<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Check  Your American Express Statement!</title>
	<atom:link href="http://www.chocolateandgarlic.com/2009/05/check-your-american-express-statement/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.chocolateandgarlic.com/2009/05/check-your-american-express-statement/</link>
	<description>The Sweet, The Savory</description>
	<lastBuildDate>Tue, 20 Jul 2010 20:04:46 -0500</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Michelle W.</title>
		<link>http://www.chocolateandgarlic.com/2009/05/check-your-american-express-statement/comment-page-1/#comment-671</link>
		<dc:creator>Michelle W.</dc:creator>
		<pubDate>Thu, 09 Jul 2009 17:12:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.chocolateandgarlic.com/?p=1591#comment-671</guid>
		<description>The same thing just happened to me with my AX card and True.com!  I never use my AX card and it&#039;s kept locked up in my desk so no one would be able to get ahold of it.  I have charges from True.com from the last four months!! I called AX and they were able to credit some back and True.com was actually really helpful and was able to credit the outstanding balance that AX wasn&#039;t able to credit back due to the fact that it was four months ago.

This is crazy! I&#039;ve never had anything like this happen again and I will definetely be keeping closer tabs on my credit accounts. I just thought I didn&#039;t have to worry about it because the card is always locked up, but I was wrong!

Thanks for posting this blog by the way! I used this as an example to both AX and True.com.  True.com is admitting that many AX accounts have been compromised, but AX claimed they haven&#039;t had any issues that they&#039;re aware of with fradulent use of AX cards on True.com.

Thanks again!!

Michelle</description>
		<content:encoded><![CDATA[<p>The same thing just happened to me with my AX card and True.com!  I never use my AX card and it&#8217;s kept locked up in my desk so no one would be able to get ahold of it.  I have charges from True.com from the last four months!! I called AX and they were able to credit some back and True.com was actually really helpful and was able to credit the outstanding balance that AX wasn&#8217;t able to credit back due to the fact that it was four months ago.</p>
<p>This is crazy! I&#8217;ve never had anything like this happen again and I will definetely be keeping closer tabs on my credit accounts. I just thought I didn&#8217;t have to worry about it because the card is always locked up, but I was wrong!</p>
<p>Thanks for posting this blog by the way! I used this as an example to both AX and True.com.  True.com is admitting that many AX accounts have been compromised, but AX claimed they haven&#8217;t had any issues that they&#8217;re aware of with fradulent use of AX cards on True.com.</p>
<p>Thanks again!!</p>
<p>Michelle</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Pmom</title>
		<link>http://www.chocolateandgarlic.com/2009/05/check-your-american-express-statement/comment-page-1/#comment-641</link>
		<dc:creator>Pmom</dc:creator>
		<pubDate>Wed, 24 Jun 2009 18:50:30 +0000</pubDate>
		<guid isPermaLink="false">http://www.chocolateandgarlic.com/?p=1591#comment-641</guid>
		<description>Readers, I&#039;m not sure who Chris is--the e-mail address he provided is fictitious.  However, his logic makes sense to me.  But, given the number of keyword searches (with words like true.com and American Express) that have led people to my site, it does appear that I&#039;m not the only one coping with fraud issues.  Perhaps the first twelve digits aren&#039;t the same, but the first six are.  Or perhaps Costco-issue American Express cards have quite similar numbers.  I have no idea.  But something is making it possible for scam artists to guess at valid numbers and that is disturbing.</description>
		<content:encoded><![CDATA[<p>Readers, I&#8217;m not sure who Chris is&#8211;the e-mail address he provided is fictitious.  However, his logic makes sense to me.  But, given the number of keyword searches (with words like true.com and American Express) that have led people to my site, it does appear that I&#8217;m not the only one coping with fraud issues.  Perhaps the first twelve digits aren&#8217;t the same, but the first six are.  Or perhaps Costco-issue American Express cards have quite similar numbers.  I have no idea.  But something is making it possible for scam artists to guess at valid numbers and that is disturbing.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris</title>
		<link>http://www.chocolateandgarlic.com/2009/05/check-your-american-express-statement/comment-page-1/#comment-640</link>
		<dc:creator>Chris</dc:creator>
		<pubDate>Wed, 24 Jun 2009 15:24:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.chocolateandgarlic.com/?p=1591#comment-640</guid>
		<description>What was said about the first 12 digits all being the same is completely incorrect. As the card number is only 15 digits long, if this were true, that would mean that there are only 1000 possible numbers, but due to Luhn (the algorithm that verifies a card number), this amount would be divided by 10, so that would mean only 100 Amex cards exist... Which is compeltely incorrect. Many also start with 3760, and some with 3778. These numbers, and the 2 that follow, depend on the country of issue and the currency of the card. :)</description>
		<content:encoded><![CDATA[<p>What was said about the first 12 digits all being the same is completely incorrect. As the card number is only 15 digits long, if this were true, that would mean that there are only 1000 possible numbers, but due to Luhn (the algorithm that verifies a card number), this amount would be divided by 10, so that would mean only 100 Amex cards exist&#8230; Which is compeltely incorrect. Many also start with 3760, and some with 3778. These numbers, and the 2 that follow, depend on the country of issue and the currency of the card. <img src='http://www.chocolateandgarlic.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kevin</title>
		<link>http://www.chocolateandgarlic.com/2009/05/check-your-american-express-statement/comment-page-1/#comment-580</link>
		<dc:creator>Kevin</dc:creator>
		<pubDate>Wed, 27 May 2009 17:44:30 +0000</pubDate>
		<guid isPermaLink="false">http://www.chocolateandgarlic.com/?p=1591#comment-580</guid>
		<description>The same incident happened to me recently. I logged into my Amex account online and saw 3 fraudulent charges from True.com. Of course when I contacted Amex, they immediately credited the charges back to my account, but I think I will be canceling my Amex account. It seemed to easy for someone to charge my credit card, and there is no guarantee that it will happen again. I seldom use this card and it pains me to think I would have to keep monitoring it to make sure that no one else is using it.</description>
		<content:encoded><![CDATA[<p>The same incident happened to me recently. I logged into my Amex account online and saw 3 fraudulent charges from True.com. Of course when I contacted Amex, they immediately credited the charges back to my account, but I think I will be canceling my Amex account. It seemed to easy for someone to charge my credit card, and there is no guarantee that it will happen again. I seldom use this card and it pains me to think I would have to keep monitoring it to make sure that no one else is using it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jim F.</title>
		<link>http://www.chocolateandgarlic.com/2009/05/check-your-american-express-statement/comment-page-1/#comment-550</link>
		<dc:creator>Jim F.</dc:creator>
		<pubDate>Fri, 15 May 2009 04:14:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.chocolateandgarlic.com/?p=1591#comment-550</guid>
		<description>They ship it to an empty house, watch for the delivery, and pick it up from the door step.</description>
		<content:encoded><![CDATA[<p>They ship it to an empty house, watch for the delivery, and pick it up from the door step.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Pdad</title>
		<link>http://www.chocolateandgarlic.com/2009/05/check-your-american-express-statement/comment-page-1/#comment-548</link>
		<dc:creator>Pdad</dc:creator>
		<pubDate>Fri, 15 May 2009 03:26:34 +0000</pubDate>
		<guid isPermaLink="false">http://www.chocolateandgarlic.com/?p=1591#comment-548</guid>
		<description>I&#039;m still not getting the whole picture here.
a) Valid card number and expiration date is figure out at crummy site that doesn&#039;t check the billing address
b) Crook can use this at other crummy sites that don&#039;t check the billing address
That doesn&#039;t seem like such a great deal...

Or maybe the idea is that the crook wants an account that cannot be traced so the goal of using your credit card isn&#039;t to avoid the charge (though that&#039;s nice too) but to not have a way to tie the account back to them. so then when they do HardDiscDriven&#039;s suggested type of fraud it is harder to catch them.</description>
		<content:encoded><![CDATA[<p>I&#8217;m still not getting the whole picture here.<br />
a) Valid card number and expiration date is figure out at crummy site that doesn&#8217;t check the billing address<br />
b) Crook can use this at other crummy sites that don&#8217;t check the billing address<br />
That doesn&#8217;t seem like such a great deal&#8230;</p>
<p>Or maybe the idea is that the crook wants an account that cannot be traced so the goal of using your credit card isn&#8217;t to avoid the charge (though that&#8217;s nice too) but to not have a way to tie the account back to them. so then when they do HardDiscDriven&#8217;s suggested type of fraud it is harder to catch them.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Pmom</title>
		<link>http://www.chocolateandgarlic.com/2009/05/check-your-american-express-statement/comment-page-1/#comment-542</link>
		<dc:creator>Pmom</dc:creator>
		<pubDate>Tue, 12 May 2009 05:35:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.chocolateandgarlic.com/?p=1591#comment-542</guid>
		<description>I realize that, but my puzzle is how the collect the goods they buy.  If they ship it to themselves can&#039;t it be traced?</description>
		<content:encoded><![CDATA[<p>I realize that, but my puzzle is how the collect the goods they buy.  If they ship it to themselves can&#8217;t it be traced?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jim F.</title>
		<link>http://www.chocolateandgarlic.com/2009/05/check-your-american-express-statement/comment-page-1/#comment-541</link>
		<dc:creator>Jim F.</dc:creator>
		<pubDate>Mon, 11 May 2009 03:27:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.chocolateandgarlic.com/?p=1591#comment-541</guid>
		<description>Once they have a valid number, they can charge things to it, more than Cooks Illustrated and WSJ. 

Just ask Amex to issue a new number. Mastercard just did that for us because there was a suspicious charge on our account.</description>
		<content:encoded><![CDATA[<p>Once they have a valid number, they can charge things to it, more than Cooks Illustrated and WSJ. </p>
<p>Just ask Amex to issue a new number. Mastercard just did that for us because there was a suspicious charge on our account.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: HardDiscDriven</title>
		<link>http://www.chocolateandgarlic.com/2009/05/check-your-american-express-statement/comment-page-1/#comment-540</link>
		<dc:creator>HardDiscDriven</dc:creator>
		<pubDate>Mon, 11 May 2009 01:29:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.chocolateandgarlic.com/?p=1591#comment-540</guid>
		<description>I can shed some light on this -- keep in mind that these thoughts are my own.

#1, it is quite easy to generate a list of valid credit card numbers, as the numbering system is not a secret.  I&#039;ll spare you the algorithm, but essentially, the only security built in is to help prevent the wrong card from being charged if the numbers are transposed -- meaning that if you accidently swap the position of the 7th and 8th digits in your card number when buying something online, the transaction will decline, because the transpostion made the card number invalid.

If a site utilizes little or no precautions for verifying the billing address (read between the lines as &quot;shady&quot;), it is possible to charge a card without having any clue who it belongs to.  However, it is somewhat trivial for a savy criminal to do a reverse-lookup via a bit of marketing-database mining.  But I digress.

#2:  The reason for the false charges coming through online dating/matchmaking sites such as true.com is because this is a big money-maker for social-engineering adept criminals.  The following articles illustrate a good example, and a bit more detail on the subject... 
http://www.cbc.ca/canada/edmonton/story/2009/02/17/edm-dating-fraud.html?ref=rss
http://www.scamtypes.com/what-exactly-is-online-dating-fraud.html

If criminals like this can be likened to bacteria, and the internet to a body, the net is very sick.</description>
		<content:encoded><![CDATA[<p>I can shed some light on this &#8212; keep in mind that these thoughts are my own.</p>
<p>#1, it is quite easy to generate a list of valid credit card numbers, as the numbering system is not a secret.  I&#8217;ll spare you the algorithm, but essentially, the only security built in is to help prevent the wrong card from being charged if the numbers are transposed &#8212; meaning that if you accidently swap the position of the 7th and 8th digits in your card number when buying something online, the transaction will decline, because the transpostion made the card number invalid.</p>
<p>If a site utilizes little or no precautions for verifying the billing address (read between the lines as &#8220;shady&#8221;), it is possible to charge a card without having any clue who it belongs to.  However, it is somewhat trivial for a savy criminal to do a reverse-lookup via a bit of marketing-database mining.  But I digress.</p>
<p>#2:  The reason for the false charges coming through online dating/matchmaking sites such as true.com is because this is a big money-maker for social-engineering adept criminals.  The following articles illustrate a good example, and a bit more detail on the subject&#8230;<br />
<a href="http://www.cbc.ca/canada/edmonton/story/2009/02/17/edm-dating-fraud.html?ref=rss" rel="nofollow">http://www.cbc.ca/canada/edmonton/story/2009/02/17/edm-dating-fraud.html?ref=rss</a><br />
<a href="http://www.scamtypes.com/what-exactly-is-online-dating-fraud.html" rel="nofollow">http://www.scamtypes.com/what-exactly-is-online-dating-fraud.html</a></p>
<p>If criminals like this can be likened to bacteria, and the internet to a body, the net is very sick.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Pmom</title>
		<link>http://www.chocolateandgarlic.com/2009/05/check-your-american-express-statement/comment-page-1/#comment-537</link>
		<dc:creator>Pmom</dc:creator>
		<pubDate>Sat, 09 May 2009 05:51:41 +0000</pubDate>
		<guid isPermaLink="false">http://www.chocolateandgarlic.com/?p=1591#comment-537</guid>
		<description>Lis, that is terrible!  But that explains a lot.  I was wonderlng, like Robin was, what the fraudster was going to do with hundreds or thousands of matchmaking site memberships.  I mean, once you pass ten . . . But this explains a lot.  

However, I still wonder exactly how they make a profit at this (and I hope I don&#039;t find out through personal experience).  Because if they buy something and have it shipped to them, then their address is known.  There would be no point in shipping it to me and they don&#039;t have my address anyway, right?  They could buy lots and lots of internet services, but how many Wall Street Journal and Cook&#039;s Illustrated subscriptions do you need?  

I am going to for sure keep an eye on my bill now.</description>
		<content:encoded><![CDATA[<p>Lis, that is terrible!  But that explains a lot.  I was wonderlng, like Robin was, what the fraudster was going to do with hundreds or thousands of matchmaking site memberships.  I mean, once you pass ten . . . But this explains a lot.  </p>
<p>However, I still wonder exactly how they make a profit at this (and I hope I don&#8217;t find out through personal experience).  Because if they buy something and have it shipped to them, then their address is known.  There would be no point in shipping it to me and they don&#8217;t have my address anyway, right?  They could buy lots and lots of internet services, but how many Wall Street Journal and Cook&#8217;s Illustrated subscriptions do you need?  </p>
<p>I am going to for sure keep an eye on my bill now.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Dynamic Page Served (once) in 0.280 seconds -->
