S

Saturday, July 22nd, 2023 4:24 AM

Closed

Retailer Partnership Gift Card Scam

This scam is currently active, and will continue to prey upon Xfinity customers until the company takes a more active role in helping customers avoid it.

I received a text message from "Xfinity" stating that "a special discount of as much as 50% off my current service rate expires today." The operation was very sophisticated. The 855 callback number in the text message had high quality, on-hold background music periodically interrupted by a professional voice actor describing Xfinity news and promotions, including a blurb asking, "Did you know that Comcast is partnering with Target Stores to sponsor big discounts for Comcast customers?  Go to xfinity.com/target-discount for details." This web address issued a 404 (page not found) error. The "xfinity sales representative" who answered my call was highly skilled. He asked me about the quality of service I was receiving and offered to send a technician to my residence free of charge when I complained of slow/spotty internet service. Turning back to the promotional discount, I asked, "How can I be sure you are calling from Xfinity?" He calmly praised me for my vigilance and offered my correct service address, the last 4 digits of my phone number, and my account's personal email address minus a few letters replaced with asterisks. As an "Xfinity Promotion Specialist," he was unable to access my full account information, including my xfinity billing account id or comcast.net email address which I specifically asked him for, due to "Xfinity's private and security policies, which were designed to protect its customers."

There were a number of additional yellow flags of this nature. I began to speculate that the missing account information is consistent with either a hack of a production Xfinity customer database table that did not include full account information, or a randomly targeted phish based on a purchase of hacked personal info. The Giant Red Flag was his last-minute explanation that Target Stores is sponsoring this promotion, which requires that I pay 10 months of service in advance... using Target Store gift cards!!!.

I'm posting a summary of this experience in order to:
1. Alert Xfinity customers and security staff that the scam remains active.

2. Propose an effective mitigation.

The mitigation is simply for xfinity to add scam alerting to its mobile app and host one or more pages on its primary web domain instrumented for SEO to yield top search results on Google, Bing, DuckDuckGo, etc that clearly state the nature of the scam and urge customers to stay away from it. When I searched the web for "Comcast Target Discount," only a small number of relevant hits were returned. These included reports from consumer protection and news sites. I was very surprised that only a single, year old, now-closed post appeared on forums.xfinity.com, with only noncommittal responses from forum moderators. My guess is that these moderators are not full-time staffers

Comcast/Xfinity and similar B2C companies can and should take a greater role in preventing their loyal, paying customers from falling victim to scams that exploit their corporate names and brands. Companies like Comcast/Xfinity typically learn about such scams far earlier than news journalists do. Customers trust official company mobile apps and web sites above all external sources of information. In short, Comcast/Xfinity's own websites and mobile app(s) should be the first and final say on scams that prey upon their valued customers... that is to say, *IF* they are truly valued.

Gold Problem Solver

 • 

25.9K Messages

1 year ago

... Alert Xfinity customers and security staff ...

Sad to say, they just don't care. This scam has been running for about a year now. See any of the many posts at https://forums.xfinity.com/conversations/search?page=1&sortKey=RELEVANCE&q=%22scam%20call%22&sortOrder=DESC. Heaven knows how many customers have lost how much money.

A competent company would have posted prominent warnings about a widespread scam that has cheated many and appears to use leaked customer data, but Comcast hasn't bothered to do that. They really should.

ETA: Also note the astonishing number of prepayment scam call reports listed under "Comcast Security Alerts" on https://internetsecurity.xfinity.com/help/alerts. And that's just the ones that have been reported! My local TV station's "On Your Side" reports have done more to spread awareness of this scam than Comcast has. 

Please be aware that there are 2 kinds of responses in this Forum: Replies and Comments. When you Comment on a post by scrolling down to "Comment on this post here...", I am notified of your response. But if you select Reply, I am NOT notified and may not be aware of your response.

(edited)

Contributor

 • 

51 Messages

1 year ago

Hello @shonji thank you for taking the time to reach out to discuss this instance of phishing. You can definitely report this here https://internetsecurity.xfinity.com/help/report-abuse and there are tons of helpful tips as well.

2 Messages

Thank you @XfinityAlexandrea​, I will report my experience at the link you cited... even if it's a black hole.

A push notification from the Xfinity mobile app and an official text message sent to all customers alerting them to the scam linking details on Xfinity's primary web domain would be highly effective in preventing the loss of their hard-earned money to this scam. 

A minimal number of customer reports should serve to incite Xfinity and its development teams to action. It's overdue.

Official Employee

 • 

850 Messages

@shonji, that is a great idea and I would highly recommend you leaving that feedback for our leaders using the feedback page available here: https://support.xfinity.com/svp-contact-form. This will help get your idea in front of decision makers with Xfinity who can get the ball rolling.

I am an Official Xfinity Employee.
Official Employees are from multiple teams within Xfinity: CARE, Product, Leadership.
We ask that you post publicly so people with similar questions may benefit from the conversation.
Was your question answered? Please, mark a reply as the Accepted Answer.tick

Expert

 • 

30.9K Messages

1 year ago

@shonji 

If you have gotten a call claiming to be from Comcast asking you to buy gift cards or paying upfront for six months or more in exchange for 50% off your bill the FTC is well aware of this scam.  If you get a call like this you can report it to:     https://reportfraud.ftc.gov/#/
If the scam involves Target gift cards call the Target GiftCard Services at 1 (800) 544-2943 and follow the instructions provided.
More information can be found here.
Please help to stop the spread of this kind of fraud.
Thanks!
 
forum icon

New to the Community?

Start Here