FB pixel

BBC reporter and his twin dupe HSBC voice ID recognition system

 

HSBC’s voice ID authentication software designed to prevent bank fraud has been duped by BBC Click reporter Dan Simmons and his non-identical twin, according to a report by BBC News.

Simmons created an HSBC account and signed up to the bank’s voice ID authentication service. His non-identical twin, Joe, was able to access the account via the telephone by impersonating his brother’s voice.

HSBC said it would “review” ways to make the ID system more sensitive following the BBC investigation.

“The security and safety of our customers’ accounts is of the utmost importance to us,” said a spokesman at HSBC. “Voice ID is a very secure method of authenticating customers. Twins do have a similar voiceprint, but the introduction of this technology has seen a significant reduction in fraud, and has proven to be more secure than PINS, passwords and memorable phrases.”

The bank rolled out the voice-based security feature in 2016, which it said measured 100 different characteristics of the human voice to verify the identity of the customer.

Customers are prompted to provide details of their account and their date of birth, and then say out loud, “My voice is my password”.

Even though Joe Simmons was unable to withdraw money after the breach, he was able to access balances and recent transactions, and was given the option to transfer money between accounts.

“What’s really alarming is that the bank allowed me seven attempts to mimic my brother’s voiceprint and get it wrong, before I got in at the eighth time of trying,” Simmons said. “Can would-be attackers try as often as they like until they get it right?”

In addition, a Click researcher found HSBC Voice ID kept allowing him to attempt to access his account even after failing 20 separate times over a span of 12 minutes.

Robert Capps, vice president of business development for NuData Security believes that while biometrics provides an effective strategy for financial institutions, they should not rely on a single biometric modality.

“It takes a layered approach combined with behavioral analytics along with passive biometrics to review hundreds of behavioral points to determine if the person conducting the transaction is really the customer,” Capps explained in an email to Biometric Update. “While you might be able to spoof a voice or fingerprints, hackers cannot reproduce individual behavior.”

In January, HSBC appointed a new technology advisory board of senior CEOs from around the world tasked with figuring out how the bank can benefit from technological innovation, fight against cybercrime, and ultimately leverage its global infrastructure.

Article Topics

 |   |   | 

Latest Biometrics News

 

Report demystifies India’s unique face biometrics market beyond the benchmarks

Biometric authentication is taking off in India as the country’s government and market align around identity as a trust layer…

 

Trust inevitable in building human rights-sensitive digital ID systems

Some digital rights advocates who spoke at the recent ID4Africa 2026 AGM in Abidjan emphasized that for African governments to…

 

Nepalese raise concerns over new DPI loans amid previous project failures

Some experts have expressed apprehensions that the government of Nepal has contracted a new loan for the implementation of a…

 

GripID introduces ultra-compact multimodal biometric enrollment kit

France-based GripID has unveiled the compact V10 multimodal biometric enrollment kit for registration to national ID and civil digital identity…

 

Australia opens feedback on verifiable credential policy, trust framework proposals

Australia’s Department of Finance is inviting community feedback on a policy for using verifiable credentials proposed by the Commonwealth. The…

 

FBI warning on Kali365 phishing kit exposes limits of weaker authentication

A new Federal Bureau of Investigation (FBI) warning about a phishing-as-a-service kit targeting Microsoft 365 accounts is underscoring why major…

Comments

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Biometric Market Analysis and Buyer's Guides

Most Viewed This Week

Featured Company

Biometrics Insight, Opinion

Digital ID In-Depth

Biometrics White Papers

Biometrics Events