> They can also be used for money laundering, as a result.
Story time:
So, back in 2009, I'd just started working at Starbucks and my first job was to figure out some reporting discrepancies in online purchases of Starbucks cards. Basically, a report from the database on how many $$ of cards we'd sold didn't seem to match up with a transaction volume report from our credit card processor. And, as the new guy, I got stuck digging through stacks of classic ASP, layers of SQL Server stored procedures, and even some really old mainframe that I can't remember the model of. It was important to the business to figure out why these reports didn't match up, but it wasn't exactly a fun assignment that engineers were leaping onto.
Anyway, I eventually figured out that it wasn't a reporting error— we were truly "selling" more $$ in Starbucks cards than we were charging for. I dug through the whole process to see how this was possible, and found what it is still one of the most hilarious bugs I've found in my career.
When you got to the checkout form to buy a Starbucks card in any denomination, you had to fill out your credit card information. If anything you filled out didn't validate or we couldn't authorize your card, you would get an error message. It would ask you to correct the credit card information and resubmit the form. But, crucially, you didn't actually have to correct the information. You could just resubmit the form with anything you wanted, and some spaghetti logic determined that since validation & credit card auth had already been run once, it didn't have to be run again! Instead, we just created an order to ship you the product and didn't bother charging your card at all.
This bug was "leaking" probably over $100K in cards each year, for who knows how long. I still wonder if anyone actually figured it out and was exploiting it. It wasn't even "laundering" money, it was wholesale minting it.
The best part was a few weeks later, long after we'd fixed the bug. Someone from the IT security team showed up at my manager's desk with a lot of questions and pretty ready to walk "the new guy" out, and possibly press charges.
Turns out, while I was troubleshooting the bug, I'd accidentally submitted some absurd order. Something like 100 Starbucks cards, each loaded with $200 or whatever the maximum was. I guess I'd submitted it in production instead of the QA environment, and because of this bug, the order had actually gone through without charging me. It was a large enough order that it triggered a manual audit, and someone was pretty sure that I was just stealing from the company.
Talking them down was fun times, since they were pretty serious about the whole thing while my whole team was just cracking up :)