Vodacom billing shock from Google Play Store

So, I may have missed it in this thread, but has the OP mentioned what exactly was billed to that account - movies games, or what? And based on that, surely he should have a word with the employee concerned - Did that person think they were getting all that stuff for free?
 
So, I may have missed it in this thread, but has the OP mentioned what exactly was billed to that account - movies games, or what? And based on that, surely he should have a word with the employee concerned - Did that person think they were getting all that stuff for free?

Stated a few times, and the same question asked already lol, it was in game content - "jewels"
 
Stated a few times, and the same question asked already lol, it was in game content - "jewels"
We are pretty sure his Google account was compromised. Obviously got his username password from a PWNED list.
AS I KEEP SAYING.....Vodacom was supposed to deactivate in January. They have just confirmed with me that they are passing a credit for the full amount. So in the end they did the right thing. There were two security breaches. 1) My employee recycled passwords, 2) Vodacom does not secure payments with an OTP or password. ABSA was more vigilant and picked up the attempt to use his credit card immediately.
 
We are pretty sure his Google account was compromised. Obviously got his username password from a PWNED list.
AS I KEEP SAYING.....Vodacom was supposed to deactivate in January. They have just confirmed with me that they are passing a credit for the full amount. So in the end they did the right thing. There were two security breaches. 1) My employee recycled passwords, 2) Vodacom does not secure payments with an OTP or password. ABSA was more vigilant and picked up the attempt to use his credit card immediately.

But others have illustrated the SIM has to be in the device when it is enabled and when one buys, so I wouldn't be able to hack your google account and then pay for content using your SIM (unless I had done a SIM swap to get your number on a SIM in my control).
 
We are pretty sure his Google account was compromised. Obviously got his username password from a PWNED list.
AS I KEEP SAYING.....Vodacom was supposed to deactivate in January. They have just confirmed with me that they are passing a credit for the full amount. So in the end they did the right thing. There were two security breaches. 1) My employee recycled passwords, 2) Vodacom does not secure payments with an OTP or password. ABSA was more vigilant and picked up the attempt to use his credit card immediately.
Im happy you got your money back - but again your employee is not innocent!
You seem to ignore the fact that the carrier purchases must be done in the phone with the vodacom sim.
I would keep an eye on him if i were you.
 
Im happy you got your money back - but again your employee is not innocent!
You seem to ignore the fact that the carrier purchases must be done in the phone with the vodacom sim.
I would keep an eye on him if i were you.
Are you sure about that? Because vodacom billing shows up on the google play website.
 
Are you sure about that? Because vodacom billing shows up on the google play website.
Ran a test on our vodacom number a while back - the carrier billing only worked with the phone with the sim in - i could not make charges online on the same account

Exactly its only on the app - So Sadly the hacked is google account story doesn't hold on theses purchases
 
Ran a test on our vodacom number a while back - the carrier billing only worked with the phone with the sim in - i could not make charges online on the same account

When transacting online (play store or Google One sub), I am unable to charge a purchase to my contract SIM. When using the actual play store app or Google One app on a device that is logged into my account, I can make purchases without the SIM being present in the device.

In my test, the same maneuver did not work on my wife's device.
 
We are pretty sure his Google account was compromised. Obviously got his username password from a PWNED list.
AS I KEEP SAYING.....Vodacom was supposed to deactivate in January. They have just confirmed with me that they are passing a credit for the full amount. So in the end they did the right thing. There were two security breaches. 1) My employee recycled passwords, 2) Vodacom does not secure payments with an OTP or password. ABSA was more vigilant and picked up the attempt to use his credit card immediately.

^^This.
Then by the same Vodacom ‘logic’ any employee on your business contract could also successfully re-activate the Google play service on all your employee phones, while your ( owner) instructions aren’t accepted ?

Glad to hear they’re doing the right thing with your credit , but imo Vodacom might do well to revise the wording in Google play sim T&C section on their website ... currently clear as mud :-

https://myvodacom.secure.vodacom.co.za/vodacom/terms/google-terms-and-conditions

‘The right to access and use the Service is strictly limited to the SIM card inserted in the device used at the time of use of the Service, and is not transferable to third parties. The customer must be fully authorized to use the SIM card to use the Service.
If the SIM card is not registered to the Client or if the real user data is not entered in the computer systems and associated users), the ultimate subject of the SIM card user must be authorized to use by the person whose name the SIM card service it.

That last para - sense much?
 
We are pretty sure his Google account was compromised. Obviously got his username password from a PWNED list.
AS I KEEP SAYING.....Vodacom was supposed to deactivate in January. They have just confirmed with me that they are passing a credit for the full amount. So in the end they did the right thing. There were two security breaches. 1) My employee recycled passwords, 2) Vodacom does not secure payments with an OTP or password. ABSA was more vigilant and picked up the attempt to use his credit card immediately.

I'll just ask one question - Did your employee ignore all the receipts for purchases too? So all those emails from the store were ignored? Glad Vodacom buckled for you.
 
We are pretty sure his Google account was compromised. Obviously got his username password from a PWNED list.
AS I KEEP SAYING.....Vodacom was supposed to deactivate in January. They have just confirmed with me that they are passing a credit for the full amount. So in the end they did the right thing. There were two security breaches. 1) My employee recycled passwords, 2) Vodacom does not secure payments with an OTP or password. ABSA was more vigilant and picked up the attempt to use his credit card immediately.
Just about everybody's emails is on some pwned list. Did you contact the devs for that app?
 
Top
Sign up to the MyBroadband newsletter
X