
Amber Shuker-Bright (left) and Fariba Rad (right) were among those affected
Scammers are still having a shopping spree with stolen Nectar points,with shoppers seeing their accounts drained in places they have never visited.
Meanwhile,some say they have been locked out of their accounts entirely and have asked Sainsbury’s for an explanation.
The supermarket introduced an ‘account lock’ feature to their loyalty app in February to try and crack down on the problem – but customer services reps are still fielding dozens of complaints.
Mum-of-two Fariba Rad,from Putney in London,told Metro she was ‘really upset’ to get two emails on Sunday morning thanking her for spending her balance.
‘First I started thinking about when I was at Sainsbury’s,but then I saw the area was Oakley and I said to myself,“someone’s hacked my points”,’ she said.
The thieves spent £12.50 in two transactions of 1000 and 1500 points,leaving her with only 194 points left worth 97p.

One shopper asked a customer service rep,‘What on earth is happening?’

Another said they were ‘going nuts’ trying to resolve £100 of lost points and then being locked out of their account

Another asked,‘I see your feed full of the same issues. Do you have a major problem?’
Some shoppers contacting Nectar online said their points had been spent while they weren’t even in the UK,while others said they were having problems with the app and ‘can’t even log in’.
In recent months,retail cybersecurity has come into the spotlight after Marks and Spencer was hit by a devastating hack which is still not completely resolved,with online shopping unavailable.
Supermarkets Co-op and Harrods were targeted by hackers too,while sports brand Adidas also fell victim – so the natural question for many was if Sainsbury’s could also have been compromised.
But the supermarket said they were not experiencing any IT issues.
They confirmed that Fariba had fallen victim to fraud,and that criminals use a range of tactics to try and profit from their popular loyalty scheme,which has over 23 million members.
The ease with which scammers can access Nectar points was revealed in January,when This Is Money revealed over 12 million points worth some £63,000 had been taken in the year prior.
People saw their points spent in places they have never been (Picture:X)
Shoppers have been asking if the app is working correctly (Picture: X)
One customer said ‘I can’t even log in. I see others have the same issue. What’s going on?!’‘To defend against this attack,app developers should incorporate security measures into the app’s design. For instance,they should require a full login or identity authentication to spend points and ensure that login portals do not indicate whether accounts are valid or not. Limiting the number of login attempts before imposing a timeout can also slow down brute-force guessing attacks.‘The attackers may also be using credential stuffing,a cyber-attack where hackers use breached account information,like usernames and passwords,to gain unauthorised access to other online accounts. To protect against credential stuffing,it is crucial that individuals do not reuse passwords across different accounts,enable multifactor authentication whenever possible,and consider using a password manager to store and manage passwords for various apps and websites securely.’A Nectar spokesperson said: ‘The security of our customer accounts is our highest priority and the proportion of those impacted by fraud each year is very small.‘We have a range of measures which detect and in many cases prevent fraud,including point spending confirmation emails and our Spend Lock feature.’
HONG KONG,March 18,2025-- China Merchants Commercial Real Estate Investment Trust ("CMC REIT" or "the Trust",HKEX stock code:1503),announced its annual results for the year ended 3
XI\'AN,China,March 18,2025-- From March 11th to 13th,the largest photovoltaic exhibition in the Netherlands,Solar Solutions Amsterdam (SSA),was grandly held in Amsterdam. As a globally leading solar
TOKYO,March 18,2025--The Global Health Innovative Technology (GHIT) Fundannounced today a total investment of approximately JPY 1.7 billion (USD 11.4 million1) in five projects for the development of
SAN JOSE,Calif.,March 18,2025-- DeepRoute.ai,a pioneer in developing and deploying end-to-end smart driving solutions,unveiled AI Spark platform to build an AI-driven "road brain" system to