“Voluntary disclosure” of card data waives the right to compensation for fraud

Two bankers advised customers to allocate an additional card for purchases, other than the original bank card, and to limit themselves to placing a specific amount in it with each purchase, and not to save their card data on websites.
They explained that using well-known websites reduces the possibility of fraud, but does not completely eliminate it, as risks may arise through user devices infected with malicious software, or sophisticated electronic phishing operations.
They stressed that compensation is not due if investigations prove that the customer voluntarily disclosed the card’s confidential data, such as the card number, expiry date, verification code (CVV), or one-time verification code (OTP).
Bank customers had complained that their bank cards had been subjected to unauthorized use attempts in some cases, stressing that they had only used these cards through well-known and reliable international websites.
They explained to “Emirates Today” that they received text messages and notifications indicating attempts to discount, or carry out electronic purchases from parties outside the country that they had not made, despite their keenness to shop through reliable platforms, suggesting that they be given additional control tools through banking applications, such as temporarily disabling electronic purchases, or setting financial ceilings for online operations.
Unauthorized use
In detail, bank customers complained that their bank cards were subjected to unauthorized use attempts, confirming that they only used these cards through well-known and reliable international websites, and asked about the reasons for the repetition of these attempts, and the mechanisms for protecting electronic payment data when using their bank cards.
They told Emirates Today that they were surprised by text messages and notifications from the banks they deal with, indicating attempts to discount or carry out electronic purchases from parties outside the country, at a time when the security systems inside those banks succeeded in stopping the operations before they were carried out, while others were forced to cancel their bank cards and issue new cards, as a precautionary measure.
They explained that they are keen to shop through reliable platforms, and do not use websites of unknown origin, which raised questions about how their card data reaches parties trying to use it in fraudulent operations.
They demanded that they be given additional control tools through banking applications, such as temporarily disabling electronic purchases, or setting financial ceilings for online operations, in a way that enhances the level of protection and limits potential losses if the card data is exposed to any external exploitation attempt.
Voluntary disclosure
In addition, banker Tamer Abu Bakr told Emirates Today: “Banks conduct an investigation into each complaint separately, but compensation is not due if investigations prove that the customer voluntarily disclosed the card’s confidential data, such as the card number, expiration date, verification code (CVV), or one-time verification code (OTP), because this data is the basic authentication method for completing electronic operations, and sharing it holds the customer partly responsible.”
Abu Bakr added: “Many modern fraud operations do not result from direct penetration of bank systems, but rather rely on what is known as (social engineering), where the customer is persuaded to disclose his confidential data through websites or messages that appear to be issued by trusted parties.”
Abu Bakr advised customers to “allocate an additional card for online purchases, other than the original bank card, and just put a specific amount in it with each purchase, to avoid any risks resulting from sharing the original card details.”
Save card data
For his part, banker Muhammad Ghazi said: “The banks investigate each transaction in detail, and the amounts are returned if the customer does not enter the verification center (OTP), or confirms the operation via the smart application, and is surprised by the presence of transactions on his account, or deducting sums of money,” explaining that “it is not possible to compensate for any breaches, as long as the customer gave permission to save the card data and share all its data.”
Ghazi stressed that “using well-known websites reduces the possibility of fraud, but does not completely eliminate it, as risks may arise through user devices infected with malware, sophisticated phishing operations, or data leakage from one of the parties involved in the payment processing system, and not necessarily from the website itself.”
Ghazi called on customers not to save their card data on websites except when necessary, to activate instant notifications, to use virtual cards when purchasing online, and not to share the one-time verification code or security code with any party, whatever it may be, stressing that banks do not request this data via phone, text messages, or email.
- For more: Follow Khaleejion 24 Arabic, Khaleejion 24 English, Khaleejion 24 Live, and for social media follow us on Facebook and Twitter




