The £8.99 you stopped noticing two years ago is not the worst of it. The worst is that the card behind it is stored, current, and sitting in a merchant database you haven't logged into since the trial ended. When that database gets breached, or a criminal with your recycled password walks straight into the account, the charges don't look like fraud. They look like you.
Household budgets get drained two ways: by the subscriptions you forgot, and by the criminals who found them first. Both rank among the mistakes that quietly cost you online. The interesting question is which one is doing more damage right now, and whether the fix for one is the fix for the other.
Two Leaks, One Wallet
The forgotten subscription is a self-inflicted wound. You signed up, meant to cancel, didn't, and the £4 or £15 keeps clearing every month because the card on file is good. Regulators have started treating this as a design problem rather than a personal one: the FTC's Click-to-Cancel rule was written after complaints about recurring charges climbed to roughly seventy a day in 2024, up from forty-two a day in 2021.
The fraudster's version comes from outside. Someone gets into a streaming account, an old shopping profile, or a food delivery app, and the stored card underwrites a spending spree that clears in tenners rather than thousands. Both leaks look the same on the statement: small, repeating, easy to miss. Only one of them is yours.
The Convenience Argument Versus the Exposure Argument
Stored payment details exist for a reason. One-tap checkout lifts conversion, keeps you from typing a sixteen-digit number on a phone in a coffee shop, and lets legitimate subscriptions run without a monthly ceremony. That convenience is real.
The exposure side is also real, and it compounds. Every merchant holding your card is a merchant whose breach becomes your problem. Every account protected by a reused password is a door that opens with a credential someone else has already leaked.
Convenience is per-transaction. Exposure is permanent, and it grows every time you tick save my details for next time.
Small Changes Beat the Big Overhaul
A weekend security overhaul is the plan people announce and never finish. The changes that stick are smaller and take an evening. A short, well-chosen list of common online mistakes is more useful than an aspirational checklist of forty items you'll abandon by Wednesday.
- Audit the card, not the inbox. Open your bank app and read six months of statements line by line. Cancel anything you don't recognize or don't use. This catches forgotten subscriptions and unauthorised charges in the same pass.
- Stop reusing passwords. A password manager is the single change with the highest return. Reused credentials are how a breach at one merchant becomes a break-in at your bank.
- Turn on two-factor everywhere it matters. Email, bank, primary shopping accounts, and any service holding a card. An authenticator app beats SMS where the option exists.
- Prune the stored cards. Delete saved payment details from merchants you use once a year. The friction of re-entering a card twelve months from now is the point.
- Patch the phone and the router. Unpatched devices are how attackers slip in unnoticed. Turn on automatic updates and reboot weekly.
Regulation Is Catching Up, Slowly
The regulatory direction is unambiguous. The FTC's Negative Option Rule documents the dark patterns subscription businesses have leaned on for years: enrollment that happens in one click and cancellation that takes seven. Similar work is moving through consumer-protection bodies in other jurisdictions, and enforcement varies by market, so check what applies to you before you assume a merchant has to make canceling easy.
Rules will help. They won't rescue a household with a shared streaming password, a decade-old email login, and a card on file at every merchant it's ever used. That part is on you.
When Each Approach Wins
Convenience wins when the merchant is one you use weekly, the account has a unique password, and two-factor is on. The stored card is earning its keep. Exposure wins when the merchant is one you used twice in 2023, the password is a variant of the one from your old email, and there's no second factor. That card is a liability parked in someone else's database.
The household budget doesn't care which leak is bleeding it. An hour with the statements and the password manager closes both. That's the whole trade.
