The vulnerability is the business model
Gift cards sit on open racks in public because they carry no value until activated. That design decision is what makes unattended display safe from the retailer’s perspective — a stolen inactive card is worthless plastic. It is also precisely the weakness the attack exploits.
A thief does not need to steal the card. They need the number. So they take cards from the rack, open the packaging carefully, record the account number and PIN, restore the packaging to look untouched, and return them. The card goes back on display genuinely inactive, and everything about it looks normal.
Then they wait for you
With a batch of harvested numbers, the attacker polls balances automatically — through the issuer’s own balance-check page, which exists precisely to let anyone with a number look up a balance. The moment one shows funds, an activation has just happened, and the balance is spent within minutes on digital goods or another card.
The timing is what makes this devastating. Frequently the money is gone before the recipient opens the envelope. The buyer did nothing wrong, the retailer sold a valid card, and the issuer recorded a redemption using correct credentials. Every party behaved normally, and the customer absorbed the loss.
Why the claim usually fails
From the issuer’s records this transaction is indistinguishable from legitimate use: the right number and PIN were presented and the balance was spent. There is no anomaly to detect after the fact, and gift cards sit outside the rules that give prepaid accounts a formal error-resolution process.
So you are asking for discretion, and discretion responds to evidence. The receipt proving when you activated it, the physical card and packaging showing tampering, and a fast report all materially improve your odds. Keep the packaging until the card is spent — it is the only physical proof that the attack occurred.
What actually reduces your exposure
Inspect before buying, properly. The PIN scratch panel should be uniformly matte with no shine, scuffing, or replaced sticker. Packaging edges should be factory-sealed, not re-adhered. Nothing should be misaligned. Compare a card against others in the same stack — an odd one out is a warning.
Then change where you buy. Take cards from the back of a stack rather than the front, since tampered cards are returned to the front to be picked up sooner. Better still, buy from behind the counter, from a customer service desk, or directly from the retailer online. A card that never sat on a public rack cannot have been harvested from one.
What retailers have and have not done
Responses exist and are uneven: tamper-evident packaging, cards moved behind counters, activation delays, purchase limits, and monitoring for balance-check patterns that look automated. Some jurisdictions have begun legislating packaging and disclosure requirements rather than waiting.
It is fair to note this arrived late. The underlying flaw — a bearer credential printed on a card left unattended in public, with a public balance-check endpoint — was understood for years. Until the redesign is universal, the burden sits with buyers, which is not a satisfying conclusion but is the accurate one.