Secure Code — Hsbc

A victim in London receives a call from "HSBC Fraud Department." The number on the caller ID matches the bank’s real number (spoofed). The voice says, "Someone in Manchester is using your card. We are sending a Secure Code to your phone. Read it to us so we can cancel the transaction."

HSBC Secure Code proves you have the phone. It does not prove that you aren't being tricked. The bank has solved cryptography, but it hasn't solved gullibility. The "Silent" Transaction: A Feature You Don't Know About There is a ghost mode to Secure Code that most customers never notice. hsbc secure code

The criminal, who is simultaneously on the checkout page of a luxury goods site, types in that code. The bank thinks the victim approved it. The money is gone. A victim in London receives a call from

It asks for a sequence of digits you don’t have memorized. You fumble for your phone. The clock ticks down from 60 seconds. Read it to us so we can cancel the transaction

You’re about to buy a new laptop. You’ve clicked “checkout.” Your card details are in. Then, the screen freezes. A small gray box pops up from your browser, or a push notification buzzes your phone.