Quantcast StorefrontBacktalk » Blog Archive » Starbucks Confirms One Million Transactions Double-Charged
advertisement
advertisement

Starbucks Confirms One Million Transactions Double-Charged

Written by Evan Schuman
June 10th, 2009
Like this story? Share it
To share this story with people in your social network, please click on the network icons below.

What is it about holidays and double- or triple-charging customers? Starbucks now confirms that it double-charged customers on Memorial Day weekend to the tune of one-million transactions, which follows 8,000 customers who were double- and triple-charged at Macys during Christmas week and an unspecified number who were overcharged at Best Buy in March.

The Macy’s and Best Buy situations only involved debit card transactions, but the one-million Starbuck transactions involved both credit and debit cards, said Starbucks spokesperson Trina Smith, who wouldn’t break down how many of each card type was involved.

That information is critical because such an error would be minimal for most credit card customers, who might not even be aware of it until they see the credit on their statements. But for debit card customers who keep just enough of a balance to cover checks, such double charges might cause checks to bounce and other problems. That couldn’t be fixed with a mere credit for the overcharges.

Another distinction between the earlier glitches is that Macy’s and Best Buy ran into their problems at the POS, with systems indicating that a charge had not gone through when in fact it had. With Starbucks, the POS charges—and the receipts given to customers—were perfectly in order. The problems kicked in hours later, in the settlement processing area, Smith said.

The glitch happened on May 22 and May 23 and credits to fix the problem were all issued by the end of May, according to a Starbucks statement.

“We apologize for the inconvenience to our impacted customers and are relieved that the issue has been fully rectified,” the statement said.

Unfortunately, the issue seems to be far from fully rectified, as Starbucks has declined to say how the glitch happened, how others could avoid the identical issue and how Starbucks plans to prevent it from happening again, assuming they do indeed plan to try and prevent it from happening again.

The Associated Press reported that the error happened only at the 7,800 company-owned Starbucks locations.


advertisement

4 Comments | Read Starbucks Confirms One Million Transactions Double-Charged

  1. John Burnett Says:

    For bankers and their debit card customers, it’s great that Starbucks identified the errors and reversed the duplicate charges. But as noted, how many bank debit card customers were tipped into overdraft territory by the double latte debits? How many banks will be scrubbing their files to find customers whose OD fees need to be reversed? How many other debits and checks were wrongfully bounced?

    That’s a hell of a lot of aggravation for debit card customers and their banks for a retailer’s lapsed controls, all of it over (personal opinion) overpriced, over-hyped coffee.

  2. grasshopper Says:

    this is bad timing for Starbucks… the last thing they need right now is more bad PR

  3. Evan Schuman Says:

    As Master Po would have said, “Perhaps, young Grasshopper, but is there ever a good time for bad PR?”

  4. Marcy Says:

    Did starbucks think that the banks should absorb the cost because of the mistake? The bank have to pay employees to go over NSF list and extra reports, paper, storage, and the time of the customer service rep or office that had to take the customer’s phone call. A simple error like that can cost a bank alot.

Leave a Reply

Newsletter

Quickly catch-up on the latest in E-Commerce and Retail Tech with our free weekly newsletter, with urgent bulletins as news merits.
advertisement

Most Recent Comments

Kill All The Passwords

This article does mention, but does not give enough attention to, the fact that the attacks discussed are only feasible when the encrypted password file can be copied and subjected to an offline attack. The trick is to have authentication performed on a separate, much more strongly secured host - such as an Active Directory Domain Controller, or a Kerberos server, or a NIS+ server, or even using something as banal as an LDAP-over-SSL authentication dialog. In these environments, the odds of the "password file" being stolen and subjected to an offline attack go to near zero, and only online attacks may be carried out by the attacker. With sensible exponential backoff between failed password attempts, lockout after a modest number of failed attempts on a single account, and pattern detection, that minimum 7 character password is quite secure enough. Passwords aren't dead yet for security purposes, and they will be with us for a very long while to come for practical purposes. The trick is to employ them correctly. Read more...
The possibilities you describe are years away from being implemented at best, so for the moment passwords are an ugly reality. Luckily, password managers can easily manage hundreds of passwords of any length. The only thing a user needs to remember is the master password. It seems like an easier task to educate users on how to use password managers rather than implement complex security technology on a global basis. Read more...