PC Optimum members get hit by points theft twice. Loblaws blames password glitch - Action News
Home WebMail Tuesday, November 26, 2024, 12:54 PM | Calgary | -8.3°C | Regions Advertise Login | Our platform is in maintenance mode. Some URLs may not be available. |
Business

PC Optimum members get hit by points theft twice. Loblaws blames password glitch

Thieves continue to steal hundreds of thousands of PC Optimum rewards points, and some members have even been hit twice. The reason? A glitch in the program's system would allow a thief to stay in a member's online account even after the initial theft was discovered and the password reset.

Even after changing password, people had more points stolen from their account

Even after Shawn Nicholson in Halifax changed his PC Optimum account password, the thief returned and stole more points. (Submitted by Shawn Nicholson)

Thieves continue to steal hundreds of thousands of PC Optimum rewards points, and some members have had the misfortune of being hit twice.

The reason?Aglitch in the program's system alloweda thief to stay in a member's online account even after the initial theft was discovered and the password reset.

"How secure is their program?" said William Grobe of Kitchener, Ont., who recently got hit by theft a second time, after beefing up his password. He had 250,000 points stolen in total. "It feels like someone's in [my account] in spite of any security."

After being contacted byCBCNewson Monday, PC Optimum's owner,Loblaws, saidit was fixing thepassword reset glitch, and reportedon Friday thatthe problemhad been resolved. The retailer said only "a very small number" of its nine million members had beennegatively affected.

Since launching on Feb. 1, the PC Optimum rewards program has battled a handful of technical issues, including strangers' accounts being combined together and members' points disappearing into cyberspace.

Last month, PC Optimum informed Kim Curry of Fraserville, Ont., that due to a technical error, her account may have been combined with someone else's. (Neil Libbenga)

Technical glitchesaren't the program's only problems. More than 40 PC Optimum members have complained toCBC News that they've had points stolen, ranging from $120 to $1,160in value.

Loblaws has advised members to protect themselves by creating strong, unique passwords. But that didn't quite work out for Grobe in Kitchener.

According to his account records, on March 23, a thief stole 240,000 points worth $240 and spent them at two Loblaws Pharmaprix drugstores inMontreal.

Grobe says he alerted PC Optimum and created a strongerpassword. But the thief struck again just two days later, this time spending 10,000 of his points at one of the same stores.

"You feel a bit violated," said Grobe. "If I get my points back, how do I know they're not going to be stolen again?"

According to Shawn Nicholson'srecords, someone hacked his account and stole 60,000 points worth $60. The thief spent them on March 24 and 26 at a Loblaws Maxi grocery store nearMontreal. Nicholson lives in Halifax.

By March 28, PC Optimum had returned Nicholson's points and advised him to secure his account by changing his password.

He did just that and thought his troubles were over. However, days later, thethief struck again, stealing 80,000 points this time, and spending them at the same Maxi store.

"I was really confused," said Nicholson.

He changed his password once again. When he reloaded the PC Optimum app on his phone, he noticed something strange: he was able to access his account and virtual PC Optimum card without having to enter the new password.

"I was quite shocked," Nicholson said, believing that was how the thief struck again so quickly. "If someone had gained access or breached the account previously, a change of password wouldn't make a difference."

After changing his password, Shawn Nicholson discovered he could still access his PC Optimum account via the phone app without having to update the password. (PC Optimum)

Loblaws spokesperson Kevin Groh acknowledgedthe password reset glitch has caused "inconvenience and concern" for some members.

"Their personal information is safe and every last point will be restored," he wrote in an email.

After being contacted by CBC News, Loblaws called both Grobe and Nicholson and returned their stolen points.

Nicholson is pleased Loblawsfixedthe password reset problem, but he's still concerned about thieves infiltrating accounts in the first place and stealing points.

"I can't say my faith is completely restored," he said. "How did they gain access? Was there a data breach of some sort?"

Industry experts say the thieves could be initially infiltrating accounts due to members creating weak passwords. Loblaws didn't comment on the cause, but the retailer did say the PC Optimum program is very secure and it continues to add new safeguards.

Meanwhile, CBCNews continues to receive theft reports. The most recent cases include Carolyn Lampshire in Kenora, Ont.This past week, a thief stole 240,000 of her points andspent them at a Pharmaprix inDrummondville, Que.

On March 31 and April 7, a thief stole a total of 220,000 points from Nicole Caputo's account and spent them atMaxi stores in Montreal. Caputolives inSault Ste. Marie, Ont.

"It's so creepy," she said. "It's just crazy to think someone could actually get into [my account] and use it no problem."