‘Worrying security flaws’ may expose online banking customers to fraud says Which?

Online banking customers are being left exposed to some worrying fraud risks, according to Which?
Watch more of our videos on Shots! 
and live on Freeview channel 276
Visit Shots! now

The consumer group urged providers to “up their game” by using the latest protections for their websites and not allowing customers to set unsecure passwords.

It conducted an investigation with security experts 6point6, testing the online and mobile app security of 15 major current account providers on a range of criteria, including encryption and protection, login, and account management and navigation.

Hide Ad
Hide Ad

Six banks – HSBC, NatWest, Santander, Starling, the Co-operative Bank and Virgin Money – let people choose passwords that include their first name and/or surname, the research found.

MoneyMoney
Money

Santander told Which? this is being phased out, while NatWest and Virgin Money said it might now increase password limitations.

TSB, Lloyds, Metro, Nationwide, Santander and the Co-operative Bank also used texts to verify people when logging in, leaving messages at risk of being hijacked by cybercriminals, Which? said.

Santander and the Co-operative Bank told Which? they were looking to move away from this.

Hide Ad
Hide Ad

Which? also claimed Nationwide, TSB and Virgin Money were not using software that ensures spoof messages sent by potential scammers are blocked or quarantined by someone’s email provider.

TSB told Which? it has since introduced this protection. Virgin Money said it was in the process of doing this. Nationwide said it has “a range of email security controls” to protect members.

HSBC came out most favourably for online banking security, scoring five stars for website encryption and account management. First Direct, which is a division of HSBC UK, was ranked top for mobile app security.

Metro Bank was placed bottom for online security, while Monzo was ranked bottom by Which? for mobile app security.

Hide Ad
Hide Ad

Which? said Monzo does not ask people to log in every time, with the bank saying this was a “conscious design decision to strike a balance between risk and customer experience”.

A Monzo spokesman said: “We strongly disagree with this assessment. Given every sensitive action or payment requires a customer to provide extra authentication in the form of a Pin or biometrics, the risk associated with remaining logged into the Monzo app is extremely low.

“We take security incredibly seriously and focus on policies and practices that we consider to be safest for Monzo customers.”

Metro Bank said: “Like all financial institutions, we need to remain vigilant to protect our systems and security.

Hide Ad
Hide Ad

“In addition, we work with other banks collectively to help guard against fraud. We take our customers’ security extremely seriously and have a range of safeguards in place across all channels to help defend them against fraud.

“As well as the controls which are visible, we have controls in the background which support our customer journeys and provide invisible protection. We are continually evaluating and evolving our controls to prevent fraud.”

Which? said the criteria it looked at included encryption and protection, login, account management, and navigation.

It said every bank and building society has behind-the-scenes security processes and it is not possible for Which? to test these legally.