Making it clear when we're on a call with you to protect you from fraud
Monzo’s new feature that lets customers verify in-app whether an inbound call is genuinely from the bank is prompting broader debate about how to protect people from phone-based fraud. Commenters like the idea in principle but argue it only works if users know and remember to check the app, and say banks should avoid calling customers at all, rely on secure in-app chat or app-based calling, and standardize the rule: never act on a request from someone who contacted you first. The thread widens into criticism of banks’ conflicting security practices, the difficulty of supporting less tech‑savvy or elderly customers, and calls for stronger regulation and clearer norms around mutual authentication and fraud liability.
Perceived Benefits and Limits of Monzo’s Call-Verification Feature
- Many see the in‑app “we’re on a call with you” indicator as a useful extra factor against phone scams.
- Others worry it mainly shifts liability to customers, especially in jurisdictions where banks already try to offload fraud risk.
- It only helps if customers know it exists and check it every time; people rarely receive bank calls, so habits may never form.
- It fails if mobile data doesn’t work during calls (no VoLTE, no Wi‑Fi) or if the user doesn’t have or open the app.
Usability and UX Concerns
- Several commenters find the UX awkward: answering a call while simultaneously authenticating in the app is error‑prone.
- Some suggest a persistent, obvious in‑app banner during calls; others say “absence of a banner” is too subtle to be useful.
- Concern that burying the indicator in a menu makes it effectively invisible to most users.
Comparison to Other Approaches
- Other banks already use in‑app confirmation prompts before reps can see account details, or push “is this us?” notifications.
- Wise’s user-chosen keyword scheme is cited, but abused in practice when people select offensive phrases.
- Some propose: in‑app secure voice calling; never calling customers at all; or push notifications instructing users to call back using an official number.
Broader Critique of Bank Security Practices
- Many banks undermine their own anti‑phishing messaging by:
- Using unfamiliar domains and URL shorteners.
- Asking for security details on inbound calls.
- Requesting one‑time codes despite telling customers “never share these.”
- Commenters describe banks locking cards or accounts when customers refuse to share sensitive data on inbound calls, effectively punishing safe behavior.
Fraud Experiences and Practical Advice
- Multiple detailed examples of sophisticated phone scams: spoofed caller IDs, deep transaction knowledge, follow‑up calls pretending to be police or fraud hotlines.
- Strong consensus guidance:
- Treat all inbound calls as untrusted; hang up and call back via a number from the card/official website.
- Prefer credit cards to debit cards for consumer protection.
- Avoid clicking links in SMS or email; distrust remote‑access requests.
Alternative Security Ideas
- Suggestions include mutual phone authentication protocols, audio-channel “beacons,” FIDO2/Yubikey-based banking, and stricter transfer limits/cooling-off periods—often noted as more secure but harder to deploy or use.