So, on a serious note. I've just been hit by the infamous deliveroo scam. £89 taken from my account and dont even have a deliveroo account. Turns out the card I hold for the account is due to expire this month and it wasnt even the card number that was used for the transaction! It was the new card details that hadnt even been made into a physical card yet, awaiting approvalnor pending or something, but no physical card exists! So in my eyes the only way this can happen is for VISA to have a dodgy employee selling off card info OR they have been hacked themselves and havent made it known publicly, i mean think of the outrage if it came out that VISA had been hacked! All different banks have been hit by it... scammers are vile cowards that wouldnt dare literally put their hand in my pocket but do so hiding behind a screen! Whatever they spent £89 on wasn't delivered to my house, so am hoping they get caught out. Have told the bank that this isnt over and I will be pushing for compensation - as this is clearly out of my control, but, Im the one having to sort it all out
It's far more likely that the card number had been assigned to your account (depending on card they're sometimes shipped out a couple of months early), and someone had a card number generator that got lucky.
IIRC there is a formula that is used to create the card numbers, and it's fairly well known as the card issuers use it with minor variations, and the first 4 digits of your card are always the same for that issuer/card type (for example IIRC Barclaycard Visa always starts with the same 4 digits whilst their MC start with a different 4), so it's only got to get 12 digits right and at least one of which is a check digit, so 11 digits.
If you ever played with old keygens for pirated games you might remember how it was often possible to get a working one within a few attempts.
So what someone can do is use what is effectively a keygen, and hope it works, and depending on the retailer or company doing the card processing they may not need to match the rest of the card details, or even physical address, so they get a huge list of potentially usable numbers then try a company that's got lax security until they get some successes and sell those numbers on as being valid.
A company like Deliveroo might be an ideal way to test these generated card numbers because you don't have to present the card number in person, and don't have to be the person it delivers to or might be asking for it to be delivered to a hotel room or whatever.
Going back a fairly long time I had some fraud on one of my cards for a porn company who authorised my card number based just on the front 16 digits and a hotmail address (at the time I didn't have one as it was new).
Another time someone was apparently creating fake cards and using them in a museum/art gallery coffee bar so loads of people were getting card transactions for something like $1.99* because America tends to be very very behind the curve in dealing with card security (partly because their consumer protection laws tend to be lacking so it's often up to the card holder to fight hard to prove fraud rather than the issuer taking responsibility).
It would be interesting to find out what card details deliveroo in various countries actually check when they validate it for order, as from memory it's largely up to the retailer as to what they do, with the understanding that the less details you take the lower the limit at which it becomes the retailers responsibility to refund any fraud out of pocket. Which is one of the reasons the likes of OCUK tend to want ALL the details and will often only ship to the cardholders address as it means their risk from fraud is massively reduced, whilst IIRC Amazon don't necessarily ask for the CVC every time (Amazon are big enough their own risk algorithms mean they can take the chance).
*I was amazed that got through Barclaycard's anti fraud system, as I rarely leave the country, have never been to the US, NEVER used my credit card for small purchases in person, and never in coffee shops etc (at the same time they blocked my reoccurring online game sub several times).