Australian retailer's payment portal compromised, resulting in $6,000 in losses

In the digital age, the convenience of online shopping is undeniable. With a few clicks, we can have everything from the latest gadgets to our weekly groceries delivered to our doorstep.

But this convenience can come at a high price, as one Australian shopper discovered after a retailer's payment portal was hacked, leading to a staggering $6,000 in fraudulent charges on his credit card.


The incident has left many Australians questioning the security of their online transactions and the responsibility of retailers to protect their customers' sensitive information.

The breach, which went unnoticed for an entire year, has exposed the personal data of countless customers, leaving them vulnerable to financial theft and fraud.


1734403631192.png
An Australian retailer's payment portal was hacked, exposing customer data and causing $6,000 in fraudulent charges on one card. Credit: Depositphotos


Steve, a Melbourne man who fell victim to this breach, shared his frustration and disbelief.

He had purchased a kettle from an online electrical retailer, Stan Cash, using his credit card—a card he had never used online before.

Shortly after, he awoke to a nightmare scenario: his card had been used for unauthorised transactions, including flights, food delivery, and international purchases, totalling around $6,000.


The recovery process was long and arduous, with Steve having to wait for pending transactions to clear before his bank could take action.

When Steve finally received communication from Stan Cash and its sister store, Billy Guyatts, the response was underwhelming.

The email advised customers to remain vigilant for suspicious activity on their credit cards but offered no apology or compensation for the breach.

‘We recommend you remain alert for any suspicious activity on the credit card you used to make the purchase. If you see any suspicious activity, you should contact your financial institution,’ the email wrote.

‘Stan Cash and Billy Guyatts do not store payment details, and no customer account passwords have been compromised in this breach.’


Steve's attempts to seek acknowledgment and support from the retailer were met with silence, adding insult to injury.

‘I was just angry as I just thought there is no apology, and they were palming off the blame to a third party—that was pretty poor,’ he said.

‘I thought, at the very least, they could have replied to my email and acknowledged it. But they just brushed their hands off it,’

‘It’s such a horrible feeling having fraudulent transactions, especially when it’s a big number like that. It’s your money and your savings, and someone has helped themselves with it.’

The parent company of Stan Cash and Billy Guyatts, BSR Group, expressed regret over the incident and assured that steps were taken to notify affected customers and remediate the breach.


‘After thorough forensic IT investigations, BSR determined the risk period and then took immediate steps to notify and communicate with the potentially impacted customers, whilst simultaneously taking all reasonable steps to remediate the breach,’ a spokesperson for the BSR group said.

‘We promptly notified the OAIC and the Victorian Police and assisted customers who reported potential fraud to be contacted by the Victorian Police who were investigating the incident.’

They also reported the breach to the Office of the Australian Information Commissioner (OAIC) and the Victorian Police.

However, details on the number of impacted customers and the extent of the data accessed were not disclosed.

The OAIC confirmed that BSR Group had complied with the Notifiable Data Breaches scheme.

‘Under the Notifiable Data Breaches scheme, any organisation or agency the Privacy Act 1988 covers must notify affected individuals and the OAIC when a data breach is likely to result in serious harm to an individual whose personal information is involved,’ a spokesperson stated.
Key Takeaways
  • An Australian retailer experienced a hack of its payment portal, resulting in the exposure of sensitive customer data and $6000 worth of fraudulent transactions on one customer's card.
  • The breach was disclosed to customers via email, alerting them that their personal information, including credit card details, could be at risk.
  • The customer, Steve, expressed frustration with the retailer's lack of apology and accountability and had to endure a stressful period of rectifying fraudulent charges.
  • The retailer, owned by BSR Group, notified the Office of the Australian Information Commissioner (OAIC) and Victorian Police and claimed to have taken steps to manage the data breach, deemed compliant by the OAIC.
Have you ever been a victim of online fraud, and how did you handle it? Share your experiences in the comments to help fellow members stay safe.
 

Seniors Discount Club

Sponsored content

Info
Loading data . . .
I’m not going to get caught like this, I go into the shops and buy what I want with cash. No waiting for delivery that I hear often get stolen. I can check the quality of the goods before I purchase, I can check the sizes and keep dockets for an easy refund if necessary. I’m not risking my savings, I worked to hard for what I hav.
 
It must have been an employee who used the card details, so why wasn't that person charged?
 
  • Like
Reactions: PattiB
I always buy online with PayPal and never had a problem. Anyone who gets caught like this is just unlucky.
And I've never heard of this shop anyway.
 
  • Like
Reactions: Kaylee and deni67
I've never heard of this company. It's very unlucky that the company got hacked at the same time customers bought something. Perhaps being a small business, they didn't have enough security with their payment system. It's good that they called the police.
 
  • Like
Reactions: DEL boy

Join the conversation

News, deals, games, and bargains for Aussies over 60. From everyday expenses like groceries and eating out, to electronics, fashion and travel, the club is all about helping you make your money go further.

Seniors Discount Club

The SDC searches for the best deals, discounts, and bargains for Aussies over 60. From everyday expenses like groceries and eating out, to electronics, fashion and travel, the club is all about helping you make your money go further.
  1. New members
  2. Jokes & fun
  3. Photography
  4. Nostalgia / Yesterday's Australia
  5. Food and Lifestyle
  6. Money Saving Hacks
  7. Offtopic / Everything else

Latest Articles

  • We believe that retirement should be a time to relax and enjoy life, not worry about money. That's why we're here to help our members make the most of their retirement years. If you're over 60 and looking for ways to save money, connect with others, and have a laugh, we’d love to have you aboard.
  • Advertise with us

User Menu

Enjoyed Reading our Story?

  • Share this forum to your loved ones.
Change Weather Postcode×
Change Petrol Postcode×