« LendingTree Emphasizes Monthly Payment Amount Instead of Rate | Main | Best Internet Banks from Global Finance Magazine »

Citibank Leaves Card Applicants Vulnerable to Identity Theft

By Jim Bruene on August 7, 2006 2:39 PM

We were impressed with Citibank’s full-page ad in Sunday’s New York Times travel section offering 25,000 miles to take a new American Airlines co-branded credit card. As usual, we looked for a link to the Web-based application and were pleased to find a large, reverse-type URL along the bottom of the ad. Unfortunately, Citi did not follow the usual convention for printed landing-page URLs, creating potential problems for applicants.

Typically, offline advertisements use a special filename after the normal domain name, such as <www.yourbank.com/special>. This allows users to go directly to the landing page explaining the special offer (see landing page below).

Citi_aadvantage_25landingpage_1

Instead, Citibank used the unique server name "miles5" as in: <www.miles5.citicards.com>. There are several problems with this approach. First, it’s long and not easily recalled. But the biggest problem is its non-standard format. Internet users do not expect to see an extra period in the middle of a bank's URL. So many users, myself included, may read this as a unique domain name, <miles5citicards.com>.

Normally, that would be okay. But in this case Citibank neglected to register that domain name. An identity thief could easily have registered that domain, and then taken “applications” for days or weeks before anyone caught on, possibly leaving hundreds of applicants vulnerable to identity theft after entering their personal info, including social security number, in the application.

By mid-day on Monday, almost two days after the ad first appeared in print, the domain was still unregistered. We went ahead and registered it to prove the point, and keep it safe.

Implications
The moral of this story: If you live in a glass house, make sure any transparencies are covered. Register your domain name. Citibank, which has spent millions on its anti-identity theft campaign, left itself and its customers vulnerable for the price of an $8.95 domain name. Make sure you register the domain name of any cute URLs you put out there for marketing campaigns. While you are at it, spend $60 and lock it up for 10 years. 

Memo to Citibank’s legal team: We have no commerical interest in the domain and will happily transfer it to your ownership. All we ask is reimbursement of our 9 bucks.

--JB

Comments (0)
AddThis Social Bookmark Button

Most Recent Posts:

TrackBack

TrackBack URL for this entry:
http://www.netbanker.com/cgi-bin/mt/mt-t.cgi/389

Post a comment

(If you haven't left a comment here before, please note that we will read your comment before it is approved to go up on the blog. However, we'd prefer that you and our other readers didn't have to wait. If you'd like your comments to appear instantly in the future, you can create a TypeKey account and we'll set you up as a trusted commenter!)


Please enter the security code you see here

Sponsors

Finovate 2008 - Come see the future of finance & banking!


Sponsored Links

Events

Research

  • NEW! Online Investing Communities: Will social networking revolutionize saving & investing?- Find out more
  • NEW! Searching for Customers 3.0: Search engine marketing for financial institutions- Find out more
  • Person-to-Person Lending 2.0: Disruptive service or market niche? - Find out more
  • Mobile Money and Payments: Why credit & debit card issuers should embrace mobile delivery now - Find out more

Products & Services

  • Compare CD (certificate of deposit) interest rates and read customer reviews at Bankaholic