13 ms·
Coding error at Santander Bank put millions into random accounts on Christmas
- zinekeller 5y agoThe original link is CNBC as stated in the article. https://www.cnbc.com/2021/12/31/santander-accidentally-put-millions-into-random-accounts-on-christmas-day.html https://www.cnbc.com/2021/12/31/santander-accidentally-put-m...
- dang 5y agoWe've changed to that from https://newsconcerns.com/santander-accidentally-put-millions-into-random-accounts-on-christmas-day/ https://newsconcerns.com/santander-accidentally-put-millions.... Thanks!
- olliej 5y agoAlas a lot of people are going to discover that Monopoly's "bank error in your favor" card doesn't work in the real world :D
- buu700 5y agoI wonder if someone could get legally get away with finagling this into a large bank loan, particularly from a bank with a partially or fully automated application process. "Oh sure, here's my 2021 year-end statement (no additional comment)." (Let's just assume for the sake of argument that the money was left in the account long enough to be reflected in a statement.)
- deleted 5y ago[deleted]
- duxup 5y agoAges ago when I had to put actual paper statements together for a loan they wanted several statements. I assume because someone could just get friends to loan them money, show one statement, and pay their buddies back. The statements didn’t even seem that important to the bank anyway.
- cmeacham98 5y agoI'd be pretty surprised if the bank didn't have some generic term in loan contract along the lines of "the information/papers I gave $bank for this loan is accurate to the best of my knowledge", in which case you'd be explicitly defrauding them.
- adrr 5y agoLying on a loan application is bank fraud.
- refurb 5y agoMortgage company wanted 3 months of statements to show the money wasn’t recently deposited.
- PragmaticPulp 5y agoLook up “seasoned funds”. Banks learned long ago that they need to trace the source of funds and confirm they’ve been in possession of the person for a long time before assuming it’s actually theirs. Otherwise people would get ultra-short loans from friends and family or even other moms and pretend it was their own.
- wumpus 5y agoThe one time I got a mortgage, I was saving an unusually high % of my salary. After the mortgage company got a look at my bank account, they were nervous that I was possibly getting extra money from somewhere, and demanded a larger downpayment. Fortunately, I was able to hit that number by continuing to save at the same rate. As they say: don't be unusual.
- jdavis703 5y agoThe banks are going to require you provide an explanation and documentation for where all funds came from for the past several months. Besides they’re going to be looking at your annual income anyways — one time cash drops are only useful for making a larger deposit. But they’re not dumb enough to use a one-time infusion to calculate your debt to income ratio.
- errcorrectcode 5y agoOnly banks and corporations are allowed to monetize float. Better off to start a bank.
- kapilvt 5y agoSort of depends… on if its a person or business on the other end ;-) https://arstechnica.com/tech-policy/2021/02/citibank-just-got-a-500-million-lesson-in-the-importance-of-ui-design/ https://arstechnica.com/tech-policy/2021/02/citibank-just-go...
- jonas21 5y agoWell... in that case, the sender actually owed the recipient the money. It just wasn't due at the moment. From the article: > Citibank sued, arguing that it was entitled to get the money back since the cash was sent out by mistake. Ordinarily, the law would be on Citibank's side here. Under New York law, someone who sends out an erroneous wire transfer—for example, sending a payment to the wrong account—is entitled to get the money back. > But the law makes an exception when a debtor accidentally wires money to a creditor. In that case, if the creditor doesn't have prior knowledge the payment was a mistake, it's free to treat it as a repayment of the loan. Judge Furman ruled that that principle applies here, even though Citibank notified its creditors of the mistake the very next day. The defendants noted that the amounts they received matched the amounts Revlon owed down to the penny, making it reasonable for them to assume it was an early repayment of the loan.
- ummonk 5y agoUnless it's an error that is plausibly paying down a loan, in which case the error might actually work in your favor, depending on how Citigroup's appeal against the hedge funds goes.
- dustintrex 5y agoBack in the 1990s, I was living in another country and noticed that sometimes, when I used my home credit card, the purchases would simply never appear on my bill. The "free" purchases were always small (no free airline tickets or cameras) and the only pattern I could figure out was that a bookshop I frequented was always free. But I felt bad about (potentially) stiffing them, so I started buying my books with cash instead.
- shitloadofbooks 5y agoThe bookshop probably had their payment gateway set to their merchant's card test gateway.
- dustintrex 5y agoIt wasn't the only place where this happened though, just the only one where it clearly happened every time. This was in the days of printed statements, so there was often a lag of several months until I would find out what was and was not actually charged.
- th3iedkid 5y agoAll of the payment system processes are structured around banks rather than individuals . What if a similar transaction error was committed by an individual or a business managed by an individual, the amount of hardship and pain they have to go through , before all those transactions could ever be reversed.
- duxup 5y agoI don’t know about if I made the transaction but I had a check stolen recently, someone edited the name and deposited it for themself. I went to the bank, filled out a page, signed and got my money back instantly.
- zaidf 5y agoIn my early 20s, I deposited a 5 figure check from a client for a contract gig. The bank cleared it. Then it turned out the client had a record of writing fraudulent checks. Common sense would dictate I was a victim of fraud. But my bank (Wells Fargo) decided to close my lone bank account of 5 years for "suspicious activity."
- winternett 5y agoWells Fargo has treated my very well as a client for the past 11 years... After I sued them... lol.
- zrobotics 5y agoThey treat their clients so well that, out of fear of you not being able to access online banking, their passwords aren't case sensitive. Why yes, that does mean that they are storing passwords in plaintext, but it's just so they can make their clients lives easier.
- davidgh 5y agoNot necessarily. They could be performing a “lower case” function on all passwords before hashing them.
- 14 5y agoEbenezer Scrooge strikes on Christmas. This is unfortunate I have had something similar happen where I thought the funds were there and spent more money then I had. What happened was Microsoft lost the payment info or something on a laptop I purchased and did not take it from my account for 3 months. I did so much Christmas shopping at the time I honestly didn't realize they had not taken it out so I made another big purchase and then all of a sudden they took out $1500 catching me by surprise. Had I realized they did not take it right away I would have not continued to spend as I did. I know I am responsible for keeping track but the way it showed up and disappeared on my banking app honestly confused me initially. I feel sorry for these people who may have thought they had a bit more so made an extra purchase or two and now have this money taken back and stuck with their purchases.
- errcorrectcode 5y agoSo it's like Superman III...
- astronautjones 5y agowhy should i change? he's the one who sucks.
- srcmap 5y agoWould be nice if Santander bank can be a real Santa this time and write off the 'mistake'.
- userbinator 5y agoSanta-nder bank. Christmas day. Almost reads like an Onion article title.
- wave_function 5y agoI’m moderately disappointed that CNBC didn’t take advantage of such an obvious pun
- epwr 5y agoWhat is going on with the denial of responsibility? Do you really get to say "oops, don't sue me" in advance?
- lbriner 5y agoFairly standard in the UK. Businesses don't want to lose face and see the share price drop so they keep everything as private as possible and only release the bear minimum information. Look out for standard phrases like, "A small number of our customers", "We are working hard to...", "Learn lessons....", "No-one will be out of pocket". Of course, these are mostly weasel words and they don't account for the fact that the amount of hassle these mistakes can cause cannot be captured in a pithy soundbite. The truth is, though, that the massive amount of regulation is both good and bad. It is good that the consumer is protected but it is bad that it is easier for a bank to stay with 50 year old technology that is already approved than risk releasing something brand-new since mistakes are penalised so badly. I think a more open regime would be better, obviously accepting that the bank has to ultimately make sure that their customers don't lose out. For example, "Dear customer, we are moving all mortgages to a new system which will make it much cheaper to run. Just in case some of the calculated payments are out by a few pennies, we will be giving all customers £1000 towards their mortgage to account for these". Much cheaper in the long run but we seem to prefer the costs of flogging a dead horse with the small amount of "sweetener" we could pay instead.
- KarlKemp 5y agoI don’t remember a single instance of 50-year old banking technology costing customers money, so I don’t see what the supposed downside is. You refer to a “brand-new system” that is “much cheaper to run”. But as far as I can tell, the operational costs of a mortgage are little more than an (exquisitely analyzed) rounding error. There are some new bank(ish) startups here in Europe like N24 and there are some new rules for data portability. But I’ve yet to see any exciting ideas coming from such efforts.
- topkai22 5y agoI had something similar happen to me- my compensation included a big incentive bonus based on an annual target, but half was paid out in advance in like June to smooth out the income a bit. One year somebody in payroll royally screwed up and at the half year mark instead of 1/2 of the bonus everyone ended up with the full bonus. The insane/awesome thing was how they clawed it back. The did require everyone pay back money, but only the money that was left after any payroll deductions. Between taxes, insurance, flexible spending accounts, retirement savings, and some other automatic deductions close to 50% of my pay check is deducted, so I walked off with what was effectively a 2.5% bonus. I was pretty happy to send back what they asked for at that point…
- jffry 5y agoDid they still pay the second installment of your bonus like normal or was it reduce to adjust for the "extra" you kept in round one?
- topkai22 5y agoFull second payment, that’s why I was happy with it. Personally, I would have thought they’d have just not clawed back the money and then only paid/clawed back money at the of the year to adjust to exceeding/undershooting the target (the company is cash rich).
- jmnicolas 5y ago
- melenaboija 5y agoNothing of what you said makes any sense to me. There may be some liquidity strategies but not moving millions between accounts by error. And letting fail a bank like Santander, in the top 5 in Europe and probably top 20 in the world, would bring enormous systemic problems.
- retube 5y agoHa ha lol what? In the grand scheme of things its a tiny amount of money for a bank with a €1tr balance sheet, the overhead of recovering the cash, not to mention the poor publicity, will be enormously costly, but most of all, how exactly is paying out £100m from the banks own funds supposed to benefit the bank?? (btw this actually will increase the banks leverage, which according you i imagine they'd want to be reducing, plus will negatively impact the banks CET1 capital, so all in all not beneficial in anyway whatsoever)
- barrkel 5y agoDeposit accounts are liabilities for banks. This move would negatively affect Santander's position.
- mndgs 5y agoEuropean banks should have been let fail... Facts on the table, please. People should check the statistics first before making such statements. An average US bank is probably 12-13% capitalized (own equity Vs total assets. An average European bank is probably 8-10%. It seems less at the first sight, but if you take negative rates into account in Europe Vs positive ones in US, that's not such big difference at all. In general,banks are well capitalized both in US and Europe. Of course, not all apples are good (we're got 3000 or so banks in Europe), some are surely close to going belly up if not the government support (Italian banks, I'm looking at you). But that's a far cry from all European banks should have been let to fail..
- danielmg 5y agoErr no. The payments get settled at BoE at the end of the cycle. This would have caused double draw on their settling account. They would have had less money.
- mirekrusin 5y agoDid they introduce microservices and learned distributed transactional consistency is hard - the hard way?
- makach 5y agoThis is not a coding error but partly a configuration error mixed up with poor general routines complemented by bad practice. Also the banking infrastructure doesn’t help. Instead of fixing these issues this incident will most likely change regulations in a way that it will be easier for banks to reclaim funds lost in similar ways in the future. What consequences I can only speculate- but it might very well have severe negative effects.
- avianlyric 5y ago> Instead of fixing these issues this incident will most likely change regulations in a way that it will be easier for banks to reclaim funds lost in similar ways in the future. The U.K. FCA tends to be extremely consumer friendly and somewhat bank hostile. There will be no regulation change as a result of this, more likely fines and greater oversight from the FCA. They’ll no doubt be demanding incident post-mortems already, and the general expectation is that Santander will have to cover any lost funds that can’t be recovered by asking nicely. The FCA takes an extremely dim view of banks aggressively pursuing individuals for money after the bank fucked up.
- tialaramex 5y agoConsumers (ie actual people) will be made whole by law. And most likely affected businesses won't end up out of pocket either, but the law doesn't protect them as much, on the rationale that they're not people. So banks do screw them over all the time too, just probably not this time. But the Fundamentally Complicit Authority (no that isn't what their initials really stand for, it's a Private Eye recurring joke because of how useless they are) as regulator is unlikely to expect Santander to actually fix anything about their process, and so this will happen again. And again.
- mike_hock 5y ago> no that isn't what their initials really ... Yes, we understand regulatory capture. Thanks for making your joke cringeworthy by explaining it at length.
- 5y ago
- lbriner 5y agoThe title should read as "scheduling error", there is no mention that I can see of a coding error.
- usr1106 5y agoNot following. The recipients received the payments twice. But did the affected business accounts also get debited twice? I'd assume some would have run out of funds or hit a credit line. I know nothing about how real life banking software works. (I guess I'm glad not to know...) But I'd assume the blance of both affefted accounts are updated in an ACID transaction?
- etothepii 5y agoI know that it is not ACID on debit and credit as I was once transferring £70k between my co-founder and I at £10k per day. For some reason the 5th transaction got credited to my account but not debited from his. We tried to return the money but both banks were adamant that no error had occurred.
- usr1106 5y agoTrue. As soon as more than 1 bank is involved you proably cannot make it always consistent from the point of view of 2 accounts in different banks.
- thenickdude 5y agoInteresting, I wonder if a transaction was accidentally "de-duplicated" on one side. I would experiment further, lol
- deleted 5y ago[deleted]
- jmclnx 5y agoKids, this is why I did my best to avoid working on Payroll Systems at all costs. So far so good :) >"It ruined my holiday period because I thought I'd paid out hundreds of thousands in error — I thought I had done something wrong," But, if you can manage the stress, I would think that position would be very secure.
- oogabooga13 5y agoAlmost a decade ago I deposited a 10k check at the bank and was told the usual (in my case) that it would take x days to clear. After x days and not even seeing a trace of it in online banking I went to the branch. They were unable to find the deposit or transaction in their system, yikes! Fortunately I had the little receipt they gave me at the time of the transaction and within half an hour 10k deposit was made available but interestingly the deposit did not come from the check writer but the bank itself. Always curious to me. Never got a clear explanation but I would have been SOL without that transaction receipt!
- wsostt 5y agoBanks have provisional accounts which they use to make customers whole. They don’t know where your check went either but they’ll make you whole while they figure it out. Your check will be credited to their provisional account if they find it! I worked for a large bank and they ran into an “issue” which required making a whole lot of clients whole out of provisional accounts while they figured out what happened. I can tell the balance of those accounts became a metric which many people were evaluated by.
- causality0 5y agoYou're not entitled to keep the money, but I always wonder what would happen to the interest if you dumped millions of dollars into your savings account. Do they take that away too?
- game_the0ry 5y agoI worked for a "systemically important financial institution" (known as SIFIs in the industry). I also worked on critical functionality, like payment processing, wire transfers, etc. Seeing how that sausage was made was eye-opening. One time, there were reddit threads circulating where customers were complaining about logging into their bank accounts then seeing the information of another user. I brought up during stand up, and my team lead freaked out, took me around the corner in the hall way, and screamed at me for 10 mins straight about how I am compromising the security practices of the company (OK, guy). Weirdly, there was not mainstream media attention or any discussion internally. My guess is the policy is to suppress aggressively when flaws become public, especially with security. Given the nature of the financial services business, you would think they would have the highest paid and most competent tech workers, but fuck no. For the most part, we would hook up FOSS components to talk to our legacy back end monoliths (usually mainframe dinosaur machines that should have been extinct a long time ago) and then render the desired output to a web or mobile interface. So the good news is that your security is as good as the open source engineer's implementation (which most of the time would be Java / Spring / Oracle / Pivotal, or C#/ .net / MS) bc that is the tooling we would build on. More good news is that, due to risk aversion, things do not change often at banks bc of fear of mistakes (downside being that there is les innovation). In all honesty, I would rather trust amazon, google, or even netflix with my finances over big banks. Except facebook, never trust facebook.
- astura 5y agoThe HN title says it was a "coding error" but the article title is "Bank accidentally deposits $176 million into people’s accounts on Christmas Day" and the article does not say it was a software error: "The bank said the duplicate payments were caused by a “scheduling issue” that has now been rectified." It could have been a software bug but it could also have been a human error.
- pvaldes 5y agoI must admit that the brief appearing of a Gringotts gnome with the face of the bank CEO in Harry Potter was a priceless moment.