Section

Security

Cybersecurity, privacy, and the fight to stay safe online.

38 stories

Bank branch interior with a gift card rack beside a service counter under flat fluorescent light, marble floor scuffs, customers blurred in queue, no logos or readable text

NatWest Refunds Faster on Romance Gift-Card APP Claims After City of London Probe

NatWest shortened reimbursement clocks on authorised push payment claims tied to romance fraud and bulk gift-card loads after City of London Police shared terminal metadata from a Square Mile probe, telling victims who bought high-street vouchers for fake partners that cases with matching MCC codes now skip a second manual review.

Daniel Okeke

Indoor covered market aisle with card terminal on a wooden counter, shopper holding a phone near the reader, fluorescent strip lighting, worn floor tiles, shallow depth, no logos or readable text

Starling Bank Patches Push Payment Token Reuse After Liverpool Merchant Probe

Starling Bank shipped an emergency app build invalidating reused push-payment tokens after Liverpool trading-standards officers flagged a merchant terminal that replayed wallet authorisations across split-ticket card sales.

Daniel Okeke

Bristol city centre office block facade in grey rain, commuter reading a phone on wet pavement, blurred handset screen, sodium street lamps reflecting on tarmac, no logos or readable text

FCA Warns Clone Firm Impersonating Hargreaves Lansdown After Weekend SMS Blasts

The FCA reissued a clone-firm alert after weekend SMS blasts mimicked Hargreaves Lansdown’s Bristol switchboard, steering savers toward spoof portals that replay genuine company numbers while stripping FSCS cover from any transfer.

Daniel Okeke

Commuter holding a smartphone with a blurred banking screen on a London tube platform, tiled walls and overhead strip lights, shallow depth, scuffed floor, no logos or readable text

Revolut Adds Device Binding After APP Fraud Taskforce Briefing

Revolut will bind high-risk transfers to registered handsets after briefing the Payment Systems Regulator’s APP fraud taskforce, tightening in-app OTP flows that ombudsman cases show scammers still defeat through coached screen sharing.

Daniel Okeke

Municipal IT server rack aisle with blinking switch lights, technician on a laptop cart under cool fluorescent panels, grey carpet tiles, cable trays overhead, screens without readable text, no logos

NCSC Issues OAuth Redirect Warning After UK Council SSO Breach

The NCSC warned councils to lock OAuth redirect URIs after a Midlands authority lost staff SSO sessions to a forged callback domain, pushing suppliers to audit open redirectors on planning portals tied to Microsoft Entra logins.

Daniel Okeke

Security from around the world