Please sign in to post.

Hacked credit card question...

Our Chase card was hacked yesterday. New card expected on Tuesday. We leave for Italy on 9/1/26, but we've made numerous reservations under that (now-invalid) credit card number. I plan to confirm all our hotel/Airbnb bookings and inform them of our new number, but I'm wondering if that's also necessary for museums, like the Borghese Gallerie or Musee D'Orsay? Will they require us to show the actual card that was used to book? (They have the money, so it's not like we're not paying them.) I guess I'll just bring the invalid card, along with our new one...? (BTW, we will have several other cards with us.) Glad this happened now and not a day or two before we leave (or while we were there). Thanks for any stories/experience you can offer to give me clarity. -- :) Linda

Posted by
663 posts

Ive had something similar happen while traveling, and you will be fine with your ID. If there are any questions, you have good backup to support your story - and you can even show the invalid card if they want to see it. I am amazed how many people this happens to, and businesses just roll with it.

Posted by
2655 posts

I've never had a museum or similar venue ask to see the card I used for pre purchased tickets unless it was for picking up tickets from a theater box office or similar. If the venue requires presentation of the card upon admission, it should state it either on your ticket or under terms of condition on their website.

If you have already prepaid any hotel/Airbnb reservations that won't require additional billing before arrival, I wouldn't share the new card info in advance.

Posted by
358 posts

Here is our experience. We had our Chase Visa hacked while in Italy in 2023. We called Chase, and Chase kept our existing (hacked) active for in person transactions only; no online purchases could be made. We had back up cards with us, but we were still able to use the Chase Visa.

Posted by
6425 posts

If you have a card on file and are using a booking platform that will run your charge on a certain date before you are there to pay in person (booking.com, Air bnb, Viator, or a B&B booked direct in New Zealand), you will need to notify them - as you mention - and update the billing info. Don’t ask me how I know this.

Posted by
17514 posts

Did you use this card to book your flight? Although it rarely happens I believe there have been threads here mentioning an airline asked for the CC used to book so do take the now invalid card with you. I do not have personal experience with this…just recall someone posting issues!

This is also a plus for having cards stored in Apple or Google wallets as the company updates the number immediately and you can use the new card before the plastic actually arrives.

Posted by
129 posts

Our experience - hotel had old credit card on the reservation and, per their policy, tried to charge the room (one night stay) but it was declined. They emailed us but we were focused on getting to that destination and we didn't keep up with email. Our bad. We arrive after an early morning flight then public transport to the hotel, only to be told no reservation and no rooms available. They did offer us a discounted room at a sister property, so it worked out OK. Gotta keep up with emails, even on the road!

Posted by
1226 posts

My experience was that the credit card company had already flagged suspicious transactions and put them in limbo until they confirmed yeah or nay whether those were legit. This was done by a human calling us to ask. I suppose you could do the opposite to call and verify pending transactions. It's a good idea to inform Chase that you will be traveling in Italy and France during these dates. That note will be added to your file and could help keep transactions running smoothly.

I have never had a museum ask for a physical credit card to verify a purchase. It's not a physical ticket waiting for you at WILL CALL, it's an e-ticket, correct?

Posted by
92 posts

Thanks everyone for your kind and informative replies! I really appreciate it. We realized that a card we already have gives us more points by using it for travel, so we've informed all Airbnbs and hotels of that number. As for the museums, I'll just have the invalid card on hand in the off chance someone might ask for it. Thanks again. So grateful for this forum and its participants. :)

Posted by
13046 posts

This is also a plus for having cards stored in Apple or Google wallets as the company updates the number immediately and you can use the new card before the plastic actually arrives.

Pam, mine did not, although it has in the past. I don't know if it was because of the circumstances.

Linda, my Chase card was used to make an illegal purchase online. But it happened about a day after I got back from my Norway trip. Luckily, I happened to be sitting at my laptop when the alert came through and was able to contact Chase immediately. They canceled the card and sent me a new one, but I had to wait until I got the card before I could put it in Apple Pay.

I have several hotels that I booked for a December trip that have the old Chase number, but since I won't be incurring any charges on that until I actually get there, I've decided to just bring the physical card along (it's also on Apple Pay) and then use that.

Posted by
17514 posts

@Mardee, that is interesting. When my AMEX card was compromised last year, I was at home and the notification for the $1500 charge came during the night so I didn’t see it til the AM. There were actually 2 charges, one for an insignificant amount and the other a short time later for the large sum. While I was on the phone with the agent he said…”I see this is in your AppleWallet, so I’ll update that number immediately.” It was done by the time I got off the phone. I guess I’m surprised Chase didn’t do it automatically.

Linda, I suspect everyone is curious to see how this plays out for you! I hope you’ll come back to update after your travels!

Posted by
9572 posts

There were actually 2 charges, one for an insignificant amount and the other a short time later for the large sum.

This tells the story pretty well. When people suffer a card being compromised, they immediately blame it on being "skimmed" or a dishonest waiter or shop clerk copied the information. That actually is rarely the case. What happened in the example above is an example of a brute force attack. also known as a BIN attack or card cracking. Crooks write programs for bots that essentially try thousands of combinations for a card number (your credit card number is not that unique, much of it identifies the type of card and the issuer, with only a few number being your specific account) to get the correct expiry date and CVV number. When they get a hit and a small transaction goes through, then they manually make a large purchase.

US based cards are prime targets for this type of scam, since there is no requirement other than card number, expiry, and CVV. Many countries use 3DS security to prevent this from even happening.

Posted by
6425 posts

Pam, as you said, both my Chase and my Citibank cards updated automatically (and quickly) in Apple Wallet this past year. Mardee, it’s weird yours didn’t.