We’ve fixed an issue that meant we weren’t storing some customers’ PINs correctly

Ok… everyone in my family has just called me to ask if this email is a scam :rofl::see_no_evil:

Good point but I don’t think I’m the only one who thinks this… :man_shrugging:

Agreed I’m not changing my pin coz of Monzo’s ‘mistake’.

2 Likes

Monzo engineers have access to our names addresses DOBs pictures of our IDs and they are worried that the engineers were writing down my pin, traveling to my house breaking in and nicking my card,

I think telling people to change the pins is overkill, it’s nice to be informed though.

3 Likes

Like a few others, I’ve used neither of these features yet still received the E-mail.

1 Like

Knowing your PIN would allow transactions in app so it’s not just the physical card

2 Likes

I don’t think anyone is suggesting you’ve done anything incorrect. However, it’s simply a precaution. The same happens if any online service that gets compromised and stores your e-mail/password. You’ll hopefully be notified and told to change your password even if only the hashes were exposed. In both cases you wouldn’t have done anything incorrect.

I presume that in the unlikely event that someone decides not to change the pin and then fraudulent activity does take place that the customer is not deemed negligent?

2 Likes

Pretty bad security blunder :man_facepalming:t2:

6 Likes

If you’ve been told your PIN has potentially been compromised and you decide not to change it then I’d call that negligent

2 Likes

I’ve just had this pop up in app…

2 Likes

Then Monzo should definitely change the wording from being a precaution to being a requirement that people must change their pin numbers.

4 Likes

I think communicating this is excellent, and I value it - but the execution could come off a little bit too alarming and (clearly by this thread and other conversations) could be concerning to many.

Something Freetrade do which I like is they use their chat (Powered by Intercom I think) to talk to their users. Comes from an authentic source in the app. If users had concerns they can then just reply as normal and be put in touch with a COp.

10 Likes

But then they’ll need to be able to login to my email for the magic link,

If this sort of breach happened to any other service I wouldn’t change my pin, it’s just that if there’s fraud on my account I can’t risk not being covered that’s why it bothers me.

They’ve claimed that only monzo staff had access to these logs , so if there’s fraud I don’t think it’s reasonable to say that I was negligent, the banks own staff knowing security details is what happens at every bank.

2 Likes

Don’t start that argument :rofl: :speak_no_evil:

4 Likes

Why was this flagged :confused:

2 Likes

I agree, I think there’s a greater chance of Brexit being successful than there is of being any fraud as a result of this, but I’m being wildly hypothetical :grin:

3 Likes

Not received email to change pin.

I use apple pay. Should I change my pin? I don’t remember using my card with the pin so it theoretically shouldn’t be logged, right?

Good news then :smiley:

If you got the email change your PIN, if you didn’t then you don’t need to :slight_smile:

1 Like