Security News > 2020 > March > Boots yanks loyalty card payouts after 150K accounts get stuffed

Boots yanks loyalty card payouts after 150K accounts get stuffed
2020-03-06 10:53

Boots, a UK pharmacy chain, has suspended payments on the loyalty cards of 14.4 million active customers after its security team spotted "Unusual" activity on a number of Boots Advantage Card accounts.

If Boots wasn't hacked, then where did crooks get the credentials that they've evidently used to try to get into people's Advantage Card accounts so they can make fraudulent purchases on what we refer to in the States as "Somebody else's dime?".

This removes the ability for people to attempt to access any Boots accounts, but means that customers will not be able to use Boots Advantage Card points to pay for products in store and online for a short period of time.

After the investigation does reach a final number, and if the final number of affected accounts turns out to be anywhere near the small percentage Boots is now estimating, it will mean that millions of customers have been locked out of their loyalty points due to a tiny minority who haven't made it a priority to protect their online accounts.

Don't dismiss accounts that "Don't matter."Boots' shutdown of its Advantage Card shows that there really isn't such a thing as a "Low-value" account.


News URL

https://nakedsecurity.sophos.com/2020/03/06/boots-yanks-loyalty-card-payouts-after-150k-accounts-get-stuffed/