BoA Visa Debit/Credit Hacked 4 Times Due to Consumer to Merchant Data Exchange
Last year, my Bank of America Visa Debit/Credit card account was used for restaurant delivery purchases four times by DoorDash hackers. The restaurant locations were in three different states.I have never had a DoorDash account. Each time I discovered the transaction in my account, I reported the transaction as unauthorized and followed up with a phone call to BoA customer service, consumer security. Each time BoA insisted I cancel that card and have them reissue it. Each unauthorized transaction happened within a month to six weeks of the issuing of the new card with new account #. The first time it happened I wanted a root cause and was told I would have to contact DoorDash. DoorDash could not provide me any information as I did not have a DoorDash account.The second time it happened, the Bank volunteered it could block "DoorDash" from charging any of my accounts. Third time, they insisted somehow my smartphone security must be breached. That time, I noticed that the merchant name on the transaction line was "DD" not "DoorDash" which I learned from the rep was an allowed data exchange shortname. BoA replied that they would also block DD. The fourth time it happened about 3 weeks after that card had been reissued and received! This time I escalated to the highest consumer security rep. Not sure how high as this person didn't seem to have much more knowledge than the others. I was very angry, asking how the bank could allow this to continue to happen and if they could they investigate the actual hackers and have them arrested. They said they don't get involved with investigations and that I should file a report with my local police. Since these crimes occurred in other states, I asked if that would be the FBI's purview. No answer. I learned from this rep that she really didn't know, as far as she knew the bank has never pursued criminal legal action in cases like mine. I threatened to close all of my accounts and transfer funds to another bank and got further escalated to a security manager. Finally, this rep speculated it could be a systemic issue. She told me every time a credit or debit card is reissued by the Bank and Visa, the account data and the new card's number is automatically transmitted to all partner merchants, which I assume could be any business that accepts Visa cards. I believe this to be true because one app allowed me to continue making purchases without updating my new debit/credit information--Starbucks. I also mention Starbucks because the DoorDash hacks started shortly after I signed up for the Bank's Starbucks new customer promotion. I have no means of proving my speculation of where this data leak is occurring but it feels more than coincidental. Here's the kicker. I worked for Bank of America for 5 & 1/2 years as a contractor. Quarterly, I had to take their mandatory cyber and infosec security education with exam certification, including regulatory, consumer and data protections, anti-fraud, etc. PPI sections include the bank's absolute adherence to never disclosing or sharing the consumer/customer's personal or financial data without the consumer's complete notification and authorization. I did try to take my complaints up with other bank security departments, I had two emails for reporting. But, the response I got was to continue working with the consumer security people. Anyway, I am not sure whether this auto transferring of PPI and card data to merchants is done by all banks and all credit card companies. Has anyone else experienced this type of unauthorized account use? Does anyone know which banking regulatory agency I should share these incidences with? Whether it caused my hacks or not, any auto sharing of consumer personal and financial data should be banned and better protections are required.