Coursera.org Attempts Unauthorized Debit Card Charge Without Customer Consent
On the evening of July 5, 2026, I did not purchase any course on Coursera.org, nor am I familiar with the course in question.
Shortly thereafter, however, I received an SMS notification from Enpara stating that an attempted transaction on Coursera.org was made using my Encard debit card. The message indicated that the transaction failed because my monthly online spending limit was set too low, but that I could complete the purchase if I increased my limit. I learned through this text message that an attempt was made by this website to withdraw funds from my account without my consent or any manual entry of my card details, and I immediately canceled my card. The fact that such a charge attempt occurred for a high amount—and would have gone through had my limit been higher—amounts to outright theft in my view.
Furthermore, Enpara needs to explain how this charge attempt was even possible using a standard debit card—not a credit card—especially when my card details were not saved on my computer. Bank representatives stated the charge failed because 3D Secure was disabled; however, I strongly emphasize that even if 3D Secure is active, a high-value transaction should always require explicit customer confirmation via a push notification or verification code before any money can be processed. I believe this represents a major security vulnerability.
I demand that Enpara conduct a thorough investigation into this incident, patch this vulnerability, and strengthen its security protocols so transactions cannot be attempted without explicit customer authorization. Regarding Coursera.org, attempting to process payments when a user has neither entered card details nor provided explicit consent is a dangerous practice prone to fraud. I demand that Coursera.org be held accountable to prevent predatory billing attempts, that proper safety checks be implemented, and that my complaint be addressed to protect other consumers from similar harm.





