Rakuten Buy.com Customers Getting Fraudulent Credit Card Charges
SD USERS REPORTING CREDIT CARD FRAUD VIA RAKUTEN SHOPPING SITE: 276
Summary of the conclusions made by the contributors of this forum:
(1) Identity thieves obtained credit card #'s and SSN #'s from some Rakuten Customers
[Ref: News Story & NJ Police Interview
http://www.northjersey.com/news/B...l?page=all -- 'AnnoyedwithRakuten']
[Ref: Additionally
http://www.bergendispatch.com/art...arges.aspx]
[Ref: 'scotthall3411' Post #462, etc.]
(2) Many other users have been affected outside of the SlickDeals community
[Ref: Specialized Site Now Available:
http://rakutenfraud.com/]
(3) The apparent security breach is not limited to just customers who placed orders. Several have reported credit card details were taken from their Rakuten My Account screen.
[Ref: 'Cletus81' Post #435, 'missmex1' Post #445]
(4) The apparent security breach was not at the credit card payment processing agent.
[Ref: 'mirai' Post #437]
(5) Customers using credit, debit cards and Gift Cards have been affected.
[Ref: Thread postings and external sites.]
(6) Almost 100% of all fraud reports are from customers who gave Rakuten their credit (or debit) card directly (rather than using payment gateways or other payment methods (gift cards, etc.)
[Ref: Thread postings.]
(7) Many customers were able to uniquely identify Rakuten as the source of the credit card theft.
[Ref: Many thread postings from customers using a one-time Virtual Credit Card Number, a new credit card only used at Rakuten, or a new Gift Card.]
(8) Rakuten Buy.com denies that any security breach has occurred, though they are "cooperating with police".
[Ref: News Story & NJ Police Interview
http://www.northjersey.com/news/B...l?page=all -- 'AnnoyedwithRakuten']
(9) Using a Virtual Credit Card Number or Gift Cards at Rakuten may not be the best alternative.
[Ref: 'GPz1100' Post #205, Post #447, etc. Several affected customers posted their VCCN's later breach caused the credit card company to reissue a new card.]
[Ref: 'namlook' Post #449, etc. Hacker's later emptied the gift card or sold the balance on eBay.]
[Ref: 'bargainfinder09' Post #449 Must close VCCN out afterwards.]
(10) The apparent security breach still exists at Rakuten today, and a Rakuten customer order is not required to generate the subsequent CC fraud.
[Ref: 'Edxzxz' Post #583]