The Mail on Sunday

Deliver-who? Hackers use your account for free meals

- By Neil Craven DEPUTY CITY EDITOR

HACKERS are selling access to Deliveroo customers’ accounts for as little as £3 – and the stolen details are then being used to order food from local shops and restaurant­s before the delivery firm’s customers become aware of the crime.

A Mail on Sunday investigat­ion found hackers are advertisin­g a menu of options on the Dark Web, including a one-off fee and pre-paid ‘credit’ for significan­t discounts.

One customer told us he was hacked five times in one evening this month and another has been hacked twice this year despite changing her password.

The company was alerted to the problem earlier this year. But last week, daily complaints on social media included more than £ 200 ordered from East London takeaways from one account and another fraudulent order for £100 worth of cigarettes from the local Co-op.

Fraudsters often order small amounts, even single meals, at a time. One customer said her account had been used to order ‘posh chocolate’.

Jason Hill, lead cyber security researcher at CyberInt, said email addresses, passwords and bank details are stolen through data breaches at other companies and traded on the Dark Web, part of the internet not visible to search engines. Hackers then flood Deliveroo and other sites to test for vulnerable accounts, mainly those where customers have used the same passwords.

Once in, they change telephone numbers and addresses to divert deliveries and then switch details back before quitting the account.

But criminals leave behind evidence and victims have found their details on digital receipts. After ‘ brief investigat­ions’ last week, Hill was able to find evidence that access to Deliveroo and other delivery firm accounts had been traded on the Dark Web. One, claiming to be a student and which appeared to be inactive, offered ‘ al l t he f ood you want’ f rom Deliveroo for £5.99. Another advertised Deliveroo ‘credit balances’ between £10 and £99 for 30 per cent of their value.

Deliveroo said last night: ‘ We regularly introduce measures to combat fraudsters and to protect customer accounts. Unfortunat­ely, cyber criminals rely on people reusing the same passwords on multiple online services and use data breaches elsewhere to try to gain access to other accounts online.’

 ??  ?? MEAL TICKET: Deliveroo account details are being sold online for as little as £3
MEAL TICKET: Deliveroo account details are being sold online for as little as £3

Newspapers in English

Newspapers from United Kingdom