I got hit again with fraud charges on my credit card again, so the old card is canceled and they are sending me a new one. It seems like I am getting a new card (and number) about every 6 months due to fraud charges of late. I think this most recent one and one about 6 months ago were online purchases through what look like are legit websites. My guess is someone has hijacked the site's payment process. I try to use paypal when I can but not all websites even legit ones offer it. Kind of annoying as I have a couple of automatic payments on the card so once I get the new card, I have to change the card number over with the merchant. I pay my balance off monthly and do charge a lot to the card as the cash back does add up. I avoid doing any automatic payments direct from my checking account as I do not have any fraud watch and ability to dispute charges with my bank like I do with my credit card.
Looking over the recent transactions, the fishy one went through about 4 days ago via a web purchase and then there was a flurry of activity yesterday for restaurant purchases in several restaurants around the country. At one of the restaurants someone tried rerun the card multiple times. My guess is the card number got resold on the dark web once the initial charge seemed to go through and multiple people bought the number and started using it.
So time to take out the backup card and wait a week for the new one to show up.
Looking over the recent transactions, the fishy one went through about 4 days ago via a web purchase and then there was a flurry of activity yesterday for restaurant purchases in several restaurants around the country. At one of the restaurants someone tried rerun the card multiple times. My guess is the card number got resold on the dark web once the initial charge seemed to go through and multiple people bought the number and started using it.
So time to take out the backup card and wait a week for the new one to show up.
Have a unique PIN for each debit card ( if you have multiples ). Use a tool like 1Password to manage your passwords ( >12 character preferably ) so you have can have a unique password for each web site. Some folks actually go as far as creating a unique login per site too. If you have a choice between using text messaging or Google Authenticator for MFA opt for Google Authenticator.