We’d like to remind Forumites to please avoid political debate on the Forum.

This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

RBS online security

2456

Comments

  • agrinnall
    agrinnall Posts: 23,344 Forumite
    10,000 Posts Combo Breaker
    c_smith wrote: »
    From what I was told, the fraudster knew the customer number and had the password reset from that. I have no idea how they could have got this information as I have never revealed it to anyone and the only two computers I use are both at home and are both secure.

    Until you mentioned it, I hadn't considered the security number part of it and this was never mentioned by the fraud dept. Are you saying the person responsible would have had to have at least know the security number in order to get the password reset?

    I'm going to contact them again on Monday now to establish whether this is the case or whether they reset both the security number and password at the same time, as that would indicate an even bigger security failing.

    The highlighted part is why they will have suggested to you that a keylogger may be responsible. What have you scanned with to determine that your computers are clean? You'd probably need to employ several methods to be absolutely sure.
  • stclair
    stclair Posts: 6,855 Forumite
    Part of the Furniture 1,000 Posts Name Dropper
    Mandelbrot wrote: »
    Is the password resetting operation based in the UK or India?

    All customer speaking departments are based in the UK.
    Im an ex employee RBS Group
    However Any Opinion Given On MSE Is Strictly My Own
  • c_smith
    c_smith Posts: 383 Forumite
    Part of the Furniture 100 Posts Combo Breaker
    agrinnall wrote: »
    The highlighted part is why they will have suggested to you that a keylogger may be responsible. What have you scanned with to determine that your computers are clean? You'd probably need to employ several methods to be absolutely sure.

    The customer number used by the bank incase you don't know, is based on your date of birth. The "random" part of my customer number (that is no more) would have been extremely easy for someone to guess. And then there is also the possibility of some unscrupulous bank employee passing on information.

    I have completed a full scan with Avast, a boot scan with Avast, an online scan with Bit Defender, a full Spybot scan, a Malwarebytes scan, and I've also checked that there are no suspicious running processes with Security Task Manager.

    Any other suggestions to be sure?
  • jalexa
    jalexa Posts: 3,448 Forumite
    edited 30 June 2012 at 5:13PM
    c_smith wrote: »
    The "random" part of my customer number (that is no more) would have been extremely easy for someone to guess.

    Err... why? AFAIAA its 1 in 100 for 2 digits. Are you suggesting its not "random"?

    Anyway IMO, and in the absence of the tape it remains a theory, the key to this is not your conduct and practice but the conduct of the "reset". A salient question for RBS to answer would be the Caller ID of the telephone call and specific process to handle non-landline or number withheld calls. And I'm curious about "bank security [later] realised there was an issue" unless that was exceeding the login attempt account (and there was no login).
  • stclair
    stclair Posts: 6,855 Forumite
    Part of the Furniture 1,000 Posts Name Dropper
    The customer number is built up of your DOB and the last 4 digits relate to the amount of customers with the same DOB as you.
    Im an ex employee RBS Group
    However Any Opinion Given On MSE Is Strictly My Own
  • Mandelbrot
    Mandelbrot Posts: 9,139 Forumite
    Rampant Recycler
    stclair wrote: »
    The customer number is built up of your DOB and the last 4 digits relate to the amount of customers with the same DOB as you.

    Any more 'secrets' you wish to share about RBS security? ;)
  • c_smith
    c_smith Posts: 383 Forumite
    Part of the Furniture 100 Posts Combo Breaker
    stclair, I see you work for the group, do you know if both the security number and the password can be reset at the same time for immediate use? If so, this would seem to be a huge security issue.
  • DCFC79
    DCFC79 Posts: 40,641 Forumite
    Part of the Furniture 10,000 Posts Name Dropper
    edited 30 June 2012 at 5:27PM
    Mandelbrot wrote: »
    Any more 'secrets' you wish to share about RBS security? ;)

    Hardly a secret, ive also heard in the past about the last four represent how many people have the same DOB as you.
  • stclair
    stclair Posts: 6,855 Forumite
    Part of the Furniture 1,000 Posts Name Dropper
    Mandelbrot wrote: »
    Any more 'secrets' you wish to share about RBS security? ;)

    It's not a secret it never has been customers always get told that information!
    Im an ex employee RBS Group
    However Any Opinion Given On MSE Is Strictly My Own
  • cbrown372
    cbrown372 Posts: 1,513 Forumite
    Part of the Furniture 1,000 Posts Name Dropper
    fraud call centre is open 24/7 so you can call them now
    Its not that we have more patience as we grow older, its just that we're too tired to care about all the pointless drama ;)
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 352.3K Banking & Borrowing
  • 253.6K Reduce Debt & Boost Income
  • 454.3K Spending & Discounts
  • 245.3K Work, Benefits & Business
  • 601.1K Mortgages, Homes & Bills
  • 177.6K Life & Family
  • 259.2K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16K Discuss & Feedback
  • 37.7K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.