My 82 year old mother found out that fraudsters had emptied her HSBC_UK account
twitter.com
twitter.com
I love the British comedian David Mitchell's long time campaign against this kind of bank behavior:
https://www.theguardian.com/commentisfree/2018/nov/25/identi... ('’Identity theft’? It’s daylight robbery by the banks' - 2018)
https://www.youtube.com/watch?v=CS9ptA3Ya9E (Mitchell & Webb - Identity Theft, 2007)
It reminds me of when I was a kid, my sister and I got two identical fish and couldn't disambiguate which was mine and which was hers. But when one of them died, she made sure to let me know that was my fish.
There are some asterisks to this statement due to the large amount of regulation around bank accounts.
Not knowing it's me just means they have to find a way to guarantee that knowledge. Because the failure to properly identify a client is the bank's not the client's.
Yes, in the same way that companies will often try to avoid honoring their warranties. That it's in their financial interest to do so doesn't mean they can just ignore their contract with you.
Banks of course will do everything in their power to shirk their responsibilities. But reading the legislation, and writing a well worded letter, plus a follow up with the Financial Ombudsman (FOS) is pretty much sure fire way to get your money back.
The FCA set clear rules around how banks must deal with complaints, and the FOS makes it easy to escalate complaints when banks refuse to acknowledge they’re responsibilities, and are extremely consumer friendly (I say this as someone who’s dealt with the FOS from the banks perspective)
But broadly the bank is completely responsible for any transaction the account owner claims is “unauthorised” unless the bank can demonstrate the account owner was “grossly negligent” with their payment credentials, or can demonstrate the account owner is making a fraudulent claim. The standard of “grossly negligent” is something you need to look to case law to understand, but it’s generally very hard to prove gross negligence, and the account owners personal situation must be considered.
A relevant example of non-gross negligence, was an older individual who entrusted their debit card and PIN number to their carer so they could buy them groceries. The carer used the card and PIN to steal money from the account holder, and bank claimed that sharing their PIN with a carer was gross negligence, but the FOS and courts disagreed on the grounds the individual needed to provide their card and PIN because their personal situation made buying groceries themselves effectively impossible.
But the TL;DR is that law places the burden on banks to prove that any transaction a customer claims is “unauthorised” was actually “authorised” by the customer, that the customer isn’t acting fraudulently, and wasn’t grossly negligent. There is no assumption of fault on the customer part.
[0] https://www.legislation.gov.uk/uksi/2017/752/part/7/crosshea...
In the Swedish supreme court case I quoted above:
Background information:
- Sweden has a public personal identification number for every citizen (except for like 10k people with protected identities)
- The four main banks in Sweden have collaborated to create something called "Bank Id". It's often used as a secure authentication tool combined with the personal identification number (something you have - the cert in the mobile app, something you know - PIN or face id).
Someone convinced an elderly person over the phone to authorize the creation of a new Bank Id on the attacker's phone. This was fairly complicated and required the old person to use their physical RSA SecurID token. The court found that the elderly person had behaved reasonably well and that the attacker was very competent.
Still, the supreme court felt that the bank should have been more careful about letting strangers steal their money.
As this case shows, this isn't always true.
If you’re house bound, entirely dependent on a trusted third party help for your day-to-day living, and your bank only provides a debit card and PIN facility to authorise your transactions, then what choice do you have but to share those credentials with a trusted third party so they can buy food for you?
The bank chooses the authentication mechanism, their customers don’t get a choice. If that mechanism doesn’t work as intended when faced with common and entirely reasonable living situations, that’s the banks failure, not the customers failure.
So yes, because we afford massive protections and rights to banks in exchange for the necessary but largely low-risk activity (holding cash then returning it in exchange for a fee) - laws holding them responsible for failing to prevent theft do exist.
Such a weird place to look for care and comfort.
Let's grant that an elderly person needs assistance and compassion in this time, and as a community we should provide it. Would we want the bank to provide it? Hell no! There's an enormous conflict of interest there. In this situation I wouldn't want somebody from the bank cozying up to my mom and earning her trust. In fact, I'd go ballistic if they tried. Their financial incentives are to use that trust to persuade her not to exercise her full rights, to avoid her becoming aware of all the avenues of recourse available to her, to make her feel that everything will be okay if she lets the matter drop.
What we really want for someone in her situation, besides emotional support, is a savvy legal advocate who will let the bank know that she is aware of her rights and the bank's obligations, and that she has legal resources at her disposal.
The very concept of a business exists at the whims of society. We can make them do better if we want.
I really don’t understand all these “business will become too onerous and they’ll lose money” argument. Society does not owe them success. If a business plan does not work, then let the company die. (It won’t be the case here, British retail customers are a blip on HSBC’s balance sheets).
That's the part that could be fixed. If we manage to provide legal assistance to every criminal defendant who can't afford it, we could provide a consumer advocate for people in her situation, backed up with a lawyer when necessary. They wouldn't have to do much; their attention and their ability to bring legal resources to bear would motivate the bank to do what they are obligated to do.
you are, on the one hand, calling for "community" to provide for assistance and compassion and to respect basic human dignity. then, on the other, you accept and normalize this notion that all human interaction is explicitly transactional, and even adversarial. these are orthogonal goals.
The hardness of the problem is borne of powerful actors making it such: there is nothing inherently difficult about it.
If it turns out that there was no fraud, they could look at clawing them back.
That is getting less and less common these days. Take companies like Google and Meta who pride themselves on not having a single human support person.
I even paid for Google support to try and get back into my Google account lol. Here's their reply:
"My name is Christopher, and I’ll be taking up your case here today. I understand you are trying to get back into a different Google account but are not able to. I understand how important this is to you to get back into your account. We'll work together to see if we can get you back into the account.
You've said you have access to your email address, password and recovery email but you lost your phone number in a fire.
Based on that, we currently don't have any other account recovery suggestions for you."There are services that I still have difficulty giving up, which are provided by companies I don't trust to not lock me out forever or to provide customer service. I feel stupid as I type this - are other people in a similar situation? Is the only option to vote with our wallets and choose better/paid providers?
I like to think that there's a solution out there which returns us to a time when it didn't feel like account access involved the sword of Damocles:
- coming up with the perfect combination of 2FA/Advanced Protection/removing mobile phone number which prevents these arbitrary lockouts,
- a popular name and shame website collating these ridiculous examples
I read somewhere in a HN comment that someone was able to restore access to a Google account which they were locked out of because they already had all email forwarding from the locked account to another account. One of the options Google offered for unlocking access to an account was having access to email from that same account, which seems ludicrous to me, but in this case worked for that person.
As well as setting recovery email addresses, it might be worth turning on forwarding to that recovery email, and a rule in the recovery account to automatically send those emails to trash.
I had exactly the same though -- if they could just send me a link or something to verify!
-some algorithm
I got banned from Twitter ages ago and never bothered to create another account. I used to not have trouble reading threads like this but among other things with "X" the UI has become absolutely impossible to use lately. I'm not even sure if I'm allowed to read the rest of this thread on Twitter itself but, if I am, how to do it is not at all obvious.
javascript: (location.hostname="nitter.net")https://addons.mozilla.org/en-US/firefox/addon/nitter-redire...
I'm exceedingly glad to have switched to a local credit union.
Someone bought a new house to retire with their life savings. Everything was arranged properly, and she transferred the money to the bank account the estate agents told them.
But they never received the money.
What had happened was that someone had hacked in to the real estate agent email and had sent a fraudulent email, so she transferred the tens of thousands of pounds to the wrong account. This was discovered a few days later.
Bank said there's nothing they can do; "your life is destroyed but not our problem kthxfucketybye". Of course the real estate agents took no responsibility either (after all, we all know that the primary function of most people involved in the housing industry is to make everyone as miserable as possible).
(I don't recall if things did end up being resolved after a few years; I'd appreciate it if someone remembers the article; IIRC it was in The Guardian).
That's why I always "warm" bank accounts. I first do a little transfer, then confirm with the person, on the phone, that the money was received. If that's not possible (for example for fully automated system which expect the exact amount), I make 100% sure the account is correct.
Invoice from my car dealership asking me to wire 3 K EUR? I call them and ask the secretary to read me loud the bank account number.
Note that what you mention is a famous scam in the cryptocurrencies world: replacing Bitcoin deposit addresses (say a Bitcoin deposit address belonging to an exchange like Kraken or Coinbase) with the attacker's address. There are even malware who modify the clipboard when they detect that a Bitcoin address is in the clipboard. Even "better": there are malware that do this while making sure the last four digits are the same as those on the legit address (so people only checking the last four digits and thinking they're good are owned).
It's very hard to not get scammed in this mediocre world full of shitty insecure, constantly owned, OSes, phones, websites, etc.: nothing that appears on these shitty devices can be trusted.
The problem is so bad people are using 2FA devices and are still getting scammed.
But if an email looks official and came from an official address, I can't imagine the settlement agent wouldn't be liable for the loss. (And often they now have cyber insurance to cover such losses.)
I know some title companies are moving away from wiring funds out and only issuing checks to prevent having this problem themselves.
But once this has been satisfactorily verified what the person does with their money is none of the bank's concern.
Yup, that's the UK. Nothing in this country works anymore. People think it does until they have a problem and then they find everything is just a facade.
Need to call an ambulance? Emergency service will tell you to take an uber. Been victim of a crime? Police will do their best to make you go away. Victim of a fraud? It was your fault go away. and so on.
and you pay for all of it highest taxes in living memory.
Sorry for the rant. Elections can't come soon enough.
And then from what I've heard the NHS is the best run health care system in the world[1].
1. Best run according to this documentary https://www.youtube.com/watch?v=x-5zEb1oS9A
I am sorry but British history says that regardless of how Labour polls today, on election day you’ll still end up with Tories. Or, alternatively, new new Labour for a couple of years and then Tories. That’s pretty much British politics for as long as there has been a UK.
This will persist until we change the laws to make misbehavior more expensive than proper behavior.
[1] https://www.ons.gov.uk/peoplepopulationandcommunity/crimeand...
In less than 5 years, all of this will be replaced by LLMs, and we will have the luxury of talking to a warm but completely fake human who will provide us even less help than before.
The main question is - did the bank fuck up and if so, will they fix their fuckup. The TLDR of this thread seems to be that (1) yes the fucked up and admitted it and (2) the author seems to believe it will be resolved. So that sounds fine. The expectation that the bank will toss mom a few quid outside of their remediation process seems preposterous.
I tested them on this before I switched, multiple times. Most of the time, it was one ring. It was never more than two.
I wish I could tell you all to switch to my bank, but it's a local one, and I'd rather keep that information under wraps.
This doesn't sound right, and the Twitter thread is devoid of much detail as to the root cause here. Last I checked, HSBC had a physical code generator that had to be involved in approving transfers, so how were these transfers (150 of them!) actually made?
So, was this actually APP fraud? (in which case - let's not beat around the bush here - it's almost certainly the account holder's fault, but obviously things are less black and white when the account holder is vulnerable). Or was there actually a flaw in HSBC's account security which allowed criminals to gain access to the account?
None of these facts excuse the poor customer service, but there's generally good reasoning that these cases are dealt with by a dedicated fraud team and not by random staff in branches. There needs to be more regulation to ensure that they're staffed appropriately and victims aren't left in the lurch, though.
It doesn't add up with my experience of how banks (incl. HSBC) deal with transfers.
> Victim blame much?
If we can't have a rational conversation about the actual factors leading to these sorts of events (i.e. exactly how the transfers were authorised, where the weakest link in the security chain was), how are we supposed to prevent future occurrences?
We can have all of the technical measures in the world in place, but if a customer explicitly consents to someone else logging in, or making these transfers - we should be discussing non-technical solutions instead.
Equally, if it turns out that the UI design of the existing security measures was poor and that lead to this case, then that's something that industry can and should improve upon (or be forced to, via regulation).
Their fraud department calls me several times a year to enquire about any transactions out of the ordinary to the point I am very careful when I travel abroad because I know they are bound to flag the activity.
Still not 100% sure it was the bank, so I asked for a reference number (which they couldn't provide) and said I would call back the number on my card instead.
Recently they also have started sending texts instead. They text that "you card ending with xxxx has been used for a transaction of x money at y company, did you make this transaction?" and you just reply Y/N. If you don't reply they start calling.
The problem is their profiling is out of whack. They should not treat foreign transactions from a frequent traveler with the same urgency (or more) as a vulnerable elderly emptying their bank account over the course of weeks. They have all the data they need to do their job properly and then some. They are not afraid to use this data when it’s to sell you plans and mortgages.
And to play devil's advocate - from their perspective, _this_ claim could very well be fraudulent. Not accusing anybody of anything, but in theory it's not a bad scam - get your son to drain your bank account, move the money where it can't be found, claim you were hacked, get all your money back. I doubt that's what happened here, but the bank has to consider it.