by Serguey Shinder
Until 2023, opening a credit account with us needed a copy of a director's passport or driving licence and three months of bank statements. The application form said to email them to the credit team. For six years, people did exactly that.
In March 2023 one of our sales managers entered his password into a convincing fake login page and somebody else had his mailbox for about four hours. The first question in the investigation was what they could have seen, and the answer included two hundred and twelve identity documents. He did not work in credit. Customers sent their applications to the person they knew, their account manager, who forwarded them on, and every forward is another copy that nobody ever deletes.
So we counted properly. The credit inbox. Fourteen personal mailboxes in sales. The ticketing system, where credit logged each application with its attachments. A folder on the shared drive where the documents were saved again in case they were needed. The backups of all of those. Roughly three thousand eight hundred identity documents and bank statements for about thirteen hundred customers, the oldest from 2014, many of those customers long gone.
The question that changed the project was what we actually needed them for. A credit controller had to look at the document once, check that the name and date of birth matched the application and the company register, and move on. That was the whole use. Asked when anybody had last gone back to an old one, the credit team could not name a single occasion. Our policy said verify the director's identity. The process that grew up around it kept the evidence of every verification, forever, in as many places as email would carry it.
Applications now arrive through an upload page into one store, visible to the credit team and nobody else. The controller records who checked the document, on what date, what type it was and the last four characters of its number, and the file is deleted automatically after thirty days. Account managers have a standing auto reply for anything with an attachment that looks like an application, asking the customer to use the page instead. The historic copies took four months to find and remove, with our solicitor confirming that nothing obliged us to keep them.
What I keep coming back to is where the risk had been decided. It was not the password, or the missing second factor, although both were fixed that week. It was one word on a form written in 2017, email, which settled where the documents would live, how many copies there would be, and that none of them would ever expire, years before anybody thought of it as a security question at all. We had needed a fact about each customer, and we had kept the document instead.
– Serguey Asael Shinder
Leave a Reply