I haven't seen any evidence of that second case happening with my users (apart from one incident where card thieves discovered my "update your credit card" workflow and used it to sanitize numbers for a few days before I fixed the loophole). But the first one happens all the time.
It'd be adorable in a way, as I'm sure the people doing it think they're totally getting away with something. If, that is, it didn't jeopardize my ability to continue charging credit cards in the future.