Using relatively simple techniques, hackers can tap into some banksโ automated telephone customer service lines and determine balances and account histories, according to an investigation by a prominent consumer advocate.
โThe trouble with this system is that hackers, crooks, suspicious spouses, or nosy neighbors can access your credit card information using the same method the reporters from the British tabloid used to break into subjectsโ voicemail accounts,โ Edgar Dworsky, founder of ConsumerWorld.org, says in a press release. โThis is far more serious, however, since consumersโ financial information and privacy are at risk.โ
The investigation determined that two banks, Chase and Bank of America, have security vulnerabilities. Bank representatives disagree with Dworskyโs assessment, saying that even if hackers do compromise their systems, the thieves wonโt get very far.
[Related article: On Cell Phone Hacking and Privacy: A Modest Proposal for Mr. Murdoch]
โIn addition to at least two levels of authentication required to access what is very limited information over the automated voice system, we have additional security controls in place to detect potential abuse of the automated system,โ says Betty Riess, a BofA spokeswoman.
Likewise, Chase says the risk of such an attack is โminimal,โ according to a prepared statement by Chase spokeswoman Christine Holevas.
Dworsky teamed up with New York Times reporter Ron Lieber to test the security of the banksโ automated systems. Using just Lieberโs zip code and the last four digits of his credit card account numbers, Dworsky managed to enter the phone systems of both Chase and Bank of America. Chase granted Dworsky access every time he tried, whereas BofA occasionally denied him. See the Times story here.
At both banks, Dworsky was able to find the cardholderโs credit limit, account balance, recent payment history. Bank of America sometimes revealed specific merchantsโ names where purchases were made.
[Featured Tool: Get your free Credit Report Card from Credit.com]
In both cases, the flaw is that the phone systems grant access with just the customersโ zip code and the last four digits of their account, both of which are easily obtained by thieves, either by rummaging through wastebaskets in retail stores or trash cans behind victimsโ houses.
โIt would be so simple for Chase and Bank of America to immediately require full account numbers when Visa and Mastercard cardholders access their system, and that would help thwart all but the most conniving of hackers,โ Dworsky says. โRequiring a password would further enhance security too.โ
But officials at Bank of America worry that adding too many hoops for customer authentication could provoke customer backlash.
โOne of the top reasons customers use the automated system is because they want to quickly check account status and transaction information,โ Riess said in a statement emailed to Credit.com. โOur objective is to balance customersโ need for convenience and quick access to general information with industry best protection of their accounts.โ
[Featured Product: Looking for credit cards for good credit]
Image: Trace Meek, via Flickr.com
You Might Also Like
April 9, 2024
Credit Cards
October 21, 2020
Credit Cards
August 3, 2020
Credit Cards