o2 ID theft flaw

Options
easyhost
easyhost Posts: 424 Forumite
i recently (yesterday) got a pay monthly phone from o2 after moving from a pay and go phone.

using their keep your number online feature it states

"To say thanks for staying with O2 we're going to send you a text with a unique code in it. You can use this code to claim a free £5 Marks & Spencer voucher at o2mandspromo.co.uk."

this never arrived so phoned their customer services and was told to email mycare(at)o2mail.co.uk as they deal with all online services, but then i get the below emailed reply

"Hello O2 Customer,
Thank you for emailing us, we'll get back to you within 72 hours with
the answers you need.

**********************************************************************
By the way, as you've not contacted us directly from our website, you
might not have included the security information we need to answer your
email.

The security information that we need is this:

- Full name:
- Date of Birth:
- Postcode:
- Mobile number:
- Email address:

If you've not included this, don't worry, just send another email (with
just this information in it) to mycare(at) o2mail.co.uk straight away. We
won't be able to answer your query without it.
**********************************************************************"

which anyone knows that you dont send such sensitive details via unsecure email as this is open to ID theft, so i called customer services back and they told me that if this is what they request then you have to do what they request or you wont get the offer.

Comments

  • parallax_20
    parallax_20 Posts: 546 Forumite
    Options
    easyhost wrote: »
    i recently (yesterday) got a pay monthly phone from o2 after moving from a pay and go phone.

    using their keep your number online feature it states

    "To say thanks for staying with O2 we're going to send you a text with a unique code in it. You can use this code to claim a free £5 Marks & Spencer voucher at o2mandspromo.co.uk."

    this never arrived so phoned their customer services and was told to email mycare(at)o2mail.co.uk as they deal with all online services, but then i get the below emailed reply

    "Hello O2 Customer,
    Thank you for emailing us, we'll get back to you within 72 hours with
    the answers you need.

    **********************************************************************
    By the way, as you've not contacted us directly from our website, you
    might not have included the security information we need to answer your
    email.

    The security information that we need is this:

    - Full name:
    - Date of Birth:
    - Postcode:
    - Mobile number:
    - Email address:

    If you've not included this, don't worry, just send another email (with
    just this information in it) to mycare(at) o2mail.co.uk
    straight away. We
    won't be able to answer your query without it.
    **********************************************************************"

    which anyone knows that you dont send such sensitive details via unsecure email as this is open to ID theft, so i called customer services back and they told me that if this is what they request then you have to do what they request or you wont get the offer.

    Did you put in the brackets and the "(at)"? If not that would immediately ring alarm bells for me as a fishing email.
  • easyhost
    easyhost Posts: 424 Forumite
    Options
    Did you put in the brackets and the "(at)"? If not that would immediately ring alarm bells for me as a fishing email.

    I placed the "(at)" as being a newbie of this forum i could not post with links and the email was from o2 guaranteed
  • parallax_20
    parallax_20 Posts: 546 Forumite
    Options
    My bad. :) It says it can take 48 hrs to transfer your number, depending on when you submitted the form it may not get actioned immediately. I'm presuming once the numbers been transfered to O2 they would be sending the text out to you shortly after. So I think its still a bit early to start chasing it up if you've only submitted the form yesterday. It'll be silly to send it the text out to a number that will be defunct prior to transfer.
  • easyhost
    easyhost Posts: 424 Forumite
    Options
    My bad. :) It says it can take 48 hrs to transfer your number, depending on when you submitted the form it may not get actioned immediately. I'm presuming once the numbers been transfered to O2 they would be sending the text out to you shortly after. So I think its still a bit early to start chasing it up if you've only submitted the form yesterday. It'll be silly to send it the text out to a number that will be defunct prior to transfer.

    number already transferred busy on live chat with o2 now see below, but they clearly state

    Ian: I've read it and don't worry, whenever you email on the above email address it comes straight to us. Be assured we don't disclose your personal details to anyone else.

    which is not true as emails are unsecure

    Welcome to O2 live chat. Someone will start chatting with you soon. You're through to Ian.
    Ian: Hi I'm Ian from O2 Online Chat. How can I help you today?
    Terry Robertson: i am not happy read below
    Terry Robertson: i recently (yesterday) got a pay monthly phone from o2 after moving from a pay and go phone. using their keep your number online feature it states "To say thanks for staying with O2 we're going to send you a text with a unique code in it. You can use this code to claim a free £5 Marks & Spencer voucher at o2mandspromo.co.uk." this never arrived so phoned their customer services and was told to email mycare(at)o2mail.co.uk as they deal with all online services, but then i get the below emailed reply "Hello O2 Customer, Thank you for emailing us, we'll get back to you within 72 hours with the answers you need. ********************************************************************** By the way, as you've not contacted us directly from our website, you might not have included the security information we need to answer your email. The security information that we need is this: - Full name: - Date of Birth: - Postcode: - Mobile number: - Email address: If you've not included this, don't worry, just send another email (with just this information in it) to mycare(at)o2mail.co.uk straight away. We won't be able to answer your query without it. **********************************************************************" which anyone knows that you dont send such sensitive details via unsecure email as this is open to ID theft, so i called customer services back and they told me that if this is what they request then you have to do what they request or you wont get the offer.
    Ian: I'm sorry about that. Give me 2 minutes while I read it.
    Ian: I've read it and don't worry, whenever you email on the above email address it comes straight to us. Be assured we don't disclose your personal details to anyone else.
    Terry Robertson: but standard email is unsecure, that means anyone can tap and take these details without either party knowing of this. i have been in the internet business for well over 10 years an know that sensitive emails should not be sent using standard email and i guarantee i will not send such details in suuch a way
    Ian: I can understand that. Don't worry, simply sign in to your online account and there you'll find email us link. Click on it to send us an email. Or if you want I can also help send an email on your behalf of you. Do you have the text with a M&S voucher unique code in it
    Terry Robertson: no i dont have the txt with the code, this is why i contact o2 in the first place
    Ian: I'm sorry about that. You can also contact our team who deal with the vouchers on 0844 561 5535. and they'll help you further.
    Terry Robertson: so its coing to cost me to sort this out, when it should have been done automatically accourding to your site
    Ian: I agree with you but it's a offer given to our pay and go customers from the third party company. Or else send an email on the above address and we'll take care of it for you.
    Ian: You can call us on 202 free from your mobile to get the code between Monday to Friday 8am to 9pm , Saturday 8am to 8pm & Sunday 8am to 6pm.
  • DCFC79
    DCFC79 Posts: 40,598 Forumite
    Name Dropper First Anniversary First Post
    Options
    So why not call on 202 either today or tomorrow
  • easyhost
    easyhost Posts: 424 Forumite
    Options
    DCFC79 wrote: »
    So why not call on 202 either today or tomorrow

    well guess what this is what i did originally and was told to email the my care team whos reply was

    "Hello O2 Customer, Thank you for emailing us, we'll get back to you within 72 hours with the answers you need. ************************************************** ******************** By the way, as you've not contacted us directly from our website, you might not have included the security information we need to answer your email. The security information that we need is this: - Full name: - Date of Birth: - Postcode: - Mobile number: - Email address: If you've not included this, don't worry, just send another email (with just this information in it) to mycare(at)o2mail.co.uk straight away. We won't be able to answer your query without it. ************************************************** ********************"
  • williham
    williham Posts: 1,223 Forumite
    Options
    Log in to the website then like he said..
This discussion has been closed.
Meet your Ambassadors

Categories

  • All Categories
  • 343.3K Banking & Borrowing
  • 250.1K Reduce Debt & Boost Income
  • 449.7K Spending & Discounts
  • 235.3K Work, Benefits & Business
  • 608.1K Mortgages, Homes & Bills
  • 173.1K Life & Family
  • 248K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 15.9K Discuss & Feedback
  • 15.1K Coronavirus Support Boards