Tesco Bank halts online payments after money was taken from 20K accounts
bbc.co.uk
bbc.co.uk
If someone is living month to month, said £500 missing could be very serious complication of life and £25 "emergency fund" is a joke. I personally doubt a wealthy person would use that bank and yet they seem to think their customers are pissing gold.
Actually they give a decent interest rate (relative to the competition) of 3% on the first £3,000[0] so I know a few people who have multiple accounts with them just to reap the interest.
Anyway, £6 (or £7.50) is the price of a meal. £72 (or £90) is the price of a few decent Christmas presents. These things add up.
Real, not nominal, returns are what people care about.
Yes but I think the point the person you're replying to is trying to make is that it doesn't matter because the inflation rate is not dependent on where you put your money.
Shouldn't the comparison be to the interest rates and risk with comparable places to put/invest your money? I suppose if inflation were extremely high or low compared to interest rates then it would affect your appetite for risk vs interest rate, but I don't think that's the case here.
There’s a website[0] dedicated to helping with this style of saving, so I think it’s a fairly popular thing with people who don’t want to leave money on the table.
(If you opening multiple ones, and juggling money between them or whatever, you're probably just the sort of person who gets a kick out of doing this sort of thing, and so the exact figure is beside the point...)
"Overseas Trade Statistics. In July 2016 the value of exports (EU and Non-EU) decreased to £23.9 billion, and imports (EU and Non-EU) decreased to £39.7 billion, compared with last month. Consequently the UK is a net importer this month, with imports exceeding exports by £15.9 billion."
https://www.uktradeinfo.com/Statistics/OverseasTradeStatisti...
(It went from +3 to 0.)
PS: I didn't downvote you.
Then again, maybe I am overly cynical. UK utilities at least do seem to have a more positive approach towards people struggling to pay than other countries.
I am astonished how many people in this discussion are completely unaware of the idea that some people aren't as lucky as us and work paycheque-to-paycheque. I know HN/SV is a bubble, but surely we're not so out of touch with reality...
And you're spot on - there are so many people juggling these financial balls that one slip up can cause issues for years.
For example, there are still open and active claims in case of NextBank that has been shut down in 2002, and had some updates on status done in early 2015, some 13 years later [1]
Personally I suggest keeping 70% of your financial assets in cash in safe at home, preferably split into 20% in low-volume silver coins (80% silver) and 20% in foreign currency (EUR) and the rest in USD.
[1] https://www.fdic.gov/bank/individual/failed/banklist.html
Yes, if you're living during the Great Depression perhaps but your suggest is ludicrous. Maybe a few percentage points in crypto and cash, but most of it should be in your bank/investment accounts.
Meanwhile banks wage war on cash. Its harder and harder to withdraw your own money. Here, try and show up at your bank say you need $150,000. They tell you to come back in few days, and in some cases they will ask you to fill out the form and explain yourself why you want to withdraw your own money.
If you do not live in a reasonably safe neighborhood, plus do not owe an alarm system, plus do not owe a safe, plus do not awe a firearm, then yes the bank is your best friend. Other than that no reason to keep some federal paper at someone's else possession at their disposal for a mere 0.5% per year. You don't gain anything and in some cases, you might lose some or all of it (yes extreme scenarios but always)
Here few articles to continue...
http://dailycaller.com/2014/01/29/bank-refuses-to-give-custo...
http://thefreethoughtproject.com/feds-banks-inform-law-enfor...
http://www.bbc.com/news/business-25861717
and here this one quick very informative read: http://www.rd.com/advice/saving-money/secrets-bank-teller-wo...
ps. in all fairness I would say keep 70% in gold or silver, but over the years this commodity has been shifted between the countries in such huge quantity (government buy/sell-outs), that the price is dictate by which country has specific political system and how much PM they owe, rather than true market price. Unless you can predict you won't need to turn your PM into cash within next 5-10 years, which is hard calculation for anyone these days.
Or maybe invest in some extra firepower?
It's not so relevant here, but in the case that the bank became insolvent (very unlikely in this case), FSCS aims to pay out within 7 days, and will pay all claims within 20 days.
These are people who may have to pay rent more than once a month, have direct debits for bills and more likely than not not have an overdraft over 100£ if at all.
If your bills bounce you will end up with fines, and even a lower credit score than the one which prompted you to open an account with Tesco in the first place.
What's interesting is that I signed us up for Tesco bank account but we were both rejected. Probably because we didn't have any history in UK yet but it still kind of sucked - now I am glad they rejected us. Ultimately the next day we went to red and blue US bank on the high street and got it all sorted within half an hour. We showed them contracts, documents and bills to our names (real estate agency through which we rent already sorted that out for us before we came) and we were done. Got our cards made at the spot as well.
So it was kind of the opposite for us. We could't get the bank account with Tesco because of their "security check" but could at the high street bank.
I normally use the phrase 'High Street bank' to mean those that have a branch on most high streets and range from unhelpful to really unhelpful. That's useful to know that Metro bank are living up to a different reputation.
As far as I know, they're not related.
I've been working in a variety of EU countries, with no issues at all. In Denmark, I was even able to secure a mortgage within my second week in the country.
I always work for very reputable employers, with long-term contracts. And I have some savings. Well, here in the UK I have had enormous trouble to lease a £100 / month car after 2 years in the country because I did not reach 3 years of credit history.
Most of the heuristics they use are a joke. And illegal. If you have a chat with the Financial Ombudsman, he can probably sort you out.
I escalated this to the Ombudsman, just to piss them off for the poor treatment... magically they offered me a SIM and an (half-)apology.
The various id requirements and 3-year credit history expectation are basically workarounds for this.
Some banks even allow opening the bank account over the internet if you are a EU resident.
(I know your pain though, opened a UK bank account a year ago, from the EU as well. The most difficult thing for me was actually the proof of address. Metro Bank required 2 plus 2 proofs of ID, a different bank was fine with just one proof of identity and even googled my post code when I forgot a letter :) )
You don't need to prove a UK address, just an address. Depending on the bank, you can open a UK bank account with an overseas address, and change it after you move.
If you haven't planned ahead, then anecdotally Barclays will open an account in branch with only a passport.
http://expatriates.stackexchange.com/questions/85/how-to-ope...
That's how I got my first UK account.
I told them to sod off and to look up the company in the company house.
Passport Accounts in the UK are pretty limited with what you can do with them, so I don't advise opening one up front if you planning to immigrate.
Just ask your employer for a cash advance and either use cash for the first 2-4 weeks or use your debit/credit card from your previous country of residence.
When I relocated initially I've arranged that the employer will cover the hotel upto 6 weeks, provide everything needed for a bank account, provide/cover the accountant needed to sort any tax liabilities when moving funds, cover the deposit for the first rental and the agent fees.
If you are hired by a large corp which does relocation all the time they'll have a standard and even a better package, if they company doesn't do relocation on a regular basis make sure all your sides are covered.
Otherwise you can land in a limbo state where you need a bank account to rent a flat, and you need an address (a hotel won't do) to open a bank account (they ask for a utility bill).
Do you know if the the £800 was all there was in that particular account?
The difference is between whether this is seen as a bank robbery, or a series of minor incidents of identity theft.
So... it sounds like there wasn't a widespread theft of account credentials, and that the attack was some kind of weakness in the bank's online systems. Perhaps the attackers found a way to log in to accounts bypassing the usual security checks? But that still doesn't explain it all.
All my online accounts have extra security when I create a payment to a new individual. Some have an extra password check, some have SMS validation, and so on. All of them send me a notification of a new payment being added. And yet there doesn't seem to be reports of Tesco customers getting any of these kind of messages. People only found about the losses when they logged into their accounts, or when Tesco broadcast a "we've been hacked" message to everyone.
Does anyone know what could have happened here?
/transfer_money?from_account=NNNN&to_account=MMMM&amount=$$$$
It would actually be really interesting if they faxed in transfer forms or something.Forex typically means buying or selling currencies, not transferring money between parties.
Also means the receiver doesn't get hit with fees to receive an international payment.
http://www.computerweekly.com/news/2240222351/Tesco-Bank-lau...
If it was a card details leak, I'd have expected cards to be cancelled, and not allowing them to continue to be used.
Unfortunately that's totally plausible, and infact, are the profitable customers for credit card companies. Why give a credit card to someone who can pay off their bills in full every month, when you can give someone more credit than they earn, let them spend it all, and then pay you monthly with interest?
As a point of reference, my Amex limit is 5x my monthly post-tax earnings. Back when I was only eligible for entry cards, at £250 limit increased to >£5k within a year.
Sounds like it's a breach from within (or at least not though compromised accounts), this would explain the lack of concern from Tesco about resting security (much to the chagrin of customers, i'm sure) and the huge numbers of affected accounts.
I personally doubt this will be revealed to be a software security issue.
The types of 2FA vary dramatically between banks. Some use an SMS OTP but as we know phone numbers aren't secure [0]. Most use a card reader but they often do this differently. Some use the 'identify' function to log on and the 'sign' function for payments (as designed) but others use the 'respond' function for everything. The danger in using 'respond' for payments is that the account and amount aren't entered into the card reader so you don't know what you are authorising.
<pure-speculation>
If Tesco have a flaw in how they are using 2FA, by only using 'respond', then local malware could intercept genuine payments, alter the account/amount details, and get the user to authorise this. Or Android malware could intercept SMS messages. N.B. This assumes the issue is in the faster payments system but it could be in the payment card system. It appears cash points still work but this is a separate system to debit card payments.
</pure-speculation>
From what I've read no one will lose money but having transactions frozen is still a big inconvenience. As mentioned elsewhere here, this is why it's a good idea to have many different bank accounts from various parent institutions (also important from a deposit guarantee position). Some banks share the same infrastructure and liability. Always have some cash available too, although that is getting harder to spend everywhere [1].
[0]: https://unop.uk/phone-numbers-for-examples-and-user-identifi...
Hell, I can't even get authenticated with my provider half the time because the simcard comes with it's ID/PIN/password that is printed on your contract. You need that to do any changes on your account.
I personally think cell phones can be made secure enough and are the most convenient. If somebody really wants to fuck with you, they will anyway, for most people there is not much point to it anyway
If tested systems that allow you to transfer money between accounts, if you can bypass the initial authentication you can transfer money without needing to use 2FA or generating a TUN code.
And these systems can be breached.
So they may still be vulnerable. If UK customers can find a low (or no) cost alternative place to put what remains of their money, I'd do that now. This might not be over.
They may not know how the attackers gained access or if they're still inside until incident responders have done a full workup on the network.
As with almost anything financial, the key to lower risk is not putting all the eggs in a single basket.
Agreed that this is sage advice for anyone who is able to financially have multiple accounts though.
Thing is, you don't even have to have a whole lot of money to set up multiple accounts. I started doing this when I was still a student, because I got freaked out by how easy it was to skim cards back in the dizzy. (Maybe it still is, but in the EU most cards seem to smart cards these days so you can't just do the swipe skim anymore – at least, I don't think so.)
I had four accounts:
- A: current account, where I would receive whatever little money I'd make on the side every once in a while, and benefits
- B: savings account, where I'd move most money I received in account A; this account had full freedom but pretty much no meaningful interest
- C: second savings account, where I'd actually put savings; some restrictions but better interest
I also had a mixed debit/credit card connected to A – it had terrible limits (something like £250) but it was enough to make purchases throughout the day. At the end of the day, I'd move funds from B to fill the credit back up, thereby never getting any penalties. It's important not to actually use this credit for more than whatever the allotted free time is. (I think I had 30 days free credit, but always paid it back immediately anyway.) A almost never had any money on it, and if I needed to make larger purchases than the credit allowed I'd just transfer it when I needed it. This setup worked well, and I had a couple of scares where my card had to be blocked, but I never lost money. My savings were abysmal (living hand to mouth) and it was the same funds moving around all the time – I just made sure that my exposure on the card was almost always the bank's money. They're pretty quick in settling things when shit hits the fan then.
This setup breaks down if someone manages to hack the bank or you though, since it's all in the same bank. This is why I use multiple banks today.
Obviously mileage varies by country, but my experience with banks in the EU is that once you've got an account, they're more than happy to set up more stuff for you. (Ye olde Wells Fargo trap, I s'pose.)
Most banks like to insist that you use them exclusively, but I've never heeded that advice and so far I've never had a problem with it. If anything, they seem to work (ever so slightly) harder to get all of your business.
If you are in the position (like most) where all your account contents are guaranteed and the only thing you are hedging on is convenience vs risk of cashflow problems.
Is it generally easy to open accounts in countries you are not resident in?
If you are an American, be aware that merely having a bank account in a foreign country will make your life a lot more complicated at tax time. It's probably not worth the pain, unless you have a specific need.
https://1office.co/estonia/blog/opening-estonian-bank-accoun...
For example, I considered opening this Tesco account, since I need to keep about £1500 in my British account for student loan payments. Tesco offer 3% interest on the balance, but I should have opened the account before I emigrated.
Both the NL (even when has temp residency / work visa) and the US account were a major PITA to create.
I've even had to convince banks that they're allowed to open an account for me in the first place...
Credit cards are great for some but inappropriate for others who lack discipline or funds. Keep in mind you spend more when using plastic over cash as well. [1]
No advice is one sized fits all.
[1] https://www.nerdwallet.com/blog/credit-cards/credit-cards-ma...
If they don't, then within the Eurozone they still don't necessarily need two accounts. It might be convenient, if it enables using local systems to pay utility bills on two properties, for example.
If currencies are being changed, SEPA doesn't help.
I have a family member who gets their pension in Canadian dollars but lives in the US. Since he lives in the US he has no need for Canadian dollars. He says that his money loses a quarter of its value converting from Canadian dollars to US dollars. I don't know if that's true, its what he told me.
Further it's relatively easy to keep USD in a Canadian bank account if you want to.
That is, the addresses can be published by whatever entity with a threat to taint addresses they send value too unless the target addresses turn the value over to the government entity.
They can freeze your bank accounts too.
Also, hard to taint coins you don't realize exist. Not that I have any of those, mine are all from exchanges, but miners could easily have backup coins, as could OTC traders
This will massively affect their provider fiserv, their internal team will almost certainly have to be replaced and I would be surprised if they don't throw their hands up and go back to being grocers. Retail banking is wafer thin margins.
Edit: I cannot think of / find a similar case - this is amoungst the first if not the first mass account attack I know of.
To do this there is a trace. Potentially an insider at Tesco to turn off the 2FA etc, or possibly they have penetrated the systems totally. Not sure which is worse.
Also there must be some mule accounts - right now all the "Big Four" are scouring their customers accounts for unusual deposits. We will hopefully see where it went soon - presumably to several people who believed a Nigerian Prince was sending them cash, and then sent it into a wash of Russian accounts.
But I would be amazed if it all gets out the country. It would trip so many alarms. Of course if it did not trip alarms
Some predictions - Gov will enforce GPG level encryption for every bank interaction - 2FA with Time based OTP for example. This will force a huge upgrade in retail banking - and will be good for the economy.
And Apple IPhone is the perfect host for making time based two factor auth that smooth. Good for apple. Android might just see the whole UK market as large enough to get its act together.
I don't think encryption levels are anything to do with the fraud problems (at the customer facing end, at least, which I guess you are referring to because of the talk of OTP)
I wonder how many mule accounts they had set up? Surely having lots of small transactions into a single account followed very quickly by a large one offshore is going to trigger fraud alerts in any modern clearing bank?
I don't think that's going to happen just yet. UK bank regulation is famously light touch and the government is extremely preoccupied at the moment.
(The loss applies to the bank, not the customers, so they've got plenty of incentive to fix this. And it's quite possible it's a backend hack from the sound of some of the other comments on this thread, for which 2FA is no use)
In the US I still get charged for withdrawing from my Wells account at a Chase ATM.
The only time it works without regulation is when banks' interest align with customers, e.g. contactless payment. For the bank, less PIN exposure so less chance of compromise and liability. For customers, quick tap-to-pay. Win-win for once.
Tesco's strategic response will be more about reputation, branding and customer relationships than about the direct profits they earn from their financial services.
I would be surprised if Her Majesty's Government started micromanaging security (unless there was political pressure to do so). That's not their style. Much better to require that banks, and their customers, are adequately insured against this kind of fraud, and then let the invisible hand decide the optimum level of security.
How would one launder so much stolen bank account credit so quickly? It depends on whether you need to remain anonymous or not. If, say, you're an established Russian gangster with an established network of ATM withdrawal agents, it's relatively straightforward. Sure, some of the agents will get caught, but that's their problem, not yours.
On the other hand, if you're within reach of British justice, I guess we're talking about Bitcoins. Can the scammers move their stolen cash to a Bitcoin market that's large enough and liquid enough to swallow that much transaction volume before the cash is frozen? I've no idea.
If I was a legislator, I would look for ways to attack bitcoin laundering / tumbling. Bitcoin transactions are anonymous, but they are also public. It's always possible to look at the Bitcoins in your wallet and see if they are in any way tainted by association with known dirty money.
It seems there are three main ways to monetise credit card / account data:
1. aggregate into a mule account
2. aggregate into an international account
3. extract cash via ATMs / payments
All three suffer from a high propensity to trigger alerts, and so rely on a fairly sophisticated understanding of each banks trigger rates.
So back in 2010 some banks could be hit with a flash attack (4) where hundreds of debit transactions for similar amounts at same time would not trigger stops (one assumes the debit approval infrastructure was fast and in memory and only went back to the ledger every five mins)
So as attackers find new vulnerabilities banks apply new systems.
(1) MIcrosoft report on this can't find right now
(2) https://en.m.wikipedia.org/wiki/2016_Bangladesh_Bank_heist
(3) http://mobile.nytimes.com/2013/05/10/nyregion/eight-charged-...
(4) http://www.atmmarketplace.com/blogs/quotflash-attacksquot-ma...
My guess someone (either insider or via technical means) has got a list of all the debit card numbers, ccv and account details - maybe even 3DSecure/VfV details?
People are then doing loads of payments via online cardholder not present.
Going to be a pain to figure what is what on this.
"Ref: Customers will still be able to use their cards for cash withdrawals, chip and pin payments, and bill payments. The bank is blocking customers from making online payments using their debit card, although transfers between accounts and to other people are still allowed, a spokesperson said."
I would consider taking the £50, but I would make damn sure not to put ALL my funds in there.
It must be far cheaper for the banks to reimburse customers rather than to patch all the security weaknesses of their financial systems. This strongly suggests that the reputational cost of hacking and fraud just isn't that big.
I am curious how you come to this conclusion, given that banks are extremely reticent to discuss what security measure they take and to avoid any publicity about security breaches (even publicity about how they caught someone brings the problem back to the public's mind). So if they WERE being effective in tracking down the criminals, how would you know?
I'm not saying the banks care nothing for security, and I am sure that they don't want to lose money if they had a choice, but their actions often give an outward impression of not being too bothered about individual losses.
I'm certainly not going to be doing anything with the accounts until Tesco give some more clarification on what actually happened (although the way these things work, I doubt there will ever be a full technical response.)
Also if it is some sort of internal breach, would any other data have been taken?
Back in 2012, Tesco were storing passwords in plain text.
They'd do a hash of each character of the password (in Lloyds' case, your "memorable word" combo), to compare your entries to.
Password: money
Secret word: ABCD
If they're going to ask for two characters from the secret word, they could then hash
saltmoneyAB
saltmoneyAC
saltmoneyAD
saltmoneyBC
saltmoneyBD
saltmoneyCD
and check against the relevant one.It's a bit like having a number of related passwords, which the bank can ask you for any of them, and then verify is correct.
After entering the two digits of the 'Security Number' you then receive a 'One Time Access Code' through a text or phone call, although I have never logged in to my account before, and seem to be unable to get past this step now.
I think you then enter your proper password in, which I would hope is not stored in plain text, although the article I linked seemed to imply this was the case back in 2012.
At the same time, they advise you to never give your password away, and that they will never ask you for your (full) password.
Talk about a mixed message...
https://www.troyhunt.com/the-tesco-hack-heres-how-it-probabl...
I had a smug thank you response.