Summary
Based on the increased customer service calls RPG received in the month of May, it was determined that there was an extraordinary amount of unauthorized redemption activity occurring on Shell Gift Cards.
Activity review determined strongest area of unauthorized redemption activity was centered around the Los Angeles area, but as mitigation steps were taken, locations began to expand.
Upon deeper review, we identified unauthorized redemption activity on both Fiserv and Shift4 card numbers, including digital. Unauthorized access to Fiserv card PIN numbers also appears to be included in this activity.
Details
Check Balance
Suspicious balance inquiry attempts on RPG website with valid PINs on both Fiserv and Shift4 BINs (RPG and Shift4 check balances are currently shut down).
Redemption Activity
High level summary of suspicious redemption activity occurring from the new Shift4 BIN. Information is through May and remains fluid.
Corporate
Consumer
3rd Party - BHN
3rd Party - InComm
Shell Dealers
Card Security Comparison
It appears the 19th digit in the new Shift4 card sequence is generated by Luhn Algorithm like the legacy Fiserv card.
Action Taken
RPG access to additional Shift4 Data
Shift4 has denied the request
RPG has requested that Shift4 increase our access to card activity on the gift card portal. The ability to see invalid attempts and the full picture of activity will help us identify root cause of suspicious check balance activity.
Shift4 to Freeze Inactive Card if Redemption Attempt
Complete
RPG identified that there is no rule in place through Shift4 to freeze a card if a redemption attempt occurs on a card that has never been activated. This was a legacy fraud rule in place since 2016 on Fiserv at the recommendation of RPG.
RPG continues to work with Shift4 on the enablement of this rule.
New Rule: Redemption <$1 Freeze Card
Complete
The <$1 Rule and removing LA market has slowed down the fraudulent redemptions. More than 50% of the cards placed on hold due to the <$1 have been confirmed as fraudulent redemptions. Initial results showed the <$1 Rule helped to identify over 1,700 confirmed compromised cards.
Current status: Rule is working, however bad actors are adapting.
Temporarily Shut Down Los Angeles Region
Complete
Due to extremely fraud attempts being conducted at Shell locations in the LA region, 491 Shell sites were shutdown from allowing gift card transaction. This remained in effect for 14 days.
Current status: LA sites were turned back on Monday, June 16.
Websites Check Balance Shutdown
Complete
RPG experienced bot attempts on the Check Balance on our website. On June 4, RPG and Shift4 shutdown check balance functionality from the websites.
Current status: Check balance functionality is still turned off.
Request from CMSPI (07/02/25)
I (Jake) have spoken to our Fraud Team, and they provided me with some data points that we would need from RPG and/or GiveX to assist you with the current gift card issue. We believe we can get started with the following data points:
From Lauren (07/02/25)
CMSPI is going to be assisting with analyzing our BIN range to try and identify a pattern that could tell us what portion of the range is impacted. This is the initial information they are requesting, but I anticipate there might be additional asks as they work through the data. I’ve asked them to share their preference on how to securely transfer the data and we can discuss during today’s meeting.
Recommendations / Requests
RPG Recommendations
RPG access to addition Shift4 Data
When Shift4 grants RPG the requested access, RPG will dig into known cards that have been stolen. We will be looking for invalid PIN attempts on these cards and any other trends.
PIN Requirement for Redemption
RPG recommends that Shell require PIN validation at the pump for redemption
Track 2 Data
Review track 2 data configuration to improve/add additional security to redemption process.
Explore Other Viable Solutions
Explore other viable solutions, potential backend data configuration – as example create a 21 digital BIN for the Master card in App.
Strategic Solutions from Shift4
Continue to encourage Shift4 to provide strategic solutions.
Physical Gift Card Production
WestRock Card Manufacturing has been the single source for all physical Shell Gift Card production. Shell cards were produced at their Woodridge, IL location. In addition to Shell – Amazon, Google, Apple, Target, Best Buy, and Home Depot, to name a few are manufactured at this location. WestRock also has plants in Dallas, TX and Guangzhou, China.
RPG submitted data requests to Shift4:
Digital Card Production
Digital Shell eGift Cards launched August 2023. Digital Shell eGift Card numbers are all produced and stored with Shift4. Digital card distribution to recipients goes directly from Shift4 to recipient via unique link in recipient email that provides access to their card number and PIN.
For B2B customers requesting bulk order, Shift4 sends an excel file via email directly to the B2B customer.
Physical Gift Cards
RPG has access to card numbers but no access to other card data including PIN. Consumer Physical Order Process (high-level):
B2B Physical Order Process (high-level):
Digital eGift Cards
RPG has access to card numbers via Shift4 portal, but no access to other card data including PIN. RPG is not included nor receives any emails/files with card numbers or data.
Consumer Digital Order Process (high-level):
B2B Digital Order Process (high-level):
Questions for Shift4
Action Requests for Shift4
Questions from Shell
Q: Is there any correlation to the legacy cards being mapped to Shift4 card numbers in the system (that started in Oct/Nov) and could this mean it’s the Shift4 BIN primarily impacted, or did we see this type of fraud prior to any mapping to the Shift4 range?
A: For clarity, legacy card numbers are not mapped to Shift4 card numbers. Shift4 received legacy card numbers from Fiserv and remain as Fiserv numbers.
Historically there have been scenarios where card numbers are figured out based on the cards being sequential. This involved guessing the check digit. Back in 2016 there were fraud rules implemented on the Fiserv end to help mitigate card testing at the pump, along with enhancements to the RPG balance inquiry page. Together, these enhancements deterred the majority of card testing attempts. It would be virtually impossible to test card numbers on the RPG site unless the PIN was known. Based on our knowledge/analysis, the difference now is fraudsters seem to know the PINs. Historically (prior to Shift4), this was not something we saw.
Q: For bulk orders, are we able to ship inactive and have primary recipient call/email to activate on receipt of shipment? If Shift4 has implemented a preventative measure to mitigate fraud on inactive gift cards, could this help?
A: For bulk orders, RPG has always had a unique process to avoid in-transit fraud on our shipments. RPG ships cards inactive and activates upon delivery. We are integrated with FedEx automated tracking to monitor the progress of shipments and activate the cards after shipments have been delivered.
Reporting
Customer Service
SGC Customer Care Team service support increases between April - June*
| Channel | Increased By | June Numbers | Monthly Average |
|---|---|---|---|
| Customer Care Tickets | 699.09% | 2,661 | 321 |
| Balance Error/Adjustment | 211.62% | 750 | 160 |
| Redemption Assistance | 228.44% | 3,150 | 715 |
| Balance Inquiries by Phone | 64.72% | 12,229 | 9,393 |
*Through June 28.
SGC Physical Inquiries supported by Digital Care Team between March - May
Replacements - Unauthorized Transactions
| January | $7,465 |
| February | $11,001 |
| March | $100,848 |
| April | $36,156 |
| May | $113,705 |
| June (thru 6/25) | $439,808 |
B2B Sales Impact
RPG is working closely with customers who have been impacted to date.
This is ongoing and impact is to be determined.