Posted 11 December 2020

Possible Subway/Subcard Data Breach.

Just received an email from 'Subcard' from the legitimate alias (subcard@UK-IE.subwaysubcard.eu).

The email contains links to access documents following a recent order. a quick glance on twitter shows many others have received the same email.

Possible data breach?


3619194.jpg
Community Updates
New Comment

50 Comments

sorted by
's avatar
  1. richp's avatar
    deleted6054311/12/2020 09:47

    Fortunately I doubt the Subcard site has any sensitive data on there?


    Hey, I don't want everyone knowing I have mayo on my salami!
  2. cosmicdav3's avatar
    I've had the same email this morning
  3. the.porter's avatar
    Me too
  4. ste_the_legend's avatar
    I've had the email too. They've definitely been hacked. Luckily I've never actually placed an online order so they don't have my bank card details.

    The least they can do is give us all a free sandwich for this!
  5. deleted2159852's avatar
    Definitely a data breach. I use a .com domain to provide a unique e-mail address for every provider I deal with and I've had two of these this morning sent to the e-mail address that I only use for Subway.
  6. OneWorld's avatar
    BBC News - Subway customers receive 'malware' emails
    bbc.co.uk/new…051
  7. Taz09's avatar
    Oh no
  8. deleted60543's avatar
    The email address can easily be faked to say anything so does not necessarily mean Subway has had any kind of breach. Still it would be very odd to use that address unless they know for sure that you have a subway account.

    These days sensibly you have to use a different password for each site anyway since there are so many breaches it’s ridiculous. Fortunately I doubt the Subcard site has any sensitive data on there?
  9. ellietoo's avatar
    I had this too, I just moved to their new app a day or two ago.
  10. markvlc's avatar
    I fwd the message to Support Desk just in case

    subcard@ipceurope.org
  11. D3adly's avatar
    Yep received the same email.
  12. deleted2628254's avatar
    Me too
  13. Jay1202's avatar
    Don't click on the link, definitely a spam email
  14. DavidCull's avatar
    Same here.
  15. deleted2628261's avatar
    Dodgy font. Definitely not right. Had it too
  16. deleted2628261's avatar
    43086309-1dGek.jpg
  17. irishwales1's avatar
    Me too .. strangely id just checked my point balance 5 mins prior .. i've tweeted subway .. no answer yet
  18. deleted2628286's avatar
    I'm here checking this out as my husband just received the same email 😡
  19. radzidek's avatar
    Just had the same
  20. bozo007's avatar
    Yet another reason to not open online accounts chasing really small discounts. I have realised that the discount is not worth the headache when these breaches happen, so if a retailer insists that an account needs to be created, I abandon my shopping cart. Obviously, can't implement it 100% but at least it minimises my number of online accounts and saves money.
  21. deleted2628304's avatar
    Worrying thing if it’s a hack they have some personal info - eg they know your name at the very least.

    Let’s see if Subway respond. If it’s a data breech they should be informing the ICO.
  22. deleted104362's avatar
    bozo00711/12/2020 10:34

    Yet another reason to not open online accounts chasing really small …Yet another reason to not open online accounts chasing really small discounts. I have realised that the discount is not worth the headache when these breaches happen, so if a retailer insists that an account needs to be created, I abandon my shopping cart. Obviously, can't implement it 100% but at least it minimises my number of online accounts and saves money.


    I wouldn't say the offers are particularly bad for Subway - they're certainly better than many places.

    But it wouldn't be the first time Subway have had data breaches - along with almost every company and organisation with an online presence.
  23. hc4eva's avatar
    deleted262830411/12/2020 10:42

    Worrying thing if it’s a hack they have some personal info - eg they know y …Worrying thing if it’s a hack they have some personal info - eg they know your name at the very least.Let’s see if Subway respond. If it’s a data breech they should be informing the ICO.



    Oh no, my name!!! Aaarrggghhh!!
  24. deleted2628304's avatar
    hc4eva11/12/2020 10:50

    Oh no, my name!!! Aaarrggghhh!!



    I gave the example of the name (it’s in their email) - if they have access to your data they may have a lot more.....
  25. hc4eva's avatar
    deleted262830411/12/2020 10:59

    I gave the example of the name (it’s in their email) - if they have access …I gave the example of the name (it’s in their email) - if they have access to your data they may have a lot more.....



    And they may not. If anyone’s concerned then you might as well just disconnect their internet and never return.

    People’s subcard details, emails, names etc have been all over the net for years now.
  26. deleted2628346's avatar
    Found this threat after googling the email address it came from. I think I have a sub card but I don't think I've ever used it 😬 but if someone wants to build some points up on there for me to spend, they can go ahead!
  27. james.robinsonKSS's avatar
    I had it too - forwarded to the email somebody posted up thread then deleted.
  28. Shino's avatar
    Shambles
  29. rhys89's avatar
    I’ve had the same. Thankfully they haven’t touched my previous sub card point balance
  30. Dilly_Dally's avatar
    It's a phishing email.
    You input your username and password and they'll test it on every website. Mostly Amazon , eBay, PayPal etc.
    Don't enter details
  31. RightSezPez's avatar
    Received it today too... Better than the average phishing attempt anyway.
  32. Lady_Luck's avatar
    Got one as well.
  33. davemcadam's avatar
    I've had it too
  34. RandomUser42's avatar
    I got it too, think it was timed with the demise of the old Subcard app? (edited)
  35. Paul_Foxton's avatar
    Me too - twice!
  36. fern37's avatar
    Me too!
  37. rhy18's avatar
    Thing is - this has come from their official email address so it doesn’t seem like it’s phishing. Something has definitely happened (edited)
  38. l518uk's avatar
    Hmm definitely think they had a breech... got email too.
  39. bunsy's avatar
    Had the same email. I’ve checked my bank and nothing has been taken. I haven’t even got the app installed.
  40. deleted2628466's avatar
    Any one else having a lot of phone calls from random mobile numbers today (edited)
's avatar