New fraud checks could catch out online shoppers - Which? News (2024)

Online shoppers will face new anti-fraud checks as retailers and banks finally adopt rules known as strong customer authentication (SCA). Yet improved security could come at a cost for customers who don't use mobile phones or have patchy reception.

SCA checks have been in place for online banking since 14 March 2020, but businesses only began rolling out SCA for online card payments in June 2021, ahead of the regulator's deadline of 14 March 2022.

Which? first warned in June 2019 that one in five of our members could struggle to make online payments because they don't own a mobile phone (4%) or have poor mobile phone signal at home (13%).

This has proved to be true of the general public too - when we surveyed 4,438 current account customers in October 2021, 17% of those who make online card payments told us they've had issues passing new security checks.

Many said it was because they have a poor mobile signal (6%) or didn't have their card reader to hand (6%). They also struggled because they ran out of time to make the payment (4%), had to call their bank to complete the online payment (4%), or don't own a mobile phone at all (2%).

This newsletter delivers free money-related content, along with other information about Which? Group products and services. Unsubscribe whenever you want. Your data will be processed in accordance with our Privacy policy

What is strong customer authentication?

The new rules require banks to identify you using at least two of three independent factors:

  • something only you know (a Pin or password);
  • something only you possess (a registered mobile device or card reader);
  • and something only you are (a digital fingerprint or voice pattern).

If this isn't possible, payments will be declined, although low-value payments (under £25) don't always require SCA.

How will your bank make security checks?

Which? asked banks what options are available to customers looking to pass security for online card payments.

Most banks rely on mobile phones for security - for example, by sending one-time passcodes via SMS or asking you to authorise payments via your banking app.

SMSEmailAppCard readerLandlineCall bank
AIB UKYNYNYN
Bank of Ireland UKNNYYNN
BarclaysYNYYNN
ChaseNNYNNN
Danske BankYNY [a]NYN
HSBC (and First Direct)YNYYNN
Lloyds Banking GroupYNYN [b]YN

Notes: [a] Via the Danske ID Security app (not the mobile bank app). [b] Via token-based authenticator from the first half of 2022. [c] Can call the bank sometimes but only with additional security. [d] Emailed passcodes only available if there's no mobile number on record. [e] Must call bank to switch to email, can only hold one passcode option at a time. [f] Can call bank in exceptional circ*mstances.

The problem with mobile solutions

The Financial Conduct Authority has told firms to also develop SCA solutions that don't rely on mobile phones. But as our table above shows, only a handful of banks let you receive passcodes via landline instead of SMS or banking app.

Challengers Chase and Monzo only let you authorise payments via their apps. Danske Bank orginally told Which? it only offers SMS or app authentication but later confirmed that non-mobile users can ask for a one-time passcode to be sent via landline.

Other banks only offer the bare minimum, for example, Metro Bank told us customers without mobiles can call its contact centre 'sometimes' to authorise payments.

Triodos said customers who can't authenticate in the mobile app can log in to Internet Banking instead (and use their physical Digipass to authorise the payment).

UK Finance told Which?: 'Each firm has been developing their own ways to approve transactions and, as with any change coming in, the more people get used to using SCA the more familiar they will become with it.'

'We understand that for some customers the application of SCA may present challenges and would encourage customers to speak to their bank or payment provider if they have any concerns about the way in which they will need to authenticate payments.'

Around 300 people have taken complaints about SCA to the Financial Ombudsman Service, including Santander customer Steve, 64, from Surrey, who asked it to intervene in August 2019, when Santander told him he would need to use a local branch or telephone banking to pass online security as he doesn't use a mobile phone.

Santander has since told us it can send one-time passcodes via email to customers who don't use mobile phones or live in areas with poor mobile network signal.

Steve thinks there's an easier solution: 'The solution of emailing OTPs is acceptable to me but those without a mobile phone or adequate reception have a diminished service compared with those who do. Wouldn't it be simpler for everyone if Santander just sent OTPs to landlines as well as mobiles thereby ensuring equal treatment?'

  • Find out more: online and mobile banking security rated

An opportunity for scammers?

Although it's designed to prevent card fraud, scammers will see SCA as a fresh opportunity so it's important that banks protect cardholders against any emerging threats.

We could see a spike in fake texts, calls and emails claiming to be from 'your bank' using the new security checks as the hook. A few SCA-related phishing emails did the rounds back in 2019.

With so many banks relying on SMS, we're also concerned about the increased threat of Sim-swap fraud - where criminals trick your mobile network provider into transferring your phone number to a Sim card that they control. This means they can intercept messages from your bank and potentially hack into your account.

Starling told Which? it has 'made a conscious decision' not to send OTPs via SMS because it does not believe this is secure.

Banks must ensure customers are fully aware of these risks and use other tools at their disposal to frustrate scammers, such as behavioural biometrics where security systems can recognise the unique way you use your phone or laptop.

  • Sign up for our free scam alert email

This article was updated on 14/03/22 to reflect Danske Bank's new position (allowing one-time passcodes via landline).

New fraud checks could catch out online shoppers - Which? News (2024)
Top Articles
Menudo Rojo (Red Mexican Tripe Stew)
Easy Steak Fajitas - Quick Weeknight Dinner Idea!
Petco Westerly Ri
University of Louisville Libraries on LinkedIn: #bannedbooks #censorship #uofl #firstamendment #studentlife #librarylife
Jodie Sweetin Breast Reduction
Lonely Ghost Discount Codes - 20% Off | September 2024
Cornell University Course Catalog
Hallmark White Coat Ceremony Cards
Swap Shop Elberton Ga
Lynchburg Arrest.org
Steve Bannon Issues Warning To Donald Trump
2013 Chevy Sonic Freon Capacity
Ff14 Cloth Softening Powder
Browse | Obituaries | Enid News and Eagle
Atl To London Google Flights
Offsale Roblox Items are Going Limited… What’s Next? | Rolimon's
Wells Fargo Banks In Florida
Huniepop Jessie Questions And Answers
Cara In Creekmaw Code
James And Lisa Goy Obituary
Walmart Com Careers Jobs
Alvin Isd Ixl
Watch Psychological Movies Online for FREE | 123Movies
Hulu documentary delves deeper into the Randall Emmett scandal
Omaha Steaks Molten Lava Cake Instructions
Sissy Hypno Gif
Joy Ride 2023 Showtimes Near Cinemark Huber Heights 16
Tamiblasters.in
Aka.ms/Compliancelock
02080797947
Bully Scholarship Edition Math 5
201-654-6727
Craigslist Labor Gigs Albuquerque
Enter Cautiously Nyt Crossword
Ups Store Laptop Box
Magma Lozenge Location
Jetnet Retirees Aa
Presentato il Brugal Maestro Reserva in Italia: l’eccellenza del rum dominicano
10000 Divided By 5
Myapps Tesla Ultipro Sign In
Craigslist Philly Free Stuff
Indium Mod Fabric
Ace Adventure Resort Discount Code 2023
Bridgeway Diagnostic Auburn Al
Scotlynd Ryan Birth Chart
High Balance Bins 2023
Aso Tools Vancouver
La tarifa "Go Hilton" para los amigos y familiares de los miembros del equipo - Lo que debe saber
The 7 best games similar to Among Us for Android - Sbenny’s Blog
Fapspace.site
Daily Cryptoquip Printable
Twisted Bow Osrs Ge Tracker
Latest Posts
Article information

Author: Jeremiah Abshire

Last Updated:

Views: 6238

Rating: 4.3 / 5 (54 voted)

Reviews: 93% of readers found this page helpful

Author information

Name: Jeremiah Abshire

Birthday: 1993-09-14

Address: Apt. 425 92748 Jannie Centers, Port Nikitaville, VT 82110

Phone: +8096210939894

Job: Lead Healthcare Manager

Hobby: Watching movies, Watching movies, Knapping, LARPing, Coffee roasting, Lacemaking, Gaming

Introduction: My name is Jeremiah Abshire, I am a outstanding, kind, clever, hilarious, curious, hilarious, outstanding person who loves writing and wants to share my knowledge and understanding with you.