The Business Magazine - B2B Business News - Site Logo
The Business Magazine - B2B Business News - Site Logo
The Business Magazine May 2024
Read now

Cybersecurity consultancy Red Maple Technologies finds bank security flaws put consumers at risk from fraud

The Business Magazine article image for: Cybersecurity consultancy Red Maple Technologies finds bank security flaws put consumers at risk from fraud
8 February 2023

Basic security flaws on some of the biggest banks’ websites and apps are putting consumers at increased risk of falling victim to fraud, according to research undertaken by Cheltenham-based cybersecurity consultancy Red Maple Technologies on behalf of consumer rights organisation Which?

The consumer champion’s tests found several banks were missing basic online and app protections.

The research comes after 29,102 cases of remote banking fraud were reported to industry body UK Finance in the first half of 2022.

This involves unscrupulous scammers gaining access to consumers’ bank accounts via their internet, telephone or mobile banking and making an unauthorised transfer of money from the account.

Which? tested the customer-facing security systems of 13 current account providers from September to November 2022, with help from independent security experts at Red Maple Technologies.

The banks were scored across four key categories – login, navigation and logout, account management and encryption – for both their online banking security and app security.

Among other issues, banks were marked down for not adequately blocking weak passwords, sending one-time passcodes or other sensitive information via text messages, which is the least secure approach, and failing to log customers out after five minutes of inactivity.

They also lost points for allowing access to accounts from multiple web browsers or IP addresses at the same time, without flagging this as a potential cyber attack, and for sending customers notifications that include a phone number or web link.

The latter can be a gift to scammers who often replicate texts and emails to trick people into calling them or entering their details on a fake website.

Virgin Money got the lowest total scores for online (52 per cent) and app (54 per cent) banking. Virgin Money’s poorest scores for online banking were in the navigation and logout and account management categories – it got two stars out of five for both. It also scored just two stars for the encryption on its app.

Red Maple Technologies found six outdated Virgin Money web applications which had potential vulnerabilities. The bank noted minor vulnerabilities on three and said these will be corrected.

Virgin Money did not adequately block insecure passwords and remove phone numbers from notifications.

There were no security checks to pay someone new, change an email address or edit the details of a payee.

Which? also found issues with website session management, though the bank said it plans to improve this in early 2023, following Which?’s tests.

Which? had several concerns when it came to TSB, which scored 57 per cent for its app, the second lowest, but got a slightly higher score of 66 per cent for its online offering.

It still asks basic security questions such as ‘name your favourite food’ to recover login details. It also failed to block insecure passwords and only requires six characters – banks should encourage much longer passwords.

Red Maple Technologies found a potentially vulnerable subdomain, which TSB said will be removed in 2023, and two outdated web applications.

TSB also lost points for using SMS-based security, not sending alerts when sensitive account changes were made and including phone numbers in new-payee notifications. TSB said it is reviewing alerts and password complexity as part of its digital strategy. The bank told Which? that it has now removed phone numbers from all SMS alerts, except for one which is due to be removed in February.

Starling came out top for online banking security (82 per cent), although its high-scoring app (80 per cent) is also key to security – it is used to authorise online logins and instant alerts of any sensitive activity. Starling scored five stars in almost every category.

Which?’s top scorer for online banking security last year, HSBC, performed well once again this year - it followed closely behind Starling with a score of 80 per cent for online banking while its app had the highest score of 82 per cent.

While Which? found fewer issues with Nationwide's app security (67 per cent), it had the second lowest score for online banking security at 63 per cent.

Which? thinks it should notify users of sensitive changes to contact details, password changes and new payees – although Nationwide said it is looking to offer this in the future.

The banks included in the research also have behind-the-scenes systems that Which? and Red Maple Technologies were not able to test.

Rob Stemp, CEO of Red Maple Technologies, said: “It is vital for consumer protection that banking apps and websites use the strongest possible security mechanisms to safeguard customers. Mobile apps offer convenience with the ability to quickly block and check transactions, but it cannot be at the expense of security.

“As part of our research we also checked the bank’s email authentication settings - SPF, DKIM and DMARC - which stop banks from being impersonated, effectively eliminating the risk posed by spammers, phishing and other spoof email issues. These critical settings mean that customers always know that any communications from their bank are legitimate.”

Which? believes the banking industry must improve its cyber defences against scammers, who are becoming increasingly sophisticated in their methods.

The consumer champion wants improvements that would see weak passwords blocked and also believes that sensitive data should not be sent via SMS text messages as these can be intercepted.

If the worst happens and consumers do fall victim to remote banking fraud, in many cases they will be entitled to a refund from their bank.

Rob Stemp continued: “What was interesting was seeing how the newer, app-based banks have more comprehensive measures in place compared to some of the more traditional banks. Having worked within some of these large enterprises we understand that they often suffer with issues of complexity within their IT estate and legacy systems at the core of their infrastructure.

“As a result of the research, many of these banks have now made changes to their systems and standard practice, which is extremely positive, however with the cost of cybercrime set to hit $10.5 trillion by 2025, 8% of the world’s GDP, these are issues that all organisations need to get a grip on, especially those in the banking sector.”

Sam Richardson, Which? Money Deputy Editor, said: “Banks should not be leaving these open doors for scammers to exploit and must up their game to protect their customers properly.

“By making improvements, such as blocking weak passwords, banks can take an important step in preventing unscrupulous fraudsters from attempting to steal money and personal data from consumers.”

Peter Davison is deputy editor of The Business Magazine. He has spent his life in journalism – doing work experience in newsrooms in and around Bristol while still at school, and landing his first job on a local newspaper aged 19. By 28 he was the youngest newspaper editor in the country.

An early advocate of online news, he spent the first years of the 2000s telling his bosses that the internet posed both the biggest opportunity and greatest threat to the newspaper industry and the art of journalism. He was right on both counts.

Since 2006 he has enjoyed a career as a freelance journalist. He lives in rural Wiltshire with one wife, two children, and three cats.

Latest deal ticket

All deals
Entaco Ltd (Worcestershire)
has completed an MBO with support from
Traditum (Yorkshire)
May 2024
Who's behind the deal?


All events

South Coast Property Awards 2024

Hilton Southampton
Utilita Bowl
More info

Leadership Roundtable: Developing strategies for financial returns over the next decade

Herrington Carmichael, Farnborough Aerospace Centre, GU14 6XR

More info

Leadership Roundtable: Opportunities and challenges in the Care Sector

Herrington Carmichael
Farnborough Aerospace Centre, GU14 6XR
More info

Thames Valley Tech & Innovation Awards 2024

Reading FC Conference & Events
Select Car Leasing Stadium, Reading
More info

Leadership Roundtable: Search Fund Exits & Acquisitions

Shawbrook Bank
9 Appold Street, London EC2A 2AP
More info

Thames Valley Property Awards 2024

Ascot Pavilion
Ascot Racecourse
More info

South Coast Tech & Innovation Awards 2024

Hilton Southampton
Utilita Bowl
More info

Thames Valley Deals Awards 2024

Reading FC Conference & Events
Select Car Leasing Stadium, Reading
More info

Hampshire Business Awards 2024

Farnborough International
Exhibition & Conference Centre
More info

Related news

Group Titles

Dorset BIZ NewsHampshire BIZ News