You've been hit. Mine had those as a forerunner to real charges. Wise move on cancelling.
Boomerang Video Ltd
12/1/2015
Following an initial enquiry at the end of last week, we have had a number of customers raise concerns regarding fraudulent payment attempts on their card details that are also registered with us.
We are fully investigating this issue and have temporarily removed access to our website while this continues.
We have contacted our Payment Provider Sagepay and our Merchant Bank World Pay and neither have any reported concerns relating to us.
However, please be assured we are treating this with the utmost urgency and can provide more information on our findings as they become available.
If you have any concerns, please contact your card issuer.
We apologise for any inconvenience the removal of our site has caused and thank you for your patience as we continue to investigate further.
Hadn't heard of boomerang rentals before.
Peaked my interests though, how's the service? Can you rent current gen titles on that £3.99 deal?
Read on other rental sites they don't offer current gen rentals 'till you're paying over £15.
Once all this fraudulent behaviour as tied over, would it be worth signing up?
It really isn't.
It's piss poor, but it's the only service left. Lovefilm wiped the floor with Boomerang.
Different experience to me. I can count on one hand the number of times in the 5 years I haven't got a new release game on day one.
Good afternoon Turnstyle,
Thank you for your email and sorry to read that you experienced fraudulent activity on your bank account.
Following an initial enquiry at the end of last week, we have had a small number of customers raise concerns regarding fraudulent payment attempts on their card details that are also registered with us.
We are currently investigating this issue and have temporarily removed access to our website while we investigate.
We have contacted our Payment Provider Sagepay and our Merchant Bank World Pay and neither have any reported concerns relating to us.
However, please be assured we are treating this with the utmost urgency and can provide more information on our findings as they become available, if you would like us to.
If you do have any concerns, please contact your card issuer.
We apologise for any inconvenience the removal of our site has caused and thank you for your patience as we continue to investigate further.
That was when they'd only had a couple of people mention it.I got hit yesterday with 2 transactions. One for £900 which they authorized and a second for £1200 which they blocked.
Card has been cancelled and now have to wait for card issuer to send a letter for me to sign before they give me a refund of the £900 back onto my account!
I can't believe how Boomerang are pretty much denying it too. I saw the reddit thread and then a day later my card has fraudulent transactions!
It's not a coincidence!
Yeah, there's multiple people reporting cards entered but inactive for years have been misused.I'd mentioned this to my parents yesterday as we signed up for the Boomerang free trial a few years ago, just found out they've now been hit. We haven't had any card details on the Boomerang site for around 2 years but someone still got them.
I'd mentioned this to my parents yesterday as we signed up for the Boomerang free trial a few years ago, just found out they've now been hit. We haven't had any card details on the Boomerang site for around 2 years but someone still got them.
Seeing what some people got hit for I'm lucky it was just a £20 Vodafone top up on my credit card last Friday. Barclaycard flagged it as suspicious and contacted me, which is how I got to knowing about this. Just waiting for the new card now.
Think I'll probably end up sending back the games I have and cancelling, but not until I can get on the site to clear my rental list. Cancellation will be accompanied by an e-mail demanding the complete removal of all my details from their system.
What happened
On Friday we were contacted by a customer who was concerned that a fraudulent charge had been attempted on his credit card, and he was worried that our system had been compromised. He quoted another person who had made a comment on Twitter of a similar issue.
What we did
We began an investigation as soon as additional concerns were raised. Credit card data is stored in a strongly encrypted format and not viewable to any internal staff, however, at that stage, we felt we should take the concerns seriously. Over the weekend, we noticed other people online reporting similar issues and we became increasingly concerned. So, based on the information available at the time and conscious of the concern, we made the decision on Sunday afternoon to take the site off line while we continued our investigations.
Where we are
By Monday morning, we had been contacted directly by a small number of additional customers. We contacted the fraud department of our merchant bank, but they knew of no issue. We also contacted our payment gateway provider and they also had no concerns. They are assisting us in a consultative capacity. By this time we could see lots of people talking about this online, but only a few people had contacted us directly.
To date we have not found any evidence of a breach of our systems. We are continuing to investigate and continue to take this issue very seriously. We have also made the decision to very quickly move over to a token method of payment which obviates the need to have encrypted data on our servers, to give our customers further reassurance.
We would not ever wish to be the source of customer card information being compromised, so are making this change urgently. This work will take about a week, and we have removed the card details in their encrypted form, from our online
system, and are removing the facility to update or provide card details until the work is complete. Subscriptions will be processed daily each weekday morning under further supervised controls. Once the new system is in place, we will be able to collect payments through the token system.
We will also investigate the possibility of introducing PayPal as a form of payment as well, to offer our customers further choice.
What next
First we will start to process incoming and outgoing rentals. Then, once we are satisfied that our investigations are complete, we will bring our website back on line so existing customers can see their rental lists. We apologise for the inconvenience caused to our customers while this work is undertaken. Once everything is running again, we will be back in touch and will include updates at that time.
Finally, we would like to re-emphasise that we have not found any evidence of a breach in our systems (our systems were regularly tested for vulnerabilities by a 3rd party specialising in this) but our Engineers and Technical Advisors continue to investigate.
We are aware of the interest and concern this situation has raised and care about our customers and our reputation greatly and are urging our customers to get in touch with us immediately if they have any concerns. We will shortly be sending an email directly to each of our customers.
Telephone: 01604 654140
Email: customersupport@boomerangrentals.co.uk
They can't find any evidence of wrong doing? hmmmmmm
"We also contacted our payment gateway provider and they also had no concerns."
Pro-tip: They should no longer be your payment gateway provider because theyre fucking reckless, shit, lazy, and seemingly clueless.
Cancelled my card last night just to be on the safe side. I tweeted them last night asking if I could cancel my subscription while the site was down and I got this reply.
I'm still amazed they haven't sent an email out to customers either. Their most recent statement says they will shortly but its been just short of four days since the first reported incident.
It would be very unlikely to be the payment processor. If it was the payment processor then there'd be thousands of people going 'my account and monies and blah blah blah!'."We also contacted our payment gateway provider and they also had no concerns."
Pro-tip: They should no longer be your payment gateway provider because theyre fucking reckless, shit, lazy, and seemingly clueless.
It would be very unlikely to be the payment processor. If it was the payment processor then there'd be thousands of people going 'my account and monies and blah blah blah!'.
How sure are you the flaw was in the system of the payment processor? They (boomerang) already admitted to storing card info, even from cancelled accounts, on their own systems - encrypted or not.
It would be very unlikely to be the payment processor. If it was the payment processor then there'd be thousands of people going 'my account and monies and blah blah blah!'.