We’d like to remind Forumites to please avoid political debate on the Forum.
This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.
📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!
Ford Money Data Breach 1 August 2023
Comments
-
flaneurs_lobster said:
Happened in The City a few years back. A new "Gentleman's Club" had solicited membership enquiries by email and then replied "CC" to the prospective members.
A few names on there raised some eyebrows, even more so that they had used their work email address.
1 -
flaneurs_lobster said:Nothing's been compromised, it's not even a "data breach". Someone has stuck a load of email addresses into "CC" rather than "BC".
Happened in The City a few years back. A new "Gentleman's Club" had solicited membership enquiries by email and then replied "CC" to the prospective members.
A few names on there raised some eyebrows, even more so that they had used their work email address.
ICO does say: "Personal data breaches can include: ... sending personal data to an incorrect recipient" which is what the opening poster is saying happened.
Best wishes.
0 -
I'm struggling to see a real issue here when it comes to security. A third party knowing your email address does not mean anything is compromised.
Presumably the email address has been used for some time with emails being sent to various recipients, all of which could have been subject to data breaches that may have disseminated the email address further and yes, the email could be in the hands of some bad actors. It's sensible to expect your email to be in the hands of bad actors by default.
If sensible security is practiced there's little risk. If your email address is dunce@hotmail.com and your password is also dunce, that's a problem - someone could log into your email account. If dunce is also used as a password for multiple services on the internet, there's another problem. If you click links in emails received without thought, then that's yet another problem - these are all problems with the email owner though.
It's a bit extreme to get very hurty because Ford included your email address in the CC field.
Personally, I've had my email address for 20 years now, I'm on multiple spam databases, I get spam all the time (hooray for junk filters - though I do dip in occasionally to amuse myself with the frequent "YOU DO NOT KNOW ME BUT I WISH TO SEND YOU A MILLION USD" or "I HACKED YOUR WEBCAM AND I HAVE COMPROMISING VIDEO OF YOU" emails). I'm also listed in multiple data breaches according to haveibeenpwned.
However, I've not once been scammed, compromised, played host to trojan horse software etc etc etc.
5 -
DeLaSole said:flaneurs_lobster said:Nothing's been compromised, it's not even a "data breach". Someone has stuck a load of email addresses into "CC" rather than "BC".
Happened in The City a few years back. A new "Gentleman's Club" had solicited membership enquiries by email and then replied "CC" to the prospective members.
A few names on there raised some eyebrows, even more so that they had used their work email address.
ICO does say: "Personal data breaches can include: ... sending personal data to an incorrect recipient" which is what the opening poster is saying happened.
Best wishes.
See my post just above1 -
DeLaSole said:flaneurs_lobster said:Nothing's been compromised, it's not even a "data breach". Someone has stuck a load of email addresses into "CC" rather than "BC".
Happened in The City a few years back. A new "Gentleman's Club" had solicited membership enquiries by email and then replied "CC" to the prospective members.
A few names on there raised some eyebrows, even more so that they had used their work email address.
ICO does say: "Personal data breaches can include: ... sending personal data to an incorrect recipient" which is what the opening poster is saying happened.
Best wishes.3 -
booneruk said:DeLaSole said:flaneurs_lobster said:Nothing's been compromised, it's not even a "data breach". Someone has stuck a load of email addresses into "CC" rather than "BC".
Happened in The City a few years back. A new "Gentleman's Club" had solicited membership enquiries by email and then replied "CC" to the prospective members.
A few names on there raised some eyebrows, even more so that they had used their work email address.
ICO does say: "Personal data breaches can include: ... sending personal data to an incorrect recipient" which is what the opening poster is saying happened.
Best wishes.
See my post just above
Like you, and I guess most posting, I do not share the underlying worry of the OP/OP's relative. But as the title of thread includes 'Ford Money Data Breach' then I just think it's reasonable not to use what we individually believe is a data breach based on our personal assessment of seriousness of situation, but rather what the ICO says can constitute a data breach.
Best wishes.
0 -
eskbanker said:LikeaDream said:The relative is now so upset at Ford Money's dismissive attitude that I hope Martin Lewis can get the FCE Bank to actually help all those Ford Money customers to be safe and secure.2
-
Growingold said:I'm a FORD Money customer and I didn;t receive any email about any competitiion results. I hadn't even known they were running one. Did other Ford Money customers receive one?
Was this a scam maybe?
Only those Ford Money customers that entered a Ford Money competition had their personal identification data breached. The data breach is limited to those hundreds of customers that trusted Ford Money with their personal data. Ford Money has now been forced to implement email training and upgrade its email systems. But is doing nothing to help customers clean up personal email systems polluted with hundreds of Ford Money customers' email addresses. They've admitted the data breach was due to a mistake and obviously lack of email training and the right email software for data security. They've offered a token gesture of goodwill but that's their full and final offer and to get proper compensation make a complaint to the Financial Ombudsman Service and the Office of the Information Commissioner.
0 -
jimjames said:This does seem a rather big overreaction calling this a compromise situation that's relying on multiple stages happening for anything to even be breached. It's nothing to do with Ford Money whether an email password has been changed and makes absolutely no difference to the security of your relative's email address. If a device has been compromised I suspect that the recipients of one email amongst thousands is unlikely to be top of the list for a hacker to access when far easier sources of email addresses are available. On it's own an email address isn't really going to do much, I'm not sure how bigjim1998@hotmail is going to link to my name or address for example.
Remember that each recipient of the Ford Money competition winner being chosen email also received all of the email addresses of all the other recipients. In two data breach emails. Unfortunately, many of the competition entrants used an email address like firstname.lastname@ so hackers accessing a compromised device will link the email to hundreds of known Ford Money savings customer and in many cases be able to deduce the customer names thus making it easier for a follow up phishing email to appear genuine. But Ford Money are ignoring the possibility of any of the hundreds of email devices being compromised and assert there's no risk of fraud to any when we see almost daily cases reported in the media of customers being conned into trusting scammers and fraud taking place.
0 -
Maybe it's me, but I'm just not getting the concern over this and quite how computers have been "polluted with hundreds of Ford Money customers' email addresses" - they'll just be in the header of one email - just hit the delete key and then empty your trash folder, job done. The yobs walking home past my house from a nearby gym and lobbing energy drink cans into my foliage cause more pollution. I utter a couple of expletives and put the offending articles in my recycling bin - problem solved. It's a bit more effort if the can wasn't empty and I get a sticky puddle on my garden furniture - I might utter a few more rude words.
The only thing that might concern me modestly is people now having my email address and what that might lead to. But I'd like to think that the kind of person that saves with Ford Money might be above doing anything outright malicious with it. If I was really concerned, I'd change the email used with my Ford account and be more vigilant about mail from them and what address it was sent to. Not sure that modest effort requires compensating.0
Confirm your email address to Create Threads and Reply

Categories
- All Categories
- 352.1K Banking & Borrowing
- 253.6K Reduce Debt & Boost Income
- 454.2K Spending & Discounts
- 245.1K Work, Benefits & Business
- 600.8K Mortgages, Homes & Bills
- 177.5K Life & Family
- 258.9K Travel & Transport
- 1.5M Hobbies & Leisure
- 16.1K Discuss & Feedback
- 37.6K Read-Only Boards