Full list of best and worst banks ranked for online security - is yours safe? (2024)

WEAKNESS in some banks' security could leave customers exposed to scammers, a new Which? investigation has found.

With more people than ever before using mobile banking, criminals are increasingly viewing mobile phones as gateways to consumers' personal details.

2

2

The consumer champion has rated the best and worst firms for keeping customers safe.

Which? researchers tested banking website and app security across four key criteria for a total score of 100%.

  • Login procedures
  • Security best practice
  • Account management
  • Navigation and logout

While all firms do use multilayered security that helps reduce the likelihood of major security breaches, Which? believes that some firms that finished towards the bottom of the rankings fell short of the high standards customers should expect.

Read more in money

Full list of best and worst banks ranked for online security - is yours safe? (3)
TO YOUR BENEFIT Full list of 12 benefits being paid early next week
Full list of best and worst banks ranked for online security - is yours safe? (4)
DEBT BUSTER Martin Lewis' 'core weapon' to beat high interest credit card charges

BOTTOM OF THE PILE

TSB scored 54%t for its mobile app security and 67% for its online security - the lowest and second-lowest scores, respectively.

The firm was the only one to score just two stars for online account management and just two stars for security best practice for its app.

The most serious problem the security best practice tests discovered was a "medium-risk" issue on the TSB app.

Its improper handling of sensitive data meant that it could be read by other apps running on the phone, making it more likely that other apps could access them.

Most read in Money

BEER WE GOWetherspoons is cutting price of seven drinks at 700 pubs in just days

TOTAL RECALLIceland recalls product and issues ‘do not eat’ warning over health risk

HOUSE THATI save £100s living in a narrowboat - I sleep in a living room but I’m smitten

TSB told Which? that the matter was under review and a fix will be "considered in the future".

How to protect yourself from scams

The bank also sent a phone number in an SMS alert, which could be replicated by scammers.

TSB told Which?: "We have removed phone numbers from the vast majority of SMS alerts with this alert being the final in plan for updating to remove the phone number."

TSB's password requirements are still only six characters and users can still choose a range of insecure passwords, which are easier for scammers to crack, Which? said.

A TSB spokesperson said:"We continue to strengthen the security of our internet and mobile banking while delivering a positive and convenient user experience for customers.

"That's reflected in our high app store ratings."

Which? also uncovered problems with The Co-operative Bank's security measures.

The bank came bottom of the online security table, with a score of just 61%.

It got three stars for both account management and navigation.

When it came to security on its mobile app, The Co-operative Bank came second-last, with a of 57%.

The firm was one of three rated average (three stars) for login security, and it was the only bank to fail to require a two-factor authentication 92FA) login on a test laptop.

2FA protects your accounts by requiring an extra level of verification before logging in – such as a text confirmation.

The bank also fails to block customers from setting weak passwords.

The Co-operative Bank said:"The security of our customers' accounts is always our top priority.

"Customers can be assured we have robust security measures in place to protect them and their money.

"We are constantly reviewing and enhancing our security controls and we will be delivering a number of further improvements in 2024 to give our customers peace of mind that they can continue to bank safely and securely with us."

Lloyds was the only bank that failed to log out website users after five minutes of inactivity, Which? found, despite this being a regulatory requirement.

The bank told Which? that this makes things easier for vulnerable customers.

THE BEST PERFORMERS

Starling, NatWest, and RBS were at the top of the pile for online security, with both posting impressive total scores of 87%.

While both firms scored four stars for login security online, they both posted a full five stars for security best practices, account management and navigation.

The best performing bank for mobile app security was HSBC, with a total score of 78%.

HSBC posted solid scores for both its app and website, and unlike many of its high street rivals, it does not rely on SMS for login, and researchers found no issues with logout or navigation.

While Barclays finished second in the mobile app rankings, with a highly respectable total score of 74%, it is still yet to fix the website management issues Which? identified last year.

These issues include letting users access accounts from multiple browsers, IP addresses or devices at the same time, which could be flagged as a potential attack by cybercriminals.

The firm told Which? it uses other controls to assess the risk profile of devices accessing online banking, and is planning to add this additional layer of protection later this year.

Sam Richardson, deputy editor of Which? Money, said:"With many people increasingly banking online or on their phones, it's crucial that the banks we trust with our money have security protections that are up to scratch.

"While our investigation found no major security issues, there were some areas of concern that we think the banks in question need to urgently address, so that sophisticated scammers can’t useloopholesto target innocent victims.

"With fraudsters still relentless in their pursuit of our money and a general election looming, the next government must make fighting fraud a national priority, with a Fraud Minister installed to work across multiple government departments."

SIX TIPS TO STAY SAFE ONLINE

WHICH? has shared its six tips for banking customers to stay safe online.

These include:

  1. Protect your mobile: Having your phone stolen needn’t put your money at risk. Add a unique Pin to your Sim card, register for Google’s Find My Device or Apple's Find My iPhone, and disable preview notifications. These flash up messages even when your phone is locked.
  2. Don't use an out-of-date device: Updates contain security patches for new vulnerabilities, so if you bank online, don't use a device that’s no longer supported.
  3. Choose strong, unique passwords: Avoid repeat or simple passwords – too many banks have failed to block this. Use a password manager if you struggle to rememberthem.
  4. Keep your phone and bank cards separate:Never leave your mobile phone and bank cards unattended together – a thief could pass security checks when armed with both.
  5. Check your social media profiles for details:Remove personal data (email, date of birth, phone numbers) from online profiles, as this raises your risk of identity theft. Only accept friend requests from people you know. What you put online is public, so never use anything that's out there in a password or security question.
  6. Act quickly:If you spot an unauthorised payment or changes you don’t recognise, report it immediately. Many banks let you freeze your debit card via their app, or they offer a 24/7 helpline to report lost and stolen cards.

How to report scams

If you think you have been a victim of a scam, you should report it to your bank as soon as possible.

There is no guarantee you'll get yourmoneyback, but banks will often compensate you if you can show you did not know the money would leave your account.

You can forward scam emails [email protected].

If you notice a website that doesn't look quite right, you can also report it to the National Cyber Security Centre by visiting www.ncsc.gov.uk/section/about-this-website/report-scam-website.

You should also contact your provider and report it to Action Fraud, which will give you acrimereference number.

You can do this online by visitingactionfraud.police.ukor by calling 0300 123 2040.

READ MORE SUN STORIES

Full list of best and worst banks ranked for online security - is yours safe? (9)
I PHONE HOME The little-known iPhone setting that's draining your battery - how to fix it
Full list of best and worst banks ranked for online security - is yours safe? (10)
BANK BLOW Full list of banks closing branches for good next week - including Lloyds and TSB

If you're inScotland, report a scam through Advice Direct Scotland online by visiting www.consumeradvice.scot. You can also report scams toPoliceScotland on 101.

If you need further help, contact Citizens Advice Scams Action by visiting www.citizensadvice.org.uk/consumer/scams/get-help-with-online-scams or calling 0808 223 1133.

Full list of best and worst banks ranked for online security - is yours safe? (2024)
Top Articles
Why we should all invest in female founders
How to Get Funding for Your Startup: A Complete Guide
Www.paystubportal.com/7-11 Login
Edina Omni Portal
The Largest Banks - ​​How to Transfer Money With Only Card Number and CVV (2024)
El Paso Pet Craigslist
Toyota Campers For Sale Craigslist
Ventura Craigs List
Beautiful Scrap Wood Paper Towel Holder
Fusion
Craigslist In South Carolina - Craigslist Near You
MADRID BALANZA, MªJ., y VIZCAÍNO SÁNCHEZ, J., 2008, "Collares de época bizantina procedentes de la necrópolis oriental de Carthago Spartaria", Verdolay, nº10, p.173-196.
Stream UFC Videos on Watch ESPN - ESPN
2013 Chevy Cruze Coolant Hose Diagram
Dutchess Cleaners Boardman Ohio
Echat Fr Review Pc Retailer In Qatar Prestige Pc Providers – Alpha Marine Group
History of Osceola County
Tvtv.us Duluth Mn
Leccion 4 Lesson Test
/Www.usps.com/International/Passports.htm
Woodmont Place At Palmer Resident Portal
Form F-1 - Registration statement for certain foreign private issuers
Greenville Sc Greyhound
Chicago Based Pizza Chain Familiarly
Dal Tadka Recipe - Punjabi Dhaba Style
Radical Red Ability Pill
Claio Rotisserie Menu
Our 10 Best Selfcleaningcatlitterbox in the US - September 2024
Shia Prayer Times Houston
Spirited Showtimes Near Marcus Twin Creek Cinema
Funky Town Gore Cartel Video
Craigslist/Phx
Springfield.craigslist
Soiza Grass
The Ride | Rotten Tomatoes
Kips Sunshine Kwik Lube
Craigs List Palm Springs
“To be able to” and “to be allowed to” – Ersatzformen von “can” | sofatutor.com
Ferguson Showroom West Chester Pa
Carteret County Busted Paper
Tricia Vacanti Obituary
Todd Gutner Salary
Senior Houses For Sale Near Me
Walmart Careers Stocker
Gt500 Forums
Erica Mena Net Worth Forbes
Understanding & Applying Carroll's Pyramid of Corporate Social Responsibility
Twizzlers Strawberry - 6 x 70 gram | bol
Vrca File Converter
Dcuo Wiki
Craigslist Centre Alabama
Latest Posts
Article information

Author: Rubie Ullrich

Last Updated:

Views: 6544

Rating: 4.1 / 5 (52 voted)

Reviews: 91% of readers found this page helpful

Author information

Name: Rubie Ullrich

Birthday: 1998-02-02

Address: 743 Stoltenberg Center, Genovevaville, NJ 59925-3119

Phone: +2202978377583

Job: Administration Engineer

Hobby: Surfing, Sailing, Listening to music, Web surfing, Kitesurfing, Geocaching, Backpacking

Introduction: My name is Rubie Ullrich, I am a enthusiastic, perfect, tender, vivacious, talented, famous, delightful person who loves writing and wants to share my knowledge and understanding with you.