We’d like to remind Forumites to please avoid political debate on the Forum.

This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!
The Forum now has a brand new text editor, adding a bunch of handy features to use when creating posts. Read more in our how-to guide

HSBC Refusing to refund stolen £1100!

245

Comments

  • paragon909 wrote: »
    Go to the police and report fraud, Use the name and account details it were sent to and the police will be able to trace the person or where it went but might not disclose information.

    Have you been to the police???

    Not yet, something I am going to do
  • I have seen that exact same letter a few months ago with someone who had a unauthorised transaction at a petrol station.
    It's a generic fob off letter, they backed down prior to the FOS taking the case and apologised.
    They appear to wait and see who takes them up in the ring before putting gloves on.
    Why not ? must save them a fortune.
    I do Contracts, all day every day.
  • 10pence wrote: »
    HSBC Secure Key doesn't have a slot for a card to be inserted - Barlcays does but not HSBC's device.

    Card and PIN number aren't used or necessary.

    If I recall correctly, the Secure Key is only needed at the end of creating and paying a new FP beneficiary, where you input the last few digits of the beneficiary account number.

    AS well as filing a complint with the bank I would first report it to Action Fraud, then you can supply HSBC a crime reference number.

    Don't b surprised if HSBC demand you do some security checks on your computer, as in they ask you to check for malware etc, as having out of date anti-malware could be deemed enough to show you've not taken enough precautions to protect you PC and thus PIB (Personal Internet Banking). They use to block PIB and only reactivate it after you've signed a form stating you've made these checks.

    You are correct about the secure key. Thanks for the link
  • I have seen that exact same letter a few months ago with someone who had a unauthorised transaction at a petrol station.
    It's a generic fob off letter, they backed down prior to the FOS taking the case and apologised.
    They appear to wait and see who takes them up in the ring before putting gloves on.
    Why not ? must save them a fortune.

    Can't believe a bank would take advantage of its customers like that. Ombudsman are now investigating it and I have also reported to Action Fraud, don't think there's much more I can do except wait and see what happens :(
  • I have seen that exact same letter a few months ago with someone who had a unauthorised transaction at a petrol station.
    It's a generic fob off letter, they backed down prior to the FOS taking the case and apologised.
    They appear to wait and see who takes them up in the ring before putting gloves on.
    Why not ? must save them a fortune.

    I'll disagree

    That secure key is unique and would have been used to authorise the payment
  • starM
    starM Posts: 1,464 Forumite
    How can someone setup a new bill payment without having access to secure key?

    In HSBC response they will say correct secure key and pin number was used. So the op did the payment himself or provided the details to someone to make the payment.
  • 10pence
    10pence Posts: 348 Forumite
    SimonSays wrote: »
    I'll disagree

    That secure key is unique and would have been used to authorise the payment
    starM wrote: »
    How can someone setup a new bill payment without having access to secure key?

    In HSBC response they will say correct secure key and pin number was used. So the op did the payment himself or provided the details to someone to make the payment.

    Man-in-the-Browser attacks could be a possibility. This is why the OP would need to make certain they have no malware on computer.
  • They are several papers on this systems vulnerability.
    The transaction can be intercepted anywhere between user and bank.
    A quick google will show just how vulnerable this is.
    If the transaction was not your doing, then the FOS is the path to stick to.
    I do Contracts, all day every day.
  • Thrugelmir
    Thrugelmir Posts: 89,546 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    It's also worth knowing that it costs a financial institution £500+ to simply answer a case at the ombudsman irrespective of any outcome.

    No it doesn't.
    when does a case fee become chargeable?

    Fewer than one in six of the initial complaints and enquiries we receive to our front-line customer helpline become chargeable cases. The other complaints and enquiries usually involve issues that we don’t deal with – or where we can sort things out informally at a very early stage.

    In any event the customer always pays in the end. So a short sighted view.
  • Man in the browser attacks could certainly allow somebody to see your account while you are logged in and possibly transfer money between your accounts or to your existing payees. But to set up a NEW payee that can only be done, as said, if they possessed your secure key device which you have in your hands.
    Of course it may not have been done via online banking despite what they say. It is a clear case of fraud and the bank needs to investigate.
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 354.3K Banking & Borrowing
  • 254.4K Reduce Debt & Boost Income
  • 455.4K Spending & Discounts
  • 247.3K Work, Benefits & Business
  • 604K Mortgages, Homes & Bills
  • 178.4K Life & Family
  • 261.5K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16K Discuss & Feedback
  • 37.7K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.