Live data from Hacker News

Deliveroo users are getting defrauded

newstatesman.com

21–30 of 354 posts

Re: Deliveroo users are getting defrauded

#21
this website makes it a point to make it as annoying as possible to disable all tracking. No option to disable all.

full article for whose whom want to read it but not be tracked:

Deliveroo users are getting defrauded – and it could be fined millions for it

Scammers are using the delivery service to clear out bank accounts, and the company’s response may be in breach of GDPR regulations. By Sarah Manavis Follow @@sarahmanavis Getty Images

On Friday morning, I woke up late, rushed to the tube, tapped in with Apple Pay, only to discover a few minutes later that my payment had been declined because I had insufficient funds. Figuring, “Well, it’s January”, I went to check my bank balance.

But rather than seeing an overspend or a direct debit I’d forgotten about, I saw three enormous charges from the food delivery service Deliveroo from the night before. They weren’t mine.

I immediately called Deliveroo to say that it wasn’t, in fact, me who ordered £100 worth of food in the space of ten minutes in three separate orders; and told them that the fraudsters had changed my email address, so I couldn’t even get into my account to look at where it was sent. I was told that they would investigate, and I would be sent an email asking for more information immediately.

I was not. After an hour, I rang again, to find that actually the email had been sent to the new email address – the one the fraudsters plugged in – so that they had presumably been alerted to the investigation. I complained, got the email re-sent to me, and was then met by radio silence for the rest of the day. When I eventually rang again, the company said it couldn’t actually tell me whether or not I would get my money back, adding that I might not hear from them for nearly a week before they let me know either way.

By 5pm, I was getting fed up, so I did what any journalist with a modest Twitter following would do, and tweeted. What I thought would happen was that my case would be bumped on the list, and maybe I’d get my money back sooner (or, indeed, at all). What actually happened was that my replies, DMs and email were all immediately flooded with people who had been a victim of the same fraud, saying, yes, this had happened to them too and no, Deliveroo had never refunded them. Of the roughly 40 people I spoke to, not a single one had been refunded by the delivery service; those who did get their money back had got it from their bank. The people tweeting the account claimed to have experienced fraud ranging from the low hundreds of pounds, like my case, to, in some cases, thousands. One person tweeted me to say that a friend of his was fraudulently charged £3,500 on his account. “Deliveroo offered him a £40 credit as a gesture.”

More shockingly, nearly half of these people told me that their cases were still technically “under investigation” by Deliveroo, some for over two months. Most of those who had been waiting for more than a week to hear about their case told me Deliveroo had simply stopped responding to their calls.

This problem is not actually new. In 2016, the Telegraph ran an expose of rampant fraud on the food-delivery service, and reported on customers’ shock at Deliveroo’s poor handling of the situation. The same day, a BBC Watchdog programme did a feature on Deliveroo fraud, in which Deliveroo claimed that “instances of fraud on our system are rare”.

But dating back several years, Deliveroo’s customer service Twitter account, @DeliverooHelp, has responded to claims of fraud nearly every day – often, in recent months, multiple times a day. They may represent only a small percentage of Deliveroo’s wider customer base, but it’s not at all obvious this is “rare”.

However, help for customers – and fines for the delivery service – could be coming from Brussels. Laura Irvine, a regulatory lawyer and Partner at Davidson Chalmers, tells me that Deliveroo may have breached the GDPR regulations introduced last year on multiple counts.

The General Data Protection Regulation (GDPR), which became European law on 25 May 2018, made sweeping changes to data protection rules across the EU: now, companies are more liable for protecting the data they hold on customers than ever before.

Irvine tells me that Deliveroo appears to have breached these regulations three times over. The sixth principle of Article 5, for example, requires companies to have “appropriate security in place to keep your financial and other personal data secure”, she notes. The firm also appears to have breached Article 32, “which provides more detail about what is expected in terms of data security – namely encryption, which appears not to have been in place”.

Lastly, there’s Article 34, which requires the “data controller” – that’s Deliveroo – to tell “anyone who may be affected by a data breach about it without undue delay. This applies when the breach is likely to result in a high risk of an impact on the individual. Getting your bank account emptied would, I suggest, meet that threshold.”

So what fines could Deliveroo face, if it were to be found guilty of these data breaches? “It could be millions of pounds,” Irvine says.

She emphasised that this is a big “could” – the millions of pounds they could be fined would be the upper end of the spectrum. But it is entirely possible, especially given the criticism the Information Commissioner’s Office (ICO) has faced for the small size of its fines in the past. “They were criticised for the small fine imposed on Facebook – £500,000 which was the maximum under the old law,” she tells me. “So I think they will want to use their powers. And they need to keep up with the other regulators,” she adds, noting that Google recently faced a €50m fine in France for breaching GDPR.

That said, there are some things that could spare Deliveroo from this fate: if, say, Deliveroo had told the ICO about the data breach within 72 hours, the threshold for fines would be lowered. But, Irvine says, the high volume of incidents and the reported response from Deliveroo suggest they aren’t informing the ICO of their data protection problems.

“They may blame other parties, but at the end of the day if you give them your data then they remain responsible – in most cases,” she says. “I am not sure how the bank would stop this.”

I put all this to Deliveroo. A spokesperson told me: “Deliveroo takes online security very seriously. Sadly fraudsters rely on the fact that people reuse the same passwords on multiple online services to try and gain entry to different accounts across the web.”

Ultimately, though, fines are not the only problems that data leaks of this sort pose to firms like Deliveroo. “Soon people will stop using companies based on how responsible they are with data,” she says. “Particularly financial data – but even your address being out there can be uncomfortable or dangerous for some people.” If she’s right, then this, for Deliveroo, could be just the beginning.

Midway through writing this story, I got my money back, by the way – and from Deliveroo itself. Other victims have not been so lucky.

Re: Deliveroo users are getting defrauded

#22

Perhaps worth mentioning, since it's nowhere in the article, that the first thing to do is not to spend hours on the phone with Deliveroo (or whoever else) but to call your bank to report the transactions as fraudulent and to block your card. That will probably get you a refund quicker (the transactions will likely be held until clarified) and will stop any further fraud. As for Deliveroo's support team... Not very g…

This is basically the sole "feature" of credit cards I value. Any time I'm buying something from somewhere that might act poorly, I use a credit card for the free leverage I have in a disagreement. Had an old phones screen repaired at a store inside a Walmart. They fixed it but half the screen had no touch capability. They were highly resistant to doing anything about it until I said I would just do a charge back. To…

I've started using privacy.com after I saw a post here on HN about it. It's pretty nice. Basically you link up your bank account and they create debit cards for any online vendors you use, and you can set limits, destroy cards etc. I usually put monthly / transactional limits. Like with Uber Eats I know I only spend x amount, if anybody tried to use my Uber Eats card for 100 USD it would decline it. But also it locks itself to the vendor you choose, so it can't be used elsewhere.

Re: Deliveroo users are getting defrauded

#24
post #15

Perhaps worth mentioning, since it's nowhere in the article, that the first thing to do is not to spend hours on the phone with Deliveroo (or whoever else) but to call your bank to report the transactions as fraudulent and to block your card. That will probably get you a refund quicker (the transactions will likely be held until clarified) and will stop any further fraud. As for Deliveroo's support team... Not very g…

Problem is most vendors will then block you from ever using their service again. Might not be such a big bummer, after all they're helping people steal your money. But here it was through Apple Pay, so it may have bigger ramifications to block the card.

> Problem is most vendors will then block you from ever using their service again.

Who is "most vendors" exactly?

Re: Deliveroo users are getting defrauded

#25
post #17

This is poor form from Deliveroo - their fraud detection seems particularly lacking, and fobbing customers off for months at a time is not good enough. However the article is unnecessarily sensationalist in banding around GDPR data breaches. Much of the article intimates there has been a Deliveroo data breach, whereas in fact the most likely explanation is attackers reusing passwords leaked from other breaches. This…

From this Deliveroo engineering blog post:

https://deliveroo.engineering/2017/09/05/improving-password-...

"Therefore, from today, we will be informing our customers when we determine that the password which they use for Deliveroo is publicly known in some way. We will contact the impacted customers to request that they change their password, and advise that they also change that password at other sites where it is also used."

Re: Deliveroo users are getting defrauded

#26
post #4

Earlier quoted context omitted.

From my experience with Deliveroo, you can pretty much order at any address, wait for the delivery person at the doorstep and retrieve your order without actually living there.

But what you going to do with 3 £100+ takeaway orders back to back? You can hardly resell it!

Probably something like this:

1) People pay the fraudster for "discounted" food.

2) The fraudster places the order using the stolen account.

3) The fraudster tells the people who paid them: "Go to the pub car park at 9pm and wait for the Deliveroo driver. If he asks, your name is John Smith."

4) Profit.

Re: Deliveroo users are getting defrauded

#27
post #12
post #10

I'm a bit confused, probably since I don't have Apple pay. Does it not use credit cards? It should then be very easy to dispute the charge with the bank.

I use Apple Pay with both my debit cards. This is in the UK.

I wouldn’t use my debit card for any purchases. More protections and less hassle using a credit card.

Re: Deliveroo users are getting defrauded

#28
post #6

I found Deliveroo sending highly detailed location information to a marketing company(Braze) yesterday[0]. I can't remember every giving explicit consent for this and AFAIK under GDPR just covering this in a Privacy Policy is not enough. On the topic of this story it seems like a case of credential stuffing so it's not a breach in Deliveroo's systems. Do the requirements as a "Data Controller" still apply in such as…

> I can't remember every giving explicit consent for this and AFAIK under GDPR just covering this in a Privacy Policy is not enough.

I don't believe Deliveroo is obligated to tell you who they send such information to. They are however obligated to tell you that they gather such information and, should they share it with a third party, ensure that said third party is GDPR compliant and sign a data processing agreement with them.

Deliveroo doesn't mention Braze directly by name in their privacy policy (https://deliveroo.co.uk/privacy), but they do let you know that they disclose "information they collect" to, among others, "Marketing and advertising partners".

They also mention in the same privacy policy that they "also collect technical information about your use of our services through a mobile device, for example, carrier, location data and performance data".

Braze themselves does appear committed to GDPR. That isn't especially surprising, it's a huge selling point for marketing companies towards enterprise customers. https://www.braze.com/product/data-agility-management/regula...

IANAL but I don't believe Deliveroo is in breach of GDPR. The best you can probably do is make a case that they do not have a reasonable justification to collect such highly-accurate location data for that particular use case, and should tone it down to, say, 5km instead of 1m accuracy. If you email dpo@deliveroo.com with such a request, there's a decent chance you could get the change done.

Re: Deliveroo users are getting defrauded

#29
post #15

Perhaps worth mentioning, since it's nowhere in the article, that the first thing to do is not to spend hours on the phone with Deliveroo (or whoever else) but to call your bank to report the transactions as fraudulent and to block your card. That will probably get you a refund quicker (the transactions will likely be held until clarified) and will stop any further fraud. As for Deliveroo's support team... Not very g…

Problem is most vendors will then block you from ever using their service again. Might not be such a big bummer, after all they're helping people steal your money. But here it was through Apple Pay, so it may have bigger ramifications to block the card.

I don't see a problem by being blocked from a service I would never use again anyways.

Plus the following dialogue: what was your name?...I am reporting you to xyz state attorney general's consumer fraud division is incredibly effective.

Re: Deliveroo users are getting defrauded

#30

Earlier quoted context omitted.

This is basically the sole "feature" of credit cards I value. Any time I'm buying something from somewhere that might act poorly, I use a credit card for the free leverage I have in a disagreement. Had an old phones screen repaired at a store inside a Walmart. They fixed it but half the screen had no touch capability. They were highly resistant to doing anything about it until I said I would just do a charge back. To…

I've started using privacy.com after I saw a post here on HN about it. It's pretty nice. Basically you link up your bank account and they create debit cards for any online vendors you use, and you can set limits, destroy cards etc. I usually put monthly / transactional limits. Like with Uber Eats I know I only spend x amount, if anybody tried to use my Uber Eats card for 100 USD it would decline it. But also it locks…

That's an interesting idea. But I find a far easier solution is to turn on notifications. I get an email on my phone within a minute of every transaction. It's really nice having that feedback loop.
Post reply on HN