accounts except traditional savings, and had them shred and disable the Debit card replacement they sent me. He confirmed they do not issue ATM cards anymore.

With this CU, I can use my driver's license with a remote teller box to get the occasional cash I need every 3 months or so.

I'm reducing my account footprint in this world. The energy required to make sure scammers and hackers aren't stealing from me is becoming too much.
 
The energy required to make sure scammers and hackers aren't stealing from me is becoming too much.
I get it.

Here's what's in today's mail, one for me, one for DW. Both cards have a distant expiration date, and they issued DW a new card only a little while ago. I guess they found out they were hacked and needed to replace all the cards.

EDIT: False Alarm!!

In the envelopes were an advertisement, NOT a new card. Well, a paper card for some life insurance or some BS. I'm ashamed to have believed "CARDS ENCLOSED"...they don't do that...cards typically come in a nondescript envelope. I must be getting old.
 

Attachments

  • CardsInMail.JPG
    CardsInMail.JPG
    75.4 KB · Views: 77
Last edited:
OP, do you and your DH have same or different debit card numbers? Are they linked to the same account?
 
OP, do you and your DH have same or different debit card numbers? Are they linked to the same account?
The OP didn't indicate if it was a joint account, but I suspect it was.
Yes it was a joint bank account. When they issue debit cards each owner gets a different number.
 
Went to the CU today and closed most of my accounts except traditional savings, and had them shred and disable the Debit card replacement they sent me. He confirmed they do not issue ATM cards anymore.

With this CU, I can use my driver's license with a remote teller box to get the occasional cash I need every 3 months or so.

I'm reducing my account footprint in this world. The energy required to make sure scammers and hackers aren't stealing from me is becoming too much.
The minimal penalties for fraudulent use and the lack of interest in tracking down fraudulent users leads to the issues we all have to be on guard against. The CC companies don't seem to care - they can just pass on the costs to those who use credit.

Lock up fraudsters for 5 years and this problem would likely shrink very quickly.
 
Back
Top Bottom