📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

ClearScore's lax attitude towards personal data security

vadek
vadek Posts: 68 Forumite
Part of the Furniture 10 Posts Name Dropper Photogenic
edited 8 September at 1:24PM in Credit file & ratings
I recently tried to login to ClearScore with an account that I hadn't used for a long time. It rejected my login by telling me that my account already existed. Well, duh!! So I thought I'd try creating a new account, but it refused to accept the password that I'd set a few seconds earlier. So I tried a password reset and again, it refused to accept the new password.
So I contacted ClearScore and, after an initially friendly and helpful email asking which email address I wished to proceed with, they told me to send a picture of my passport or driving licence in the same frame as my face by an email attachment!! Good grief! How unprofessional can you get? Sending this kind of personal data in the clear by email is flouting basic security tenets.
I've now said I'll contact a couple of IT security specialists, and maybe the ICO, with this information to see what they think. I'm furious!

Practising Scrooge and stingy old miser.
«1

Comments

  • MyRealNameToo
    MyRealNameToo Posts: 1,297 Forumite
    1,000 Posts Name Dropper
    What do you expect your "IT security specialists" to tell you? Why spend money on getting the professional opinion of experts about a third party website? 

    Agree emailing things isnt ideal but thousands do it every day without issue. If you dont like their approach to infosec then just move on to another company who you think has a better policy. 
  • vadek
    vadek Posts: 68 Forumite
    Part of the Furniture 10 Posts Name Dropper Photogenic
    edited 8 September at 1:24PM
    What do you expect your "IT security specialists" to tell you? Why spend money on getting the professional opinion of experts about a third party website? 

    Agree emailing things isnt ideal but thousands do it every day without issue. If you dont like their approach to infosec then just move on to another company who you think has a better policy. 

    I don't expect them to tell me anything that I don't already know. I'm basically threatening ClearScore with publicity and maybe an ICO complaint
    ClearScore is the only way to check my Experian credit score for free. I'm not aware of any free alternatives.
    Emailing personal data such as they request may be a thing that people do without understanding the security risks. I don't believe it's worth the risk of potential identity theft.
    Practising Scrooge and stingy old miser.
  • singhini
    singhini Posts: 911 Forumite
    Tenth Anniversary 500 Posts Name Dropper Combo Breaker
    vadek said:
    What do you expect your "IT security specialists" to tell you? Why spend money on getting the professional opinion of experts about a third party website? 

    Agree emailing things isnt ideal but thousands do it every day without issue. If you dont like their approach to infosec then just move on to another company who you think has a better policy. 

    I don't expect them to tell me anything that I don't already know. I'm basically threatening ClearScore with publicity and maybe an ICO complaint
    ClearScore is the only way to check my Experian credit score for free. I'm not aware of any free alternatives.
    Emailing personal data such as they request may be a thing that people do without understanding the security risks. I don't believe it's worth the risk of potential identity theft.
    ClearScore is not the only way to check your Experian credit score (infact its not even possible to check your Experian credit score with ClearScore).
  • All this drama over a fictional number provided by a CRA.
  • MeteredOut
    MeteredOut Posts: 3,294 Forumite
    1,000 Posts Second Anniversary Name Dropper
    edited 8 September at 4:10PM
    Just wondering, what would be the basis of any complaint to the ICO? Yes, asking for both in a single email is not great from a security perspective, but is that in itself a breach of data security?
  • singhini
    singhini Posts: 911 Forumite
    Tenth Anniversary 500 Posts Name Dropper Combo Breaker
    vadek said:
    I recently tried to login to ClearScore with an account that I hadn't used for a long time. It rejected my login by telling me that my account already existed. Well, duh!! So I thought I'd try creating a new account, but it refused to accept the password that I'd set a few seconds earlier. So I tried a password reset and again, it refused to accept the new password.
    So I contacted ClearScore and, after an initially friendly and helpful email asking which email address I wished to proceed with, they told me to send a picture of my passport or driving licence in the same frame as my face by an email attachment!! Good grief! How unprofessional can you get? Sending this kind of personal data in the clear by email is flouting basic security tenets.
    I've now said I'll contact a couple of IT security specialists, and maybe the ICO, with this information to see what they think. I'm furious!

    What are you expecting the IT Security Specialists to do?
  • vadek
    vadek Posts: 68 Forumite
    Part of the Furniture 10 Posts Name Dropper Photogenic
    I'd like to thank everyone for their help and useful advice. As I apparently can't lock this thread or block people (or AI bots), I'm now muting it so that I can't see any more friendly responses.
    Practising Scrooge and stingy old miser.
  • Grumpy_chap
    Grumpy_chap Posts: 18,506 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Combo Breaker
    AIUI, Clearscore uses Equifax.
    I understand that MSE Credit Club previously used Experian but has now changed to an alternative data provider.
  • vadek
    vadek Posts: 68 Forumite
    Part of the Furniture 10 Posts Name Dropper Photogenic
    Experian has a free app. TransUnion is available via MSE Credit Club (or Lloyds Bank, if you're with them). Equifax is only available for free via ClearScore - otherwise you have to pay Equifax (after a free month).
    Practising Scrooge and stingy old miser.
  • Nasqueron
    Nasqueron Posts: 10,900 Forumite
    Part of the Furniture 10,000 Posts Photogenic Name Dropper
    vadek said:
    Experian has a free app. TransUnion is available via MSE Credit Club (or Lloyds Bank, if you're with them). Equifax is only available for free via ClearScore - otherwise you have to pay Equifax (after a free month).
    To block people, click on their profile then (at least on a PC browser) there is an icon of a head/profile next to message, click that and choose Ignore - you can see they have posted sometimes but don't see their messages on the forum

    Sam Vimes' Boots Theory of Socioeconomic Unfairness: 

    People are rich because they spend less money. A poor man buys $10 boots that last a season or two before he's walking in wet shoes and has to buy another pair. A rich man buys $50 boots that are made better and give him 10 years of dry feet. The poor man has spent $100 over those 10 years and still has wet feet.

Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 351.6K Banking & Borrowing
  • 253.3K Reduce Debt & Boost Income
  • 453.9K Spending & Discounts
  • 244.6K Work, Benefits & Business
  • 599.9K Mortgages, Homes & Bills
  • 177.2K Life & Family
  • 258.2K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.2K Discuss & Feedback
  • 37.6K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.