Consumer Advocate: Simple Phone Hack Exposes Credit Card History

Using relatively simple techniques, hackers can tap into some banksโ€™ automated telephone customer service lines and determine balances and account histories, according to an investigation by a prominent consumer advocate.

โ€œThe trouble with this system is that hackers, crooks, suspicious spouses, or nosy neighbors can access your credit card information using the same method the reporters from the British tabloid used to break into subjectsโ€™ voicemail accounts,โ€ Edgar Dworsky, founder of ConsumerWorld.org, says in a press release. โ€œThis is far more serious, however, since consumersโ€™ financial information and privacy are at risk.โ€

The investigation determined that two banks, Chase and Bank of America, have security vulnerabilities. Bank representatives disagree with Dworskyโ€™s assessment, saying that even if hackers do compromise their systems, the thieves wonโ€™t get very far.

[Related article: On Cell Phone Hacking and Privacy: A Modest Proposal for Mr. Murdoch]

โ€œIn addition to at least two levels of authentication required to access what is very limited information over the automated voice system, we have additional security controls in place to detect potential abuse of the automated system,โ€ says Betty Riess, a BofA spokeswoman.

Likewise, Chase says the risk of such an attack is โ€œminimal,โ€ according to a prepared statement by Chase spokeswoman Christine Holevas.

Dworsky teamed up with New York Times reporter Ron Lieber to test the security of the banksโ€™ automated systems. Using just Lieberโ€™s zip code and the last four digits of his credit card account numbers, Dworsky managed to enter the phone systems of both Chase and Bank of America. Chase granted Dworsky access every time he tried, whereas BofA occasionally denied him. See the Times story here.

At both banks, Dworsky was able to find the cardholderโ€™s credit limit, account balance, recent payment history. Bank of America sometimes revealed specific merchantsโ€™ names where purchases were made.

[Featured Tool: Get your free Credit Report Card from Credit.com]

In both cases, the flaw is that the phone systems grant access with just the customersโ€™ zip code and the last four digits of their account, both of which are easily obtained by thieves, either by rummaging through wastebaskets in retail stores or trash cans behind victimsโ€™ houses.

โ€œIt would be so simple for Chase and Bank of America to immediately require full account numbers when Visa and Mastercard cardholders access their system, and that would help thwart all but the most conniving of hackers,โ€ Dworsky says. โ€œRequiring a password would further enhance security too.โ€

But officials at Bank of America worry that adding too many hoops for customer authentication could provoke customer backlash.

โ€œOne of the top reasons customers use the automated system is because they want to quickly check account status and transaction information,โ€ Riess said in a statement emailed to Credit.com. โ€œOur objective is to balance customersโ€™ need for convenience and quick access to general information with industry best protection of their accounts.โ€

[Featured Product: Looking for credit cards for good credit]

Image: Trace Meek, via Flickr.com

You Might Also Like

A woman looks at her laptop computer with a thoughtful look on her face.
Wondering if it's time to add another credit card to your wallet?... Read More

April 9, 2024

Credit Cards

A woman sitting on a couch
Thereโ€™s nothing fun about declaring bankruptcy, but those w... Read More

October 21, 2020

Credit Cards

[UPDATE: Some offers mentioned below have expired and/or are... Read More

August 3, 2020

Credit Cards