36
Heartland Vapes CC info possibly compromised.
submitted about 5 years ago by _nines

I'll post the message I sent to them. This isn't a "torch and pitchfork" type post, this stuff happens, just an FYI to keep an eye on your CC statements if you've made an order through them. > This is purely for information, no finger-pointing or denigration meant. Whatever system (or 3rd party) you're using to store credit card data seems to be compromised. My last order through you was approximately 10 weeks ago (05/02/20), using a Privacy.com virtual credit card. That card is tied to only this merchant, it can't be used anywhere else. > > This morning (07/19/20) I was notified by Privacy.com > "$0.00 charge at AIRBNB INC declined on your Heartland Vapes card because it was already in use at HEARTLAND VAPES LLC. Cards can only be used at a single merchant."
> > Someone has accessed the virtual card data and appears to be testing it. There is no area in my account details where the CC details are available, so this isn't a simple compromised account. This wouldn't be a Privacy.com compromise, because beyond that account using 2fa, if they were in that account they would have my actual credit card information.

Comments
Sort
13 points
 
by HisPerceptionWarpsabout 5 years ago

If they respond to you, could you post an update?

Actually, wait, I changed my mind. If they DON'T respond to you, post an update. That would be far more disturbing.

6 points
 
by nebben11about 5 years ago

Not surprising, happened to me a few years back on a new card that only had 2 transactions(McDonalds and Heartland), the bank caught it due to them buying a train ticket somewhere in the EU!

4 points
 
by kuri_sanTouabout 5 years agoDiketones, Schmiketones

That reminds me, it’s been some years but I got a charge like that for two tickets for a movie and some popcorn, lol. Some place in the USA. I live in Japan

2 points
 
by 2020JD2020about 5 years ago

Samurai war screaming intensifies

1 points
 
by ivertrioabout 5 years ago

Shit, I ordered from them just last week. Thanks for the heads up.

1 points
 
by Cheflavacabout 5 years ago

Thanks for the heads up!

1 points
 
by SigmaLanceabout 5 years ago

How did this turn out?

1 points
 
by _ninesabout 5 years ago

Haven't heard anything yet.

1 points
 
by Philosaphuckerabout 5 years agoWinner: Best Recipe of 2016 - Grack Juice

Took a look on built with.com and got some evidence for my hunch. Heartland vapes is built on Magento e-commerce CMS. There is a known exploit in Magento that keeps getting recycled as it updates which grants the actor access to the database. The attackers are able to create a credential that will allow them to access those stored details at will. I don't have causal evidence, but this shoe fits pretty well: https://community.spiceworks.com/topic/2281679-snap-magento-s-backdoor-edge-updates-g-suite-security-features-sunlike-star?source=start&pos=21 I'm pretty sure ECX had a similar problem in the past.

1 points
 
by Twitchy993about 5 years ago

Just cancelled my card... Airbnb charge. I don't have a dedicated card for heartland so can't be sure but remembered seeing this post. Headed to check out Privacy.com now

1 points
 
by CommanderChrichtonabout 5 years ago

Thanks for the heads up - my card was recently compromised and could not figure out really how since I am pretty careful. This now adds up.

Site copyright © 2025 DIY Compendium. Data courtesy of Reddit.