« LendingTree Emphasizes Monthly Payment Amount Instead of Rate | Main | Best Internet Banks from Global Finance Magazine »

Citibank Leaves Card Applicants Vulnerable to Identity Theft

By Jim Bruene on August 7, 2006 2:39 PM | Comments (0)

We were impressed with Citibank’s full-page ad in Sunday’s New York Times travel section offering 25,000 miles to take a new American Airlines co-branded credit card. As usual, we looked for a link to the Web-based application and were pleased to find a large, reverse-type URL along the bottom of the ad. Unfortunately, Citi did not follow the usual convention for printed landing-page URLs, creating potential problems for applicants.

Typically, offline advertisements use a special filename after the normal domain name, such as <www.yourbank.com/special>. This allows users to go directly to the landing page explaining the special offer (see landing page below).

Citi_aadvantage_25landingpage_1

Instead, Citibank used the unique server name "miles5" as in: <www.miles5.citicards.com>. There are several problems with this approach. First, it’s long and not easily recalled. But the biggest problem is its non-standard format. Internet users do not expect to see an extra period in the middle of a bank's URL. So many users, myself included, may read this as a unique domain name, <miles5citicards.com>.

Normally, that would be okay. But in this case Citibank neglected to register that domain name. An identity thief could easily have registered that domain, and then taken “applications” for days or weeks before anyone caught on, possibly leaving hundreds of applicants vulnerable to identity theft after entering their personal info, including social security number, in the application.

By mid-day on Monday, almost two days after the ad first appeared in print, the domain was still unregistered. We went ahead and registered it to prove the point, and keep it safe.

Implications
The moral of this story: If you live in a glass house, make sure any transparencies are covered. Register your domain name. Citibank, which has spent millions on its anti-identity theft campaign, left itself and its customers vulnerable for the price of an $8.95 domain name. Make sure you register the domain name of any cute URLs you put out there for marketing campaigns. While you are at it, spend $60 and lock it up for 10 years. 

Memo to Citibank’s legal team: We have no commerical interest in the domain and will happily transfer it to your ownership. All we ask is reimbursement of our 9 bucks.

--JB

Comments (0)

Most Recent Posts:

TrackBack

TrackBack URL for this entry:
http://www.netbanker.com/cgi-bin/mt/mt-t.cgi/389

Leave a comment

Sponsors

BackBase IntelliResponse Yodlee FinovateEurope 2012

Events

  • FinovateEurope 2012 -- On February 7th, 2012, the second annual FinovateEurope will feature dozens of Europe's newest fintech innovations via a fast-paced demo-only format in the financial capital of London. 7 minutes each on stage. No slides allowed. Come watch the future of fintech in Europe unfold live! Get your ticket today and lock in your spot before it is too late!
  • FinovateSpring 2012 -- On May 8th & 9th, 2012, Finovate will return to San Francisco for our 5th annual west coast showcase of the newest fintech innovations from Silicon Valley and beyond. Each company gets 7 minutes to demo live. No slides allowed. Come watch the future of fintech debut! Get your ticket today and save big!

Research

  • NEW! Online & Mobile Banking Forecast: Current, future and historical usage: 1994 to 2021 - Find out more
  • NEW! Selling Insurance Online (Banking Edition): Can insurance help fill the fee-income gap? - Find out more
  • NEW! True Virtual Banking Has Arrived: BankSimple, Personal Capital, Betterment and others go branchless, paperless and “bank-less” - Find out more
  • 2012 Guide to Online & Mobile Banking Products, Pricing & Strategy: Preparing for a mobile-first world - Find out more
  • Family Banking: Tweens, Teens & their Parents: In a remote banking world, your most-promising prospects aren’t even driving yet! - Find out more

 

   

RSS Subscribe via RSS
RSS Subscribe to Comments



Email:


@NetBanker Twitter Feed



See all @NetBanker tweets