7 ms·
Ask HN: Found a way to fraud my bank thru a loophole, how to disclose properly?
Hey guys,
First, excuse the messy title - I was limited to 80 characters.
I recently found a way to create money out of thin air through a loophole in my bank's current banking portal.
I tried reporting it a few times, but every time I am stonewalled by a low-level employee, telling me they will call me back later in the day, which never ends up happening.
The furthest I've come is to call their abuse department, found on their ARIN records, who seemed to take it seriously, but I ended up going full circle - back to the low level-guys.
I discovered it inadvertently and, technically, defrauded them of ~0.32 US$ using legitimate transactions that the bank's software should have handled differently. Pennies, but still.
I also confirmed the issue with other accounts and other transactions - my account is not a glitch in the system.
What is the best course of action? How would you get in touch with security officials at a big bank?
I mostly don't want to get caught or charged with (attempted?) fraud over $0.32.
I have also spent quite a few hours trying to disclose it, unsuccessfully. What would be the best way to get some of this time spent trying to do things right compensated?
Thanks!
- miguelrochefort 10y ago> What would be the best way to get some of this time spent trying to do things right compensated? Creating more money out of thin air seems like the appropriate compensation. /s
- smt88 10y agoDocument your attempts to alert the bank. You should have proof that you contacted them about it. Don't use the loophole obviously. Definitely switch banks.
- alexleclair 10y agoYep, good idea. I'm documenting everything I can think of. Tried the loophole three times - once inadvertently, a second time to try a different approach and a third time on a different account. Told the low-level techs all about that, they didn't seem too concerned about le ~0.32$ I created, but still being careful. I'm documenting everyone I talk to as well - there is never any case file # though. Are there any other things you think I should document? As for switching banks - definitely will. This is realllllly bad.
- smt88 10y agoIf it's possible for regular transactions to look like fraud due to this loophole, you should make sure all your legit transactions have a paper trail (receipts or whatever).
- alexleclair 10y agoGood idea, thanks!
- tmaly 10y agoapply for a job with the bank
- alexleclair 10y agoWell, I don't really want to work there. And I wouldn't be able to disclose the info simply by applying, I'm sure. The real question is - how can I get the higher ups attention? Or would I be better off going public with it, given the private disclosure didn't work out?
- partisan 10y agoWhen I worked at a big company, one thing that always got everyone's attention was when the CEO received written letters from his customers. It's a very slow way of going about airing grievances, but it might work the same way. The CEO was notified and every letter was responded to.
- alexleclair 10y agoSimilar to the LinkedIn[1] idea - I like it! Nice, clever and convenient :) Thanks [1] https://news.ycombinator.com/item?id=11772336 https://news.ycombinator.com/item?id=11772336
- partisan 10y agoAlso, stop doing anything that involves creating money from thin air. In today's world, that could get you sent to prison.
- alexleclair 10y agoHah! Yeah. The last time I did it was on the phone after a low-level tech from the bank asked me to do it. I have her name and employee number, in case anything happens. But yes, definitely.
- joshmn 10y agoIn 2016 I've found that this strategy — "hey, I found a really bad security thing, and a pattern of really bad security things" or "hey, I did something 100x better than what you're doing and people know it, here's my stuff, let's join forces" — doesn't work like it used to. In fact, any advice often falls on deaf ears and feels like pandering. I'm looking at you (however among many others), YC's favorite payment processor.
- exolymph 10y agoYou've tried to disclose and they made it impossible. Time to post it on Twitter and cc @troyhunt.
- alexleclair 10y agoHah! Yeah, that's definitely something I'll try if my latest inquiries don't go through! :) Thanks!
- exolymph 10y agoGood luck! I respect that you're making the effort to do the right thing, even though I don't think the bank deserves it.
- sheraz 10y agoI use LinkedIn when I have to penetrate a bureaucracy such as this. Nothing gets action faster when a VP or higher get a personal email / phone call regarding something like this. Step 1: Troll linkedin to find these people in positions of real power. Step 2: If they are easy to reach via email or on the platform, try that. Failing that, call their HQ and work the phones until you get to them. Step 3: Win.
- alexleclair 10y agoActually a pretty good idea! Thanks!
- otterley 10y agoI think you mean "trawl," not "troll." :-)
- sheraz 10y ago...or do I ;-) ?
- deleted 10y ago[deleted]
- Gustomaximus 10y agoI did this recently when I noticed a way into a company customer database that had name/address/phone/purchases. Initially I contacted 3 different employees who I had emails addresses and nothing happened. Some months later when I saw nothing changed I contacted the CEO on Linkedin. Surprisingly he wrote to me saying thanks and this was really bad, rather than the expected no response or legal nothing to say response. He also said someone would be in contact to thank we and then some days later I got a call from the CIO who asked 'what do you think I should do to fix'... very strange call. Most importantly I made sure on the email sent to the company clearly stated I had accidently found this error in their systems, only told them and worded it in a way that if by small chance they went legal on me I would post the correspondence on social media (they are several very large brands) and get the relevant attention that would likely make them back off. I aslo found one that I feel is, while less relevant, a breach of data trust with Google but they believe this is a 'feature': I posted about this one here: https://news.ycombinator.com/item?id=10591980 https://news.ycombinator.com/item?id=10591980 Personally I find it strange Google would confirm an email address exists and share my first/last name with anyone.
- chad_strategic 10y agoIs this a big bank? If so I would let it slide. If you really understand how big banks stole from the US taxpayer in 2008, you might want to steal more.
- loumf 10y agoYou could contact a legitimate security firm that buys vulnerabilities to get the credit (and knows how to report responsibly). You want one that immediately discloses and does not resell.
- boodm 10y agoCall the bank's regional HQs. Ask to speak with the manager of security. Report the instance. Ask for his/her name and number. Tell the individual you plan to go public with the information in 48 hours if there's no resolution. The individual will feel a career risk and act accordingly.
- alexleclair 10y agoBold. Love it!
- dragonbonheur 10y agoDon't call from your land line. Don't call from your cell phone. Find a public phone, away from cameras.
- jason_slack 10y agoI have to ask the folks here. Given the OP used an ID that seems easily traceable and he/she admits to defrauding the bank publicly (I know, just .32 USD, but still people are going to prison these days for so many silly things). Should OP retain legal counsel and have the lawyer make contact with a VP? Or does lawyer-ing up make OP look guilty from the start?
- alexleclair 10y agoWell, there are audio recordings of bank staff asking to demonstrate the flaw and there are also recordings of the same staff telling me that going public is within my rights, but they don't seem to understand the underlying issue. Not sure about lawyering up, maybe it's something that I should do (should have done?)..
- jason_slack 10y agoIANAL, but I thought I would mention it anyway. Do you have these recordings for safe keeping?
- alexleclair 10y agoSome places, yes. But you're right, definitely. Better safe than sorry!
- jason_slack 10y agoOne more idea. I once witnessed another company being shown a competing companies unreleased product while testing my own product in a testing facility. I send them an unmarked envelope with a letter of what I saw and the names of the people involved (as they were wearing name tags). This is stone-age now, but perhaps it might help.
- cweagans 10y agoFind a good lawyer. Reach out to them and let them know what's going on and that you may require their services in the future. Just establish the relationship now so that you don't have to do that legwork on a 2 minutes phone call.
- brador 10y agoStop. You're risking your freedom to save a corporation. If you press ahead you will be dealing with people who lack knowledge and are scared of what you did affecting their career. They will rake you over coals. And you will have gained what? The minute pleasure of helping them save a few bucks? You have a desire to help people. That's great and noble and commendable. But that's not what you would be doing here. My advice: drop it. It's not worth it. If there was no risk to life or liberty from what you found, then yes chase the disclosure. But there isn't. Drop it and forget it ever happened. Your life is worth it.
- piron_t 10y agoI can't agree more with Brador, you're really risking your freedom and if they don't have a bug bounty, you might end up in court / being sued. Here is a google translate from a French article that you might find interesting : https://translate.google.com/translate?sl=fr&tl=en&js=y&prev=_t&hl=en&ie=UTF-8&u=http%3A%2F%2Fkorben.info%2Ferreurs-dun-professionnel-pentest.html&edit-text= https://translate.google.com/translate?sl=fr&tl=en&js=y&prev...
- alexleclair 10y agoThanks for the link
- alexleclair 10y agoYeah, makes sense. I'll probably just forget about it (but switch banks beforehand!)
- ChuckSanders 10y agoPlease see my other comment and contact me, this is my job and I can get you in touch with the right folks without any kind of risk or BS
- chrisbennet 10y agoJust drop it. It only hurts the bank and you did your best to warn them. At this point the only reason to peruse it is to get recognition/reward or attention for being clever.
- dreamdu5t 10y agoThe bank isn't going to pay you money. You gain nothing from reporting this, and risk getting fucked over for mere pennies. Just forget about it and move on with your life.
- drallison 10y agodefraud is the verb form. To defraud is to illegally obtain money from (someone) by deception. fraud is the noun form. 1) wrongful or criminal deception intended to result in financial or personal gain or 2) a person or thing intended to deceive others, typically by unjustifiably claiming or being credited with accomplishments or qualities. The English language is changing. Modern usage has promoted some nouns to verbs in informal use, but for many of us, the change is a bit like scratching your fingernails on a blackboard. In a situation like this, where credibility is important, careful attention to usage and spelling is critical.
- Gustomaximus 10y agoIt's amazing that any large firm who business heavily relies on security doesn't have some kind of report a bug or bounty system easily findable. This should be as standard as a 404 page.
- WhatIsThisIm12 10y ago> What would be the best way to get some of this time spent trying to do things right compensated? That depends how quickly you can get the money out of the bank, and get yourself out of the country!
- cweagans 10y agoTry to find developers that work at the bank via LinkedIn or something. Ask if they have a bug bounty program, and disclose things appropriately. You won't ever get to the right person calling in on the customer support or abuse numbers. You need to go around. EDIT: Also, how long does that money stick around in your account? I wonder if there is some kind reconciliation processes that go through and square everything up. The web software is probably just a replica of the actual ACH data, so maybe those processes would correct things and it's not as big of a deal as it seems to be?
- tapiwa 10y agoDocument the vulnerability. Document your attempts to contact the bank. Contact your local[1] newspaper. Particularly one that is big on investigative journalism, and technology. A good hint is if they covered the recent SWIFT bank heists. [1]Local is relative. If it is a big national bank, go national. The idea is for them to do an article, not necessarily exposing the vulnerability, but how processes (or lack thereof) in the big banks allow security holes to go unfixed.
- saluki 10y agoSTOP, you're already done this on multiple accounts that is asking for trouble. I wouldn't risk interacting with them further if they aren't interested in listening. Document that you tried to contact them and report it so they can fix it. But you're in the gray area where they could attack you feeling you were attacking their their system. Forget it and move on. Otherwise you're going to be tempted to: https://www.youtube.com/watch?v=GyB6ffmXsZo https://www.youtube.com/watch?v=GyB6ffmXsZo (Office Space Virus Scene) And we all know how that ends.
- ChuckSanders 10y agoI am a developer who works with one of the largest US banks and I would love to speak with you about what you have found and pass it along to the head of security in my office.. Unfortunately like others have pointed out you will more than likely encounter low level employees who dismiss you OR, and this is the dangerous part.. you may bruise the ego of someone in a position who can and should listen to you.. possibly resulting in adverse actions being taken against you. Do you have an email address I could contact you at? I could conference you in to my department and see the exploit you found(MOST banks share the same backend software for their online services so this is alarming)