Not sure if this is right thread but google pushed this to the top of my news feedā¦
OK itās from a paper that barely ranks above the beano but these stories get aboutā¦
Not sure if this is right thread but google pushed this to the top of my news feedā¦
OK itās from a paper that barely ranks above the beano but these stories get aboutā¦
MONZO customer Harriet, whose name has been changed
No sh*t.
It is interesting how Monzo refunded the charges and gave compensation after the media were involved. When these things happen either refund them, or donāt refund them. The precedent is now set. Got scammed? Go to the press.
It basically using someone who was scammed for marketing purposes. There is no way they would have paid out unless the media were involved. And of course it is not only Monzo who are guilty of it.
Thatās nearly every story I read in a paper or hear on radio around this kind of thing
After we contacted X they decided to pay
That happens almost every time a newspaper picks up on a story regardless of which bank is involved.
(On another note, was this story āripped from the forumā? Certain parts of it sounded very familiar, as if Iād read them before.)
āThey had information such as my motherās maiden name, they had my postcode, they had my date of birth, they had my last four digits of my bank account numberā¦They proceeded to state that I had three savings pots, and a current account. I donāt know how they would know thatā
Oh Harriet. They had hacked your email ā they were actually in your bank account.
Yes - the only thing they did not have was the PIN to move the money themselves it seems.
Saw this today @simonb @cookywook
Iāve always wondered about who is liable once your email is hacked, surely thatās no longer a Monzo issue.
Or did Monzo take on that liability when they use email as away to communicate with you
But they donāt use email to communicate with you, they use the app.
If you mean āWhy did Monzo pay outā, this is probably why:
But in terms of your email being hacked, thatās nothing to do with Monzo. In 99% of cases, thatās on the user not securing their account properly.
I mean more the use of email and magic links
Yeah really its ease of targetting and value really
Good Education would solve many of these problems
EDIT: Thatās what banks should be working on how to educate their customers well( Not just banks, family, friends etc.)
Easier said than done, apparently:
Lloyds told the Observer that Ross did not take sufficient steps to verify that the text message was genuine and ignored a fraud warning about spoofed numbersā āsafeā accounts.
Ross only recalls a generic fraud alert which the scammers told her was a default message sent before every transaction.
![]()
These scams are the online equivalent of someone approaching you on the street with the bankās name tag and claiming that your money is at risk and you should go to the ATM, withdraw it and give it to them.
We all agree that someone falling for this in the physical world is quite stupid, so why are we tolerating it online, and even worse, trying to blame the banks for it? Can I also go withdraw all my cash at the ATM, throw it all in the wind and then blame the bank for not refunding my stupidity?
The email interception cases seem to be the fault of the business and the bank - theyāre the ones I have most sympathy for. The business for not securing their email and the bank(s) for not implementing payee name checks. Although I still think there should be better ways for businesses to accept payments other than sending an email with an account name and number.
The code some of the banks have signed up to is way too vague and pretty worthless when it has to be put into action. Plus, thereās really no incentive for the banks to actually improve their ability to combat fraud. The payee name check thing is probably still quite distant in the horizon for most banks.
I agree, the email cases should be the fault of the business. As far as the customer is concerned the business has invoiced them. They have no way to tell whether the bank account details they are given on the (fake) invoice are legitimate. The business should eat the cost in this case (Iād argue that for a lot of businesses the impact of an email compromise is much bigger than stolen funds, as there could be also confidential data coming through the same email address).
But I was talking more about the conventional āyour money is at risk, you need to move it to this safe accountā scam. Thereās really no excuse for falling for one of those and I donāt think the banks should be liable for it.
CoP is mandatory for the major UK banks by 31st March 2020: https://www.psr.org.uk/sites/default/files/media/PDF/PSR%20Specific%20Direction%2010%20Confirmation%20of%20Payee%20-%20February%202020.pdf