U.K.-based Boomerang Rentals are thought to have had the card details of some of its customers compromised, leading to fraudulent transactions on some user’s accounts.
Last week, queries were made to Boomerang by concerned customers regarding irregular payments on their cards after some traced a link back to the company. At the time, Boomerang denied any responsibility and posted this on Reddit in response to the concerns.
"On Behalf on Boomerang
We take security of card details very seriously and we are compliant to the latest PCI compliance standards.
The payment card details that we store, are all encrypted, even employees cannot see a customers full card number. We do not accept card details over the phone.
Furthermore, we don’t store all the card details on our systems. For example we don’t store the 3 digit security code or the bank security code i.e. Verified by Visa or MasterCard Secure.
All this means it is very unlikely someone could retrieve your card details and as we mentioned in our individual replies, and even if they could break the encryption, we physically don’t store all the details a fraudster would need to make a purchase from a legitimate site with reasonable security measures.
The O2/Vodaphone fraud problem has been ongoing for a number of years, it would seem. While we aren’t able to comment on these companies fraud prevention methods, it seems unlikely that they would accept purchases without at least the 3 digit security number being provided at the time of purchase.
In fact, they would be required to ask for the 3 digit number and verified by Visa/Mastercard Secure, to maintain the required level of payment card security.
As to the source of the fraud, there are many ways fraudsters can obtain an individuals card details and so it is more likely that your card details were obtained via other means.
Please contact us directly if you would like further information."
Then, on Sunday, Boomerang’s website went down for maintenance before going fully offline and has continued to be so ever since. The company released the following statement on Monday morning via Facebook.
"Following an initial enquiry at the end of last week, we have had a number of customers raise concerns regarding fraudulent payment attempts on their card details that are also registered with us.
We are fully investigating this issue and have temporarily removed access to our website while this continues.
We have contacted our Payment Provider Sagepay and our Merchant Bank World Pay and neither have any reported concerns relating to us.
However, please be assured we are treating this with the utmost urgency and can provide more information on our findings as they become available.
If you have any concerns, please contact your card issuer.
We apologise for any inconvenience the removal of our site has caused and thank you for your patience as we continue to investigate further."
User accounts that were compromised had a variety of charges against them including phone top-ups, plane tickets and retail outlet spending sprees that ranged from £50 to over £1000.
So far, banks have been mostly sympathetic of those affected and refunded any fraudulent charges. The general advice for anyone who has or has had a Boomerang account – even if it is just signing up for a free trial – is to scan through your recent transactions for irregularities and contact your bank so you can be refunded and to cancel your credit or debit card associated with your account should you have been targeted.
Sadly, I speak from personal experience on this story. I have my card details on record with just two companies and Boomerang is one of them. This morning It was found that two fraudulent charges had been made on my account totalling nearly £400. Thankfully, the bank has understood and refunded it. PSU has reached out to Boomerang for further comment on the situation.
UPDATE: 19:34 01/13/15
Boomerang released a statement this afternoon in response to customers concerns.
In this statement, they continue to refute any link between the acts of fraud and their collected data, yet they also go on to say that future payment methods will be revised and that all card details on their system will be deleted. You can read their statement in the link below.
