Coles $250 Mastercard - Various Fradulent Transactions ie Healthy Massage

We purchased several Coles $250 Mastercard during the 10% off promotion (which usually occurs in Feb, Jun and Oct)

As we have seen on previous posts, people have mentioned how the balance of their cards were drained by scammers and its been suggested not to stock up too much and to use them as soon as possible etc

Recently when going to use a brand new 1x $250 purchased in the June 2022 promotion, I noticed the entire balance was drained to the last $5.00 - with numerous purchases from different merchants (one was used for $215 by HEALTHY MASSAGE)

It is also noted that you would enter all the card details when checking your balance (card number, expiry, CCV) which can create security risks

Called the customer service line today who seemed very unhelpful and was told that I would need to "raise with the merchant directly" However on further prompts, they took my details and said they would email a dispute form

Just wanted to check whether others have had similar issues with the new Coles $100/$250 Mastercard

UPDATE: Called Customer care per number on back of card. Call centre appears to be based in Philippines. 1st lady spoke to said they will email me a dispute form which will arrive in 24 hrs.. After waiting 24 hrs, called to follow up the dispute form but told something completely different. No dispute form yet as there are some "pending" transactions

*****UPDATE 31/8/22***** Called Heritage Banks complaints team Mon 29/8 after getting nowhere. Have since heard back from Heritage Bank who advised they are aware of the fraudulent transactions most notably from this Happy Massage and several others which appears to have effected multiple cards.. Was advised they will send me a replacement card

Unauthorised charge as follows:
HEALTHY MASSAGE $218 posted
Several 2 or 3 small charges still pending

Related Stores

Coles Financial Services
Coles Financial Services

Comments

  • See the deal thread, some have already reported seeing their cards hacked.

    Hopefully Heritage Bank will do the right thing and compensate those affected

  • I haven’t had this issue with any of my Coles Mastercard gift cards (or any of the Coles Gift Mastercards or any other prepaid gift card), although I only have a couple of Coles Mastercard gift cards left.

    I’m quite confused and surprised by the customer service’s response, because:

    • Clause 14 of the Cardholder Agreement quite clearly outlines your rights in terms of transaction disputes (as long as your dispute is within Mastercard Scheme Rules, which yours appear to be).

    • If you went directly to a merchant to dispute a transaction, the vast majority of the time you will be told to talk to your card issuer to dispute the transaction.

    If you are not getting anywhere with Heritage Bank, you can also complain to AFCA (which is also mentioned in clause 14).

    • +1

      Thank you @wookiemonster for this helpful response. I'm being getting a bit of a run around from the call centre. The first lady i spoke to said theyll email a dispute form.. when calling to chase up the dispute form, was told there is no dispute form but to wait for a week for the pending to post before calling again

      Appears to be based in Philippines.. so frustrating

      • +1

        Heritage Bank has a complaints email ([email protected]) outlined in clause 14 as well, so if you want to get the dispute form faster (and also complain about the general unhelpfulness of the staff on the phone line), that may be an option. I've previously sent an email to that address and got a helpful response the next business day.

        Keep in mind that the staff you are calling are probably actually InComm staff, not Heritage Bank staff.

        • InComm owns and operates the Coles Mastercard gift card (and similar versions of this gift card are issued by other financial institutions in the USA, which probably explains the use of an American accent and American terminology on the phone line). As the owner and operator of the scheme, InComm collect and manage any personal information and/or transaction information associated with a gift card.

        • However, Heritage Bank acts as a service provider to InComm and carry out the financial administration associated with a gift card, but they do not have access to the personal and/or transaction information.

        • +1

          Thanks wookiemonster. I'll try heritage bank again. I actually called them this morning and the lady I spoke to (Australian, QLD based) said Heritage doesn't deal with these cards anymore and then proceeded to provide me with the same 07 number per the back of the card. I explained per the above I've been getting nowhere then she proceeded to give me Coles gift cards number.

          Not sure why we are being made to jump so many hoops and being bounced around like this just to get your money back.

          I'll try Heritage again tmrw and also send an email. Thanks again for that helpful info

  • +4

    So much effort and potential financial loss all for $25.

    Pass.

    • Yep, I bought some but only for immediate use (ie completely spent on bills once home)

    • 👍

  • +3

    Moving forward I'd suggest only buying to the amount you know you'd be using within a relatively short period of time to minimise hacking risks.

  • curious, does heritage bank allow you to lock the cards or are they just as insecure as before?

  • small savings or even better no savings for a massive headache!

  • +1

    I would like to know what merchants and for how much each was?

    • +1

      Hi steven6 there was a $218 charge from a HEALTHY MASSAGE. On googling this business, appears the business is located in Merrylands Sydney.. And there small $5 transactions as well pending, one which I think is similar from the thread posted by another user who got hacked.

      Interestingly, there are 2 posts from this massage business that says their credit card details were used???

      • HEALTHY MASSAGE

        Albo or Shaquille?

  • +1

    Why do people still insist on doing the whole gift card thing. The risk/reward ratio is terrible.

  • How do cards get "hacked" or how do scammers get hold of the details so easily - out of curiosity?

    • They can easily work out the carn numbers and expiry. They can only use them on sites that don't require you to enter the CCV. if all online sites required CCV, then their game would be up.

      • +1

        No, they can't "easily work out the card numbers & expiry". Otherwise, everyone would have fraudulent transactions on their cards all the time.

        Typically, card details get hacked because of bad data security by merchants & financial institutions.

        Just looking at the front page of the new website for checking the gift card balance shows that it was a total bodge job. It goes by default to a US site, and the Aussie site has grammatical mistakes such as "Debit Mastercard are accepted in the Australia".

        The developer might have left a backdoor open by mistake, which allowed hackers to get in & grab card details. It could even be an inside job with a developer deliberately copying the details.

        Alternatively, if Heritage Bank are incompetent enough to hire such cowboys to design their websites, then they may be similarly incompetent in other aspects of their internal data security, and the card details were somehow grabbed by hackers from their systems.

        • +1

          Hi thanks for sharing this, i feel where u check your balance using your card details inc cvv etc is a big security risk.. they should change it

        • Card schemes must be PCI compliant so this is not how they do it.

          Anyone with a LUHN calculator can make up a valid range of 10,000 card numbers with the gift card bin, the expiry which is the same on most cards in store, and off they go.

          This is how they do it…

          • @singingwolf: They won't be able to do it if the merchant process transaction with CVV.

            There is multiple fraudulent transactions worth thousands of dollar which means this Healthy Land Massage is a really questionable business.

      • 👍

  • Have luckily used most of my $100 card balance,

  • Maybe you can contact the massage place. To have used your card, they probably paid online so the vendor might have their email address. If the thief has used the massage, then there might be CCTV footage of them or even their contact number.

    Obviously they won't give the info to you but it might be worth getting the police involved if they exist.

    I'm assuming the massage place isn't in on the scam.

    • Hi there, I googled that massage company and it appears they are based in Merrylands Sydney. Surprisingly there were some reviews left there by people claiming the venue had illegally charged their card.

      I'm just baffled how this could have happened. I suspect it may be due to the way u check your balance, that is you have to enter all numbers expiry ccv etc or per what others have been previously saying that scammers can easily guess the numbers etc…

      • What you're suggesting implies that someone has hacked your computer/ internet connection and managed to capture all those info that you entered when you checked the card balance. If that is the case, you've got a much bigger problem on hand than the $245.

        What singingwolf suggested seems to be more plausible.

      • Doubt it is from the way you check the balance. I have never used my card (just opened it today) and found that the balance of $208 was used 2 weeks ago at HEALTHY LAND MASSAGE.

        I suspect it is because there are certain merchants that allow card transactions to be processed without the CVC code. As such, without this code anyone can pretty much guess the card numbers (as long as it meets the checksum) and the expiry date.

        • Hi jasper thanks for sharing. Heritage bank is aware of the fraudulent HEALTHY massage transactions that is effecting multiple cards .. Pls report your card to them

  • +2

    I checked all my cards. A word of warning don't do more than 10 cards on one ip address as you'll get blocked from checking cards. I got a charge for The Baltimore Abortion Fund. It's less than $10. Maybe I'll just leave a 1 star review.

    • +2

      Use that card ASAP. The $10 could have been a test transaction.

      • I ended up lodging the dispute packet. Never heard anything back. Checked the card after a few well and the funds had been reimbursed. I spent the balance promptly.

        • What's the dispute packet?
          I called the number mentioned on the website where we check balance and they asked me to send front and back of card along with my ID and created a dispute for me
          Is that all you did as well?

          • @jimmy1593: It had a form to fill out and send back. It was all via email.

  • One of my cards also had a charge made at 'HEALTHY MASSAGE' for $208 on 19 August

    • Hi jasper, i have since being contacted by Heritage Banks complaints team who advised they are aware of this fradulent Healthy Massage transactions which is effecting multiple cards. They are organising a replacement card for my one. Pls contact Heritage Banks complaints team to report your card and also monitor the balance for other unused cards you may have incase

      • Hi rockybalboa,

        I have several cards charged byt the Healthy Land Massage too !!!
        What is the contact number of the Heritage Banks complaints team, please?

  • +2

    $218 for a massage? i hope that included a happy ending

    • Should be a full service at that price.

  • One of my cards was hacked. Merchant is HOUSTON TRADING COMPANY.

    • Seems its effected a lot of cards.. hope yours was only a small amount?

      • No, an amount close to $250. It was settled yesterday. Maybe a new start.

  • just wondering if anyone received a confirmation email from InComm after seeing the Dispute Packet form?

    It has been 2 weeks now since I sent the email.

  • Another unauthorised transaction from another card. $2.53 - SERVERBLEN. Called Heritage last week again, they said someone would contact me but no one had called yet. These crooks (ง'̀-'́)ง

  • One of my cards also had a charge made at 'HEALTHY MASSAGE' for $98 on 26 August 11:05 pm.

    • +2

      no happy ending for that customer!

  • +1

    Someone use my card at yuanda farm inc. $71.43

  • OP, thanks for posting, very useful for people.
    Did you happen to receive your replacement card/s?

  • Thanks for posting, may I ask did you receive the refund or any replacement card?

  • what's the number of Heritage bank complain team?

  • all the impacted card has been registered with PIN?

  • Could anyone advise the contact details of the Heritage Banks complaints team, please?

  • Hi all, pls see Section 14 on the packing slip which lists a number for Heritage Bank complaints team - 1800 797 799 or from overseas 07 4690 9000

    • Many thanks rockyballoa. It is good to post the contact number here so others can save times and follow the same path and hope to provide more information to the bank. Thanks again.

  • Still waiting for refund. It's been 70 days.

    • Is this resolved for you?

      • They said they will send a replacement card 2 weeks ago. Still waiting for that.

  • Hi, I only opened the card now and also realise that I had been scammed by healthy land massage
    . Will be grateful if I can be given advise on how to go about this. Did u all manage to get the refund?

    • Lodge a claim. Hopefully you get a happy ending.

      • Hi Jim.
        Is there a form to raise the claim? Thx

  • Opened one of my cards today bought in July promotions last year and found 218$ been used on happy massage
    Lodged a case, not sure what way it goes
    I still have 8-10 cards with me and now am scared to even check the balance

  • Opened a card today, found it got hacked by someone who spend $240ish on TikTok on 1 Jan 11:16pm
    called Heritage Bank, they say they don't deal with this card, all the can do is to help me to lodge a complaint email to Incomm.
    And I did so.

    After that I called the number at the back, waited for 30 mins
    they collect my personal details, give me a case number and says they will send me a claim form within 5 business days by email
    and it will take 45-90 days to resolve.

    It's just a shame that they have done nothing to improve their system after so many fraud transactions.

    • When did you buy that one and when was it charged? I am assuming there would have been a breach for the July batch cards

      • This one was purchased in Jun 2022. hacked on 1/1/23.
        I've used at least 200+ Coles prepaid / vanilla cards over the last 2 years
        and this is the only one got hacked.

        I used to get 40x$250 cards during each 10% off promotion
        probably won't get as many this year, not because of the security breach,
        but because term deposit interest rate is now around 4.2% p.a.
        which means the actual savings for these cards has dropped from 7.5% to around 3.25%
        not worth stocking up large amount anymore.

        • Yeah it's the July batch I believe then that's impacted

    • +1

      Just an update:
      I received a call today (30/1/2023), the gentleman says my claim is finalized and he will post a new card to me this afternoon.
      It should take a week or so to reach my letterbox.

      I'm surprise how quick they processed my claim. only took them 6 business days. :)

      • Did you had the purchase receipt?

        • yap, photos of Coles receipt & original gold package back + front provided.
          And I've received my replacement card on 2Feb

      • Thanks for sharing your experience. Just lodged a claim yesterday for x2 $250 cards that had been compromised.
        The new card they will be posting to you will be for the full amount of the original purchased gift card I assume?

        • +1

          I didn't spend a single cent from the old card so I got a brand new $250 card.

        • +1

          $98 was fraudulently charged in my card. They sent me $100 gift card. :)

      • Hi I just had my first experience of a hacked card. Did you happen to still have the complaints form to fill? (I can't get through on the phone)

        • You need to obtain a case number by phone before filling the form.

Login or Join to leave a comment