Elon's Vision
  • Contacts
  • Privacy Policy
  • Terms & Conditions
  • News
  • Economy
  • Editor’s Pick
  • Investing
  • Stock
No Result
View All Result
  • News
  • Economy
  • Editor’s Pick
  • Investing
  • Stock
No Result
View All Result
Elon's Vision
No Result
View All Result
Home Investing

Millions of HSBC, NatWest, Monzo, Santander and Starling customers exposed to app security flaw

by
January 12, 2022
in Investing
0
Millions of HSBC, NatWest, Monzo, Santander and Starling customers exposed to app security flaw
0
SHARES
24
VIEWS
Share on FacebookShare on Twitter

Millions of Brits who use online banking services are exposed to some worrying fraud risks, industry experts warned today.

Following an investigation by security experts 6point6, testing the online and mobile app security of 15 major current account providers on a range of criteria, including encryption and protection, login, and account management and navigation, consumer group Which! warned today.

Six banks – HSBC, NatWest, Santander, Starling, the Co-operative Bank and Virgin Money – let people choose passwords that include their first name and/or surname, the research found.

Santander told Which? this is being phased out, while NatWest and Virgin Money said it might now increase password limitations.

TSB, Lloyds, Metro, Nationwide, Santander and the Co-operative Bank also used texts to verify people when logging in, leaving messages at risk of being hijacked by cybercriminals, Which? said.

Santander and the Co-operative Bank told Which? they were looking to move away from this.

Which? also claimed Nationwide, TSB and Virgin Money were not using software that ensures spoof messages sent by potential scammers are blocked or quarantined by someone’s email provider.

TSB told Which? it has since introduced this protection. Virgin Money said it was in the process of doing this. Nationwide said it has “a range of email security controls” to protect members.

HSBC came out most favourably for online banking security, scoring five stars for website encryption and account management. First Direct, which is a division of HSBC UK, was ranked top for mobile app security.

Metro Bank was placed bottom for online security, while Monzo was ranked bottom by Which? for mobile app security.

Which? said Monzo does not ask people to log in every time, with the bank saying this was a “conscious design decision to strike a balance between risk and customer experience”.

A Monzo spokesman said: “We strongly disagree with this assessment. Given every sensitive action or payment requires a customer to provide extra authentication in the form of a Pin or biometrics, the risk associated with remaining logged into the Monzo app is extremely low.

“We take security incredibly seriously and focus on policies and practices that we consider to be safest for Monzo customers.”

Metro Bank said: “Like all financial institutions, we need to remain vigilant to protect our systems and security. We work with other banks collectively to help guard against fraud. We take our customers’ security extremely seriously and have a range of safeguards in place across all channels to help defend them against fraud.”

“As well as the controls which are visible, we have controls in the background which support our customer journeys and provide invisible protection. We are continually evaluating and evolving our controls to prevent fraud.”

Which? said the criteria it looked at included encryption and protection, login, account management, and navigation.

It said every bank and building society has behind-the-scenes security processes and it is not possible for Which? to test these legally.

Jenny Ross, Which? Money editor, said: “Banks must lead the battle against fraud, yet our security tests have revealed worrying flaws when it comes to keeping people safe from the threat of having their account compromised.

“Banks need to up their game on tackling fraud by using the latest protections for their websites and not allowing customers to set insecure passwords. We also want banks to stop sending sensitive data to customers via SMS texts as this could leave the door open to fraudsters.”

Banks emphasised that security is a top priority.

Read more:
Millions of HSBC, NatWest, Monzo, Santander and Starling customers exposed to app security flaw

Previous Post

Smart motorway rollout suspended amid safety concerns

Next Post

Sheffield Forgemasters wins £3.7m contract on Rolls-Royce nuclear project

Next Post
Sheffield Forgemasters wins £3.7m contract on Rolls-Royce nuclear project

Sheffield Forgemasters wins £3.7m contract on Rolls-Royce nuclear project

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Get the daily email that makes reading the news actually enjoyable. Stay informed and entertained, for free.
Your information is secure and your privacy is protected. By opting in you agree to receive emails from us. Remember that you can opt-out any time, we hate spam too!
  • Trending
  • Comments
  • Latest

Jay Bhattacharya on Public Health

October 12, 2021

That Bangladesh Mask Study!

December 1, 2021

Antitrust Regulation Assumes Bureaucrats Know the “Correct” Amount of Competition

November 24, 2021
Pints of champagne could be the next ‘Brexit dividend’

Pints of champagne could be the next ‘Brexit dividend’

December 24, 2021

The Political Business Cycle 50 Years Later

0

0

0

0

The Political Business Cycle 50 Years Later

May 10, 2025

Why Elon Musk Is Right: The Case Against Subsidizing Amtrak

May 10, 2025

The Gold-Silver Ratio

May 10, 2025
Friday Feature: MCP Academy

Friday Feature: MCP Academy

May 9, 2025

Recent News

The Political Business Cycle 50 Years Later

May 10, 2025

Why Elon Musk Is Right: The Case Against Subsidizing Amtrak

May 10, 2025

The Gold-Silver Ratio

May 10, 2025
Friday Feature: MCP Academy

Friday Feature: MCP Academy

May 9, 2025

Disclaimer: ElonsVision.com, its managers, its employees, and assigns (collectively "The Company") do not make any guarantee or warranty about what is advertised above. Information provided by this website is for research purposes only and should not be considered as personalized financial advice. The Company is not affiliated with, nor does it receive compensation from, any specific security. The Company is not registered or licensed by any governing body in any jurisdiction to give investing advice or provide investment recommendation. Any investments recommended here should be taken into consideration only after consulting with your investment advisor and after reviewing the prospectus or financial statements of the company.

  • Contacts
  • Privacy Policy
  • Terms & Conditions

Copyright © 2025 ElonsVision. All Rights Reserved.

No Result
View All Result
  • News
  • Economy
  • Editor’s Pick
  • Investing
  • Stock

Copyright © 2025 ElonsVision. All Rights Reserved.