Hello,
I'm seeking guidance on a concerning situation:
About 9 days ago, I received an email from Amex containing a SafeKey (apparently their online MFA verification for vendors) notifying me of an attempted charge of 1 INR on my card. I didn't authorize this transaction nor share the code provided. Following the email's advice, I contacted Amex. The representative downplayed the situation, saying the charge was prevented by SafeKey and Amex saying they can't see SafeKey charges that aren't verified. Even so, I opted to freeze my card because I had no dealings with the merchant (PayU/India) and was uncomfortable with the response.
Fast forward to yesterday: With my card still frozen, I noticed attempted charges for Facebook Advertising – all were declined. I contacted Amex again, explaining the issue, and they decided to issue me a new card with a different number.
However, today, I received another email pertaining to an attempted charge on this new card (which I haven't even received or know the number of) from "PAYU RETAIL PG" for 499 INR. For context, PayU appears to be a peer-to-peer payment platform in India.
Considering I have a replaced card, had active MFA on my Amex account, and the new card details are neither online nor stored in any digital wallets: How are these unauthorized charges happening and what steps can I take to prevent them?
Thank you for any insights!