Banks should up their game by improving online security features, says Which?

The consumer group said banks ‘should not be leaving these open doors for scammers to exploit’.

Vicky Shaw
Monday 06 February 2023 19:01 EST
Account providers were scored by looking at their processes for login, navigation and logout, account management and encryption (Yui Mok/PA)
Account providers were scored by looking at their processes for login, navigation and logout, account management and encryption (Yui Mok/PA) (PA Archive)

Your support helps us to tell the story

From reproductive rights to climate change to Big Tech, The Independent is on the ground when the story is developing. Whether it's investigating the financials of Elon Musk's pro-Trump PAC or producing our latest documentary, 'The A Word', which shines a light on the American women fighting for reproductive rights, we know how important it is to parse out the facts from the messaging.

At such a critical moment in US history, we need reporters on the ground. Your donation allows us to keep sending journalists to speak to both sides of the story.

The Independent is trusted by Americans across the entire political spectrum. And unlike many other quality news outlets, we choose not to lock Americans out of our reporting and analysis with paywalls. We believe quality journalism should be available to everyone, paid for by those who can afford it.

Your support makes all the difference.

Some banks’ websites and apps are missing security protections, potentially leaving “open doors” for scammers, Which? claims.

The consumer group tested customer-facing security systems of 13 current account providers from September to November 2022, with help from security experts at Red Maple Technologies.

Account providers were scored by looking at their processes for login, navigation and logout, account management and encryption – for both their online banking security and app security.

Virgin Money was scored the lowest overall for online and app banking in the research.

We are continually monitoring, assessing and improving our security controls

Virgin Money spokesperson

A spokesperson for Virgin Money said: “The safety and security of our banking services is our top priority, and we are continually monitoring, assessing and improving our security controls.

“A number of the points raised in this research relate to decisions we’ve taken to enhance the digital user experience while ensuring our robust, multi-layered controls remain in place to protect customers’ accounts.”

Which? said it also had some concerns over TSB, which received the second lowest score for its app in the study.

A spokesperson for TSB said: “We continue to invest in our online and mobile services – and work with globally leading tech firms to deliver both security and accessibility to our customers. TSB also tracks well across the industry on fraud prevention and we are the only bank that protects its customers with a guarantee to return their money should they ever fall victim to fraud.”

Nationwide Building Society was given the second lowest score for online banking security.

A spokesperson for Nationwide said: “Nationwide takes the security of its members and their money very seriously.

We will take the points raised by Which? on board as we continue to evolve our digital services

Nationwide Building Society spokesperson

“We are never complacent and conduct regular testing of our systems to ensure that we maintain an appropriate level of protection, whilst ensuring a positive user experience.

“We will take the points raised by Which? on board as we continue to evolve our digital services.”

Meanwhile, Which? said Starling Bank was placed top for online banking security.

Its top scorer for online banking security last year, HSBC UK, also performed well this year. HSBC followed closely behind Starling for online banking, while its app had the highest score.

Which? said the banks included in the research also have behind-the-scenes systems that the consumer group and Red Maple Technologies were not able to test.

In general, the consumer champion said it wants improvements that would see weak passwords blocked and it also believes that sensitive data should not be sent via text messages as these can be intercepted.

If the worst happens and people do fall victim to remote banking fraud, in many cases they will be entitled to a refund from their bank.

By making improvements, such as blocking weak passwords, banks can take an important step in preventing unscrupulous fraudsters from attempting to steal money and personal data from consumers

Sam Richardson, Which? Money

Sam Richardson, Which? Money deputy editor, said: “Banks should not be leaving these open doors for scammers to exploit and must up their game to protect their customers properly.

“By making improvements, such as blocking weak passwords, banks can take an important step in preventing unscrupulous fraudsters from attempting to steal money and personal data from consumers.”

A UK Finance spokesperson said: “The banking and finance industry is committed to stopping fraud from happening in the first place, investing billions in advanced technology to protect customers.

“Our figures have shown that the number of recorded cases of unauthorised fraud has fallen year on year, with the first half of 2022 showing a fall of 7% to just under 1.4 million, and banks stopping £583.9 million of unauthorised fraudulent transactions.

“The industry continues to work closely with the Government and law enforcement to target the criminal gangs responsible and continue its efforts to prevent fraud to customers.”

Here are five tips from Which? for safe banking online:

1. If you receive unexpected emails, texts, WhatsApp or any other type of messages, do not click on the hyperlinks they contain.

Criminals posing as your bank might try to steal sensitive data or trick you into sending money, going as far as creating fake websites to impersonate banks and other firms.

Do not download attachments or call phone numbers either. If you need to get in touch with your bank, call it on a trusted number, such as the one on your debit card.

2. Use up-to-date security software. This means downloading antivirus software on your computer, phone and any other devices you have.

It is also important to download and install the latest updates for the device itself. Updates contain security patches for new vulnerabilities, so do not use an out-of-date device.

3. Protect your mobile phone. Go into the settings to ensure your phone auto-locks after a short period of inactivity.

While you are in there, disable lock screen notifications, to prevent criminals seeing incoming texts, which could include bank codes for accessing your account.

You can also add a Pin to your Sim card, to prevent it being accessed.

4. Check privacy settings on social media. Remove any personal information such as your email, date of birth and phone number – all of which can be used by criminals to steal your identity or impersonate your bank.

Only accept friend requests from people you know.

5. Replace default passwords on your home router. This will prevent others from accessing it. Also, avoid banking on unsecured wireless networks or public computers.

If you do use a public computer, never leave it unattended and always log out when you have finished.

Thank you for registering

Please refresh the page or navigate to another page on the site to be automatically logged inPlease refresh your browser to be logged in