Last month, I noticed a transaction on my Citibank Visa credit card that I didn’t recall making. It was for an event software solution so it was probable I could have made it, but on checking out the vendor’s website, I knew I hadn’t. I had never heard of it.
I then went over my statements more carefully and found another transaction on Agoda that I didn’t recall making.
I called Citibank to enquire about those payments. The customer service officer’s first question was, “Have you ever bought anything online?” I said, “Yes.” Her second question was, “Have you ever shared your CVV code online?” I said, “Yes. When you make an online purchase, you have to share that code. It’s part of the payment process with any website.”
She then said something like “well, if you have done that, then it’s possible your credit card may have been used by someone else.”
In other words, it’s your fault, not ours, who asked you to share that code? (Incidentally, in my second follow-up call, when I was asked the same question again, I asked the officer if he had ever bought anything online and he said no.)
I was then told that I had to contact the vendors directly for refunds. When I said shouldn’t it be the bank’s responsibility, she said no. She said I could have my card cancelled and they could issue a new one.
The query to the first vendor remains unanswered to this day. Agoda responded very promptly and told me that their investigation revealed that the transaction had been made on a “whitelisted account that hadn’t been used for 2.5 years and it looks like it went ‘bad’.”
It added, “A full refund has already been completed on our side …”
True enough, I found the amount credited to my account in this month’s statement. So kudos to Agoda for its prompt action.
I followed up with Citibank via email to update them on the situation and to suggest that they should investigate as to how my credit card was used for the Agoda transaction, given that I now had a response from the vendor. I thought they’d be interested.
Instead, I got this email. “We wish to inform you that, we will not be able to stop, cancel or reverse the charge from the merchant, as Citibank is obliged to honour and pay, on your behalf, all charges presented by the merchants through their processing bank. Therefore, would advise you to contact the merchant directly to request them to cancel the deduction.”
“If there are no response from the merchant, please complete the Cardholder’s Letter of Dispute, available for download and print at …”
It then explained the procedure and concluded, “Upon receipt of your signed dispute letter specifying the reason for dispute, we will review the case and proceed to initiate the investigation process if appropriate and raise the appropriate adjustment to your account.”
The rational side of me understands how a bank would want to cover their backside in such cases, but the emotional side of me asks, am I not supposed to trust them to keep my credit card details safe and if something bad happens, shouldn’t they at least show some care and reassure me that everything’s being done their end to ensure it doesn’t happen again?
In any case, the rational and emotional side of me have decided to cancel my Citibank Visa credit card because I have lost confidence in them.
Fraud is a serious issue holding back consumers from making online purchases. This incident has certainly made me more cautious and I know I am not alone. The 3D secure feature where banks require you to enter a PIN sent via SMS does give a certain sense of security but I am sure it’s not foolproof.
Discussing this matter with someone in travel e-commerce, he tells me it’s also a major issue for them because when a “false” transaction is made, he has to pay the full refund to the customer disputing the transaction. So even though he may only make 10% commission from the transaction, he has to refund 100% because the bank says it is not their responsibility. He also has to pay merchant fees to his payment provider when fraud charges occur, and that most of these are with stolen credit cards.
Last month alone, he said he had to make $45,000 in refunds.
So my question is, if not the bank’s, then whose responsibility is it to ensure both vendor and customer are protected from syndicates operating off stolen credit cards? The rational side of me thinks it should be those who issue credit cards. What do you think?
Clearly though, this is a big problem that needs to be solved if we are to see e-commerce take off fully in our region.