We’d like to remind Forumites to please avoid political debate on the Forum.

This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

Cyber security, savings accounts and banks

I had a query about an ISA with a UK BS which I posted via secure message. I received a call from them and they wanted me to prove who I was by revealing personal information and password details. Although I'm fairly confident the call is genuine is there no UK standard for banks and BS to prove who they are when they call? It seems to be an open invitation for fraudsters. A simple password or the secure message ref number only known to the customer and the bank might help. Any views?
«1

Comments

  • Eyeful
    Eyeful Posts: 1,034 Forumite
    1,000 Posts Fourth Anniversary Name Dropper
    So call them on a number you know is theirs, go through security and ask your question and get an answer.
    The scammers already find ways around passwords, so I think they would find a way around your method.
  • eskbanker
    eskbanker Posts: 37,837 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    I don't believe there's a standard for such verbal ID verification but would agree that it's less than ideal to make outbound calls when secure messaging was used to initiate contact - which BS are you referring to and exactly what did they ask for?
  • born_again
    born_again Posts: 20,985 Forumite
    10,000 Posts Sixth Anniversary Name Dropper
    JSmith321 said:
    I had a query about an ISA with a UK BS which I posted via secure message. I received a call from them and they wanted me to prove who I was by revealing personal information and password details. Although I'm fairly confident the call is genuine is there no UK standard for banks and BS to prove who they are when they call? It seems to be an open invitation for fraudsters. A simple password or the secure message ref number only known to the customer and the bank might help. Any views?
    Actually a standard would be less secure. As fraudsters would know exactly what is required.

    Best way to deal with this is to simply say. I will call back. Then use a known number. If on a landline. Then make sure that there is a dialling tone before calling. Or you could end up with fraudster still on the line.
    Life in the slow lane
  • eskbanker
    eskbanker Posts: 37,837 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    born_again said:
    If on a landline. Then make sure that there is a dialling tone before calling. Or you could end up with fraudster still on the line.
    I thought the basis of such scams was the fraudsters playing a recording of a dialling tone in order to trick the punter into believing that they'd terminated the previous call, so merely hearing a dialling tone isn't sufficient to be sure of not succumbing to the scam....
  • mon3ysav3r
    mon3ysav3r Posts: 103 Forumite
    100 Posts Name Dropper Photogenic
    Using a different phone is the only real way to be sure you are making a genuine new call. 

    I had this when a credit card company phoned me due to actual fraud (a restaurant copied my credit card, the old we can't get a signal here and moved out of view to clone it). The credit card company refused to tell me what it was about unless I gave them personal information and I refused because they wouldn't provide anything to prove that they were genuine. I ended up phoning back on their main number, they then proceeded to ask had I been withdrawing cash using my credit card in India, I was phoning from a UK land line!
  • Eco_Miser
    Eco_Miser Posts: 4,902 Forumite
    Part of the Furniture 1,000 Posts Photogenic Name Dropper
    Eyeful said:
    The scammers already find ways around passwords, so I think they would find a way around your method.
    Since their method involves the bank quoting a reference number generated when the customer contacted them, there's no way a scammer could know that number. A hacker, possibly, but in that case they could just clear out the account by themselves.

    Eco Miser
    Saving money for well over half a century
  • haze23
    haze23 Posts: 35 Forumite
    10 Posts First Anniversary
    I do think this is a valid concern for customers and companies could and should do better.

    On the one hand, everyone is warned about scams, safeguard your details, jump through hoops to contact them etc. On the other hand they expect you to give out those same details to an unscheduled call from an unknown number simply by saying they are from company X. They put all the risk on you; even if they somehow end up paying as a result of a future scam the impact on the individual is likely far greater, and it feels avoidable.

    Whilst advice to call back on their public number is a sensible option, unfortunately it doesn't always work. Some enquiries may have been passed on to other teams, or even a single person and it can be very difficult to get in touch with them directly. Or the front line guardians have no idea about who was calling. At best all you achieve is a response they'll call back at some unspecified point. Back to the original problem. And yes, I've have people call and refuse to give a reference number first 'for data protection' but expect to be given security details.

    So, with the OP on this one.
  • dunstonh
    dunstonh Posts: 120,009 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Combo Breaker
    I had a query about an ISA with a UK BS which I posted via secure message. I received a call from them and they wanted me to prove who I was by revealing personal information and password details.
    Banks never want you to reveal password details.  Although some banks will operate a secondary password purely for internal ID purposes (such as phone banking) and may ask for certain letters in that password.



    I am an Independent Financial Adviser (IFA). The comments I make are just my opinion and are for discussion purposes only. They are not financial advice and you should not treat them as such. If you feel an area discussed may be relevant to you, then please seek advice from an Independent Financial Adviser local to you.
  • DjangoUnchained
    DjangoUnchained Posts: 548 Forumite
    500 Posts Fourth Anniversary Name Dropper
    Had a strange experience last year with barclays. My wife got a phone call one evening claiming to be from barclays fraud team, blah blah and was aking her to confirm things. I overheard and told her to not say anything, i said we would call barclays , on another phone . The caller got quite irate, saying they needed to sort it out quickly. Alarm bells told me it was a scam and to hang up.  we did call barclays, different phone, looked up number. Turned out the fraud call was genuine and there was some nonsence going on with her account. We both complained that the guy who called us acted like a scammer, and we believed we were doing everything correct as regards to how we should treat these calls. The person agreed with us and said it would be looked into ( some chance). Basically we are warned and prepared for scam calls, then a genuine bank acts in a scammy manor . 
  • eskbanker
    eskbanker Posts: 37,837 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    We both complained that the guy who called us acted like a scammer, and we believed we were doing everything correct as regards to how we should treat these calls. The person agreed with us and said it would be looked into ( some chance).
    Was this a proper formal complaint, i.e. logged with a reference number, etc, or just a passing comment?
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 351.7K Banking & Borrowing
  • 253.4K Reduce Debt & Boost Income
  • 454K Spending & Discounts
  • 244.7K Work, Benefits & Business
  • 600.1K Mortgages, Homes & Bills
  • 177.3K Life & Family
  • 258.4K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.2K Discuss & Feedback
  • 37.6K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.