Boots Advantage Card payments suspended after hijack attempts

(Image credit: Shutterstock / Maddie Red)

Boots has temporarily suspended payments using loyalty points earned via its Advantage Card scheme after attackers attempted to hijack customer accounts.

The high-street giant confirmed none of its systems were compromised, but that attackers had tried to access accounts using credentials scraped from other platforms.

Advantage Card holders will be barred from redeeming their points both online and in store until Boots has a handle on the situation, though customers can still collect points when making purchases.

The measure comes just days after a similar incident saw Tesco issue new cards to 600,000 members of its Clubcard loyalty scheme.

Boots account hijack

The percentage of Boots customers affected is reportedly less than 1% of the 14.4 million total active accounts - or roughly 145,000 people.

“We are writing to customers if we believe their account has been affected, and if their Boots Advantage Cards have been used fraudulently we will, of course, replace them,” said the company in a statement.

“We would like to reassure our customers that these details were not obtained from Boots,” the firm was careful to add.

Chris Miller, Regional Director UK&I at RSA Security, earlier this week predicted the same credentials used to access Tesco Clubcard accounts would be tried on other sites too - and was proven correct.

“From the end-user’s perspective, it is really important not to use the same password for multiple accounts,” he warned.

“Some sites and apps offer two-stage authentication, asking for both a password and, for example, a code delivered to a mobile phone…[which] can offer an extra degree of security.”

Boots has advised customers to reset their passwords online, and to select a unique password not used for other accounts.

Via BBC

Joel Khalili
News and Features Editor

Joel Khalili is the News and Features Editor at TechRadar Pro, covering cybersecurity, data privacy, cloud, AI, blockchain, internet infrastructure, 5G, data storage and computing. He's responsible for curating our news content, as well as commissioning and producing features on the technologies that are transforming the way the world does business.

Latest in Security
ransomware avast
Ransomware attacks are costing Government offices a month of downtime on average
Lock on Laptop Screen
Data breach at Pennsylvania education union potentially exposes 500,000 victims
Data leak
Top collectibles site leaks personal data of nearly a million users
Spyware
Stalkerware data breach potentially hits over 2 million users, including thousands of Apple devices
An American flag flying outside the US Capitol building against a blue sky
Five Eyes "cannot replace US intel in Ukraine", claims former US Cyber Command Chief
Pirate skull cyber attack digital technology flag cyber on on computer CPU in background. Darknet and cybercrime banner cyberattack and espionage concept illustration.
Criminals are using a virtual hard disk image file to host and distribute dangerous malware
Latest in News
Apple iPhone 16 Pro Max REVIEW
The latest batch of leaked iPhone 17 dummy units appear to show where glass meets metal on the new designs
Hornet swings their weapon in mid air
Hollow Knight: Silksong could potentially launch this year and I reckon it could be a great game for an Xbox handheld
ransomware avast
Ransomware attacks are costing Government offices a month of downtime on average
Cassian looking at someone off-camera from a TIE fighter cockpit in Andor season 2
Star Wars: Andor creator is taking a stance against AI by canceling plans to release its scripts, and I completely get why
Nintendo x Seattle Mariners partnership
The Nintendo Switch 2 logo will be featured on the Seattle Mariners' baseball jerseys this season
Apple iPhone 16 Pro Max Review
Siri's chances to beat ChatGPT just got a whole lot better