£21k stolen from phone snatch

Author
Discussion

leef44

Original Poster:

4,957 posts

168 months

Saturday 14th December 2024
quotequote all
https://www.bbc.co.uk/news/articles/cy8y70pvz92o

BBC article about a guy having lost £21k after his phone was stolen. But he says it has facial recognition and password protection.

How is this possible? The thief even managed to get a £7k loan from HSBC but the victim could not get such a loan himself when he was trying previously.

Richard-D

1,491 posts

79 months

Saturday 14th December 2024
quotequote all
Glad you posted this, I was going to.

I also don't understand how they accessed his bank account to move the money, never mind the loan. Was hoping someone might have some insight.

bitchstewie

58,992 posts

225 months

Saturday 14th December 2024
quotequote all
Don't know all the specifics with this guy but in general terms say you hand someone your laptop or phone right now and it's unlocked and the person you give it to can get to your email and answer your calls and see your SMS messages think how much they can do to fk up your life and how quickly they could do it.

leef44

Original Poster:

4,957 posts

168 months

Saturday 14th December 2024
quotequote all
They were able to transfer £14k to Monzo which is easier to make a payment but just can't see how they got access to the money in HSBC in the first place.

Unless there is more to it than meets the eye e.g. the thieves made it look like a simple grab but it has actually been targeted so they already had his password e.g. over his shoulder while he was accessing in public. But then again, he wouldn't be doing that in public since he would use facial recognition.

abzmike

10,406 posts

121 months

Saturday 14th December 2024
quotequote all
Each of the banking apps I have need a PIN or facial recognition to get into even if the phone is unlocked, seems an odd tale to me. I guess the crim could do PIN resets but that usually needs challenge questions…

tim0409

5,273 posts

174 months

Saturday 14th December 2024
quotequote all
I read the article and was left asking the same questions as well. Even if they take your unlocked phone, presumably all the banking apps are locked via passcode or facial recognition?

bitchstewie

58,992 posts

225 months

Saturday 14th December 2024
quotequote all
Maybe he uses a password manager but has the app configured not to lock or it was unlocked.

Maybe he's a prat and has all his password in his Notes app.

Like I said no idea how the loan stuff happened and I don't know the specifics of how you login to the banks in question but I can think of all kinds of ways someone could get enough info from an unlocked phone to login to a bank account - you could do it with mine if you had access to my unlocked phone and I'd been slack with storing passwords.

NickXX

1,612 posts

233 months

Saturday 14th December 2024
quotequote all
Good reason to enable Face ID on SMS and mail apps on iPhone.

leef44

Original Poster:

4,957 posts

168 months

Saturday 14th December 2024
quotequote all
Is Face ID more secure than finger print, just out of curiosity?

bitchstewie

58,992 posts

225 months

Saturday 14th December 2024
quotequote all
Exactly.

Maybe the phone doesn't need to unlock before previewing SMS messages.

Maybe there's no SIM PIN configured.

Etc.

NickXX

1,612 posts

233 months

Saturday 14th December 2024
quotequote all
leef44 said:
Is Face ID more secure than finger print, just out of curiosity?
Probably not much of a difference in this context. The risk is if you have your phone snatched while it’s unlocked. Without Face ID enabled at the app level, they will have access to your SMS and emails which opens up the ability to do password resets etc.

bitchstewie

58,992 posts

225 months

Saturday 14th December 2024
quotequote all
leef44 said:
Is Face ID more secure than finger print, just out of curiosity?
I'm sure cryptography experts will have a view or two but in the context of handing an average thief a locked iPhone secured with one or the other I wouldn't care which one it was - my view would be good luck with that.

Bluevanman

8,532 posts

208 months

Saturday 14th December 2024
quotequote all
All the financial apps on my phone need a fingerprint,after the phone is unlocked which again requires a fingerprint or a pin.
Even if his phone was permanently unlocked it would still need face I'd or fingerprint to access the apps

popeyewhite

23,007 posts

135 months

Saturday 14th December 2024
quotequote all
leef44 said:
https://www.bbc.co.uk/news/articles/cy8y70pvz92o

BBC article about a guy having lost £21k after his phone was stolen. But he says it has facial recognition and password protection.

How is this possible?
The app was open when the phone was snatched presumably.

wombleh

2,113 posts

137 months

Saturday 14th December 2024
quotequote all
Speaking about this with some former security colleagues in banking, consensus is shenanigans.

popeyewhite

23,007 posts

135 months

Saturday 14th December 2024
quotequote all
wombleh said:
Speaking about this with some former security colleagues in banking, consensus is shenanigans.
One does wonder.. .

Vasco

18,009 posts

120 months

Saturday 14th December 2024
quotequote all
Some of us still won't have ANY financial data on any phone......

aeropilot

38,364 posts

242 months

Saturday 14th December 2024
quotequote all
Vasco said:
Some of us still won't have ANY financial data on any phone......
yes


Mabbs9

1,408 posts

233 months

Saturday 14th December 2024
quotequote all
R4 had a good bit on this the other day. Specifically keeping your card with your phone. Worth looking it up. It's scary how fast they can access your accounts, including the savings accounts.

popeyewhite

23,007 posts

135 months

Saturday 14th December 2024
quotequote all
Mabbs9 said:
keeping your card with your phone.
People do this?!?