How AJ Bell keeps your information secure
As technology advancements continue, many people have become increasingly concerned about their accounts being breached and their data being shared with unintended sources. We take this extremely seriously at AJ Bell and do everything in our power to keep this from happening. Here, we’ll explain the steps we take to protect you, and how you can help ensure your data is safe.
Readers may have recently seen the headline that some of Revolut’s customer data was stolen last month. While not all the details around this are clear, it presents a very good case study of how many of these breaches tend to occur: for the most part, they are the result of human error rather than the core systems themselves being breached. In Revolut’s case, the data was disclosed after a fraudulent email was sent from a legitimate Italian government agency. No money was taken from accounts, but some of the customer’s details were given over to the hackers.
Head of Security Operations at AJ Bell, Zalak Karia, said the Revolut breach was classified as a ‘third party compromise’, because it came from a legitimate government address. While this is not as obvious as some scam situations, it’s still possible for companies like AJ Bell to protect against.
One measure is technology systems that are put in place to monitor the number of requests and activity from the third party making the ask. If this is out of the ordinary, the system will flag it, and AJ Bell can do additional checks. In addition, if the person processing the request can see that it is unusual, for example an unprecedented amount of information, it can be escalated within the business before any information is shared.
AJ Bell’s customer protection
We have a team that is purely dedicated to keeping your information safe. In addition to using security systems and identifying suspicious activity when it arises, we have a network that keeps an eye out for any new ways that customers might be targeted and put blockers in place ahead of time to protect you.
AJ Bell uses several layers of security to help prevent unauthorised access. Customers sign in using a username and password, and the first login from a new device or browser also requires a one-time code sent by text, email or an authenticator app. Customers can switch on two-factor authentication for every login, adding another check even if somebody obtains their password.
In addition to adding protection on our own website, we can now use technology to scan for scams using the AJ Bell brand on social media or other platforms and have them taken down.
Of course, we aren’t able to protect against every attempt, which means customers need to be vigilant as well.
Could AI hack into your banking?
One thing we are not seeing much at the moment is AI hacking into systems directly. Instead, AI is used as a tool in phishing attempts. For example, a hacker may use AI to look more legitimate by getting help designing the website or responding quickly to chats.
Laura Lehane, Head of Financial Crime at AJ Bell, said “AI is helping fraudsters make scams look and sound more convincing, from improving the spelling and grammar in phishing emails to creating professional websites, realistic messages and even cloned voices. Fraudsters may deliberately target people who are vulnerable or isolated, so customer education is a vital first line of defence. Sharing warning signs with friends and family can help protect others too.”
The year after ChatGPT launched the number of phishing attacks increased by 138% as hackers made use of this new technology, according to cybersecurity company Proofpoint.
While fraudsters are using AI, AJ Bell is also increasingly using AI to help identify possible scams and put more protections in place.
How you can help keep your account safe
The easiest way for hackers to get into an account is through human error. These are overwhelmingly still phishing attempts where users are tricked into giving away their information by a scammer pretending to be the company or another party that would need your information. There are a few different ways that you can create extra security for your AJ Bell account.
1. Turn on two-factor authentication
Two-factor authentication is a method where you need to approve a login to your account rather than just having a username and password. This creates an extra step if someone were to gain access to that information. You can learn how to set this up for your AJ Bell account.
If you are contacted unexpectedly with two-factor authentication, do not approve it. In some cases, you may even get a message from someone posing as a friend or family member asking for approval. If you think it could be legitimate, take the time to call them, not just message, to ensure you are speaking to who you think you are. Don’t rush to do any approvals without ensuring that you know what is being approved.
2. Use a unique password
There are a lot of passwords to keep track of in this day and age, and most of us have been guilty of using the same one for many accounts. If you aren’t going to use a different password for everything, banking and investment accounts are some of the best ones to keep separate. Do not reuse the same password for email, banking, investing and shopping accounts. A password manager can create and store separate passwords for you. Where available, passkeys can offer a more secure alternative because they cannot be shared with a fraudster in the same way as a password.
3. Have a consistent login method
Previously, we have seen fraudsters try to target our customers by using the promoted slot which will come up as the first link in a Google search. Instead of going to our actual website, it would go to a fake version and prompt users to log in. The best way to prevent this is to ensure you have the AJ Bell site favourited on your web browser. That way, you can click on the link you are sure is right each time. Or you can use the AJ Bell app. If you plan to use the AJ Bell app, make sure you are downloading it from the official app store associated with your phone, for example the Apple app store or the Google Play store. Other sites claiming to be app stores may have downloads available that aren’t the legitimate AJ Bell app.
4. Don’t use your account on public Wi-Fi
It is very easy for scammers to create something that looks like a public Wi-Fi system. If you accidentally use this, it’s possible that the scammers could have a full view of what you are doing on your computer or phone, including logging into accounts and viewing your personal information. For using your AJ Bell account, it’s better to wait until you are home with a private system, and where no one could possibly see over your shoulder.
