Webtrends Tracking Code
 
UK Home >  OUT-LAW News >  News Archive >  2006 >  January 2006 >  Poor call-centre security exposes bank accounts to fraud

Poor call-centre security exposes bank accounts to fraud

OUT-LAW News, 27/01/2006

Sloppy security practices at call centres operated by 20 of the UK’s top financial institutions are leaving consumers at risk, according to an investigation commissioned by voice and data solutions provider Intervoice.

The study assessed the ability of researchers to access financial services through the bank-run call centres if they were unable to provide a password – the most commonly used call centre security tool.

The study found that call centre agents at nearly half (9 out of 20) of the financial institutions investigated – which in total offer services to more than 20 million people in the UK – could be simply coaxed into accepting less stringent identity checks from callers claiming to have forgotten their personal passwords.

These included requests for alternative data such as a landline phone number for the account holder, mother’s maiden name or recent direct debit details.

In the case of three financial institutions that provide personal credit cards, no security password was required at all to conduct a balance transfer of £500.

Intervoice Director David Noone described the findings as shocking.

“The problem is that call centre staff are trained to be helpful and in their efforts to avoid customer frustrations will readily offer up alternative security checks,” he said. “This is often with questions relating to personal data on the account holder that could be second sourced in the most extreme cases through stolen bags or in the simplest form through internet research.”

He warned that in their rush to prevent fraudsters gaining access to accounts over the internet or through computer viruses, financial institutions had turned their back on telephone fraud.

“This has become one of the easiest back doors for criminals to conduct fraud. The Intervoice study shows that passwords may have had their day in call centres,” added Noone.

 

OUT-LAW Recommends

Data Protection training
We offer training courses on Data Protection and Freedom of Information laws

Winner at 2008 Webby Awards

OUT-LAW star: link to the home page
Disclaimer: This was printed from OUT-LAW.COM, a service of international law firm Pinsent Masons. We hope you find this content useful. However, please note that nothing in this document constitutes specific legal advice. You should consult a suitably qualified lawyer on any specific legal problem or matter. Any questions, please email info@out-law.com.