We’d like to remind Forumites to please avoid political debate on the Forum.

This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!
The Forum now has a brand new text editor, adding a bunch of handy features to use when creating posts. Read more in our how-to guide

Scam from bank

13»

Comments

  • cx6
    cx6 Posts: 1,176 Forumite
    1,000 Posts Name Dropper
    edited 21 October 2021 at 6:34AM
    Unfortunately, NatWest (and Barclays) are less secure than Lloyds in that  they fall foul of one of the basic bits of security in that the first step in internet logon is to ask you to enter either your bank allocated user number OR card number. This is just plain stupid - allowing something as potentially public as your card number to replace your secret user number.

    The scammers didn't know the user number but did have the card (or a copy of it) so could enter the card number.

    Don't have Natwest now but I would bet the next step is to enter characters x y and z of password.
  • Alderbank said:
    My accounts are all with LBG but I suspect NatWest is similar...

    Cashcard and PIN are of no use for accessing my accounts. Mobile banking needs a bank allocated user number, password and a phone which has been pre-approved (they must know IMEA) plus fingerprint.

    Logging on from a pre-approved 'trusted' laptop (they must know MAC no) needs the same user number and password and 3 random numbers from a special word. If it's not a 'trusted' device it also needs a pass code each time sent to my phone.

    The MAC for a network adapter does not propagate beyond the local network segment.  In a home that means it gets as far as your router.  A website you access will never see any MAC on your network, not even that on the external side of your router.

    Mobile phone apps cannot get the IMEA, both google and apple block their APIs from providing this information to apps.
    Proud member of the wokerati, though I don't eat tofu.Home is where my books are.Solar PV 5.2kWp system, SE facing, >1% shading, installed March 2019.Mortgage free July 2023
  • Alderbank
    Alderbank Posts: 4,286 Forumite
    Ninth Anniversary 1,000 Posts Name Dropper
    Thanks for putting me right on that, onomatopoeia. How does the bank's 'trusted devices' stuff work then? Is it just cookies?
  • cx6
    cx6 Posts: 1,176 Forumite
    1,000 Posts Name Dropper
    Yes, when you tick 'trust this device' a cookie is placed - clearing cookies will un-trust the device.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 353.6K Banking & Borrowing
  • 254.2K Reduce Debt & Boost Income
  • 455.1K Spending & Discounts
  • 246.6K Work, Benefits & Business
  • 603K Mortgages, Homes & Bills
  • 178.1K Life & Family
  • 260.6K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16K Discuss & Feedback
  • 37.7K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.