No credit card required
Browse credit cards from a variety of issuers to see if there's a better card for you.
Today I discovered a major security flaw with USAA. I logged in to my account to "view documents" and lo and behold I had access to my documents and other USAA memebers' documents.
What??!!
Yep, USAA admitted faulty IT implementations that allowed all USAA members to view everyone else’s documents.
The concern is not only privacy but ID theft. I have Tax documents that show my full blown SSN. And other USAA members had access to that!! Are you F'ing kidding me?!
I called USAA immediately and they have since taken down the View Documents portion of the website.
I told them I was very very unhappy and very concerned. On Monday I will be requesting free Subscription to their CMS as restitution.
Watch your Credit Report Closely if you are a USAA Member.
[UPDATE]
From USAA:
"Please note there was a technical issue last weekend during a system upgrade in which some personal member information could possibly have been visible to another USAA member on USAA.com. We identified the error within one hour of its occurrence, and immediately retracted the information to limit exposure.
From the information we have gathered, there is no indication of any fraudulent activity related to this occurrence. Furthermore, we are taking precautions to prevent this from happening again. We did want to make you aware of the situation. In response to this incident, we are taking the appropriate steps to notify and protect the identification of the people whose information was made available.
The protection and security of our member’s personal information is our top priority"
Lovely....
@Dustink wrote:Lovely....
Yeah that’s what I would have said had I not been livid about the situation.
It amazes me that USAA would even allow this to happen. IT departments are suppose to run things in test environments before live rollouts.
I sense IT firings to come.
@Anonymous wrote:
@Dustink wrote:Lovely....
Yeah that’s what I would have said had I not been livid about the situation.
It amazes me that USAA would even allow this to happen. IT departments are suppose to run things in test environments before live rollouts.
I sense IT firings to come.
It's likely that the majority of their IT departmnet is outsourced with only the uppper levels of IT management being in-house. This makes for very minor if any level of accountability in most IT departments. The outsourcer simply states it as a bug for remediation and no it held accountable. If USAA wants to hold its outsourcer accountable, it simply ends the contract and gets another company. It could try to sue the outsourcer but that still won't change the level of accountability that their next outsourcing company is held to.
There is an intrinsic value to in housed IT departments that never sees the bottom line of a financial report.
It shouldnt be a great deal but of course we deserve to be notified of this.
I dont know they have treated me good so far.Its not the banks fault rather IT's
I remember I checked for documents early this morning and didn't see anything amiss - however you're correct, as of right now, their documents section at USAA has been taken down.
I would hope that the quality of your average USAA member would preclude most of us from doing anything wrong with any information that was accessible that wasn't supposed to be accessible.
But for sure everybody should keep a close eye on their credit reports. If you've printed documents already, take a look at your documents and see what information is printed on those. That will give you a good idea of what information somebody else might have seen about you and your accounts.
There's no doubt that USAA is going to take care of this and figure out what happened, who saw what, and take measures to compensate members in some way. I have no doubt in my mind as well that if you ask for credit monitoring or something, USAA probably will accomodate you and pick up the tab for it!
But good looking out for the rest of us and THANKS for posting this information! Otherwise, I might not have known about this as soon as I did (thanks to you)!
Fast side note:
If you log into your USAA accounts anybody see this message from them at the top of your accounts page?
Due to system maintenance some account information and access to documents may be unavailable.
They're calling it "system maintenance" and not a security breach/error.
That's interesting....
Wow.....
I'd be livid. I was not impressed at all with them last year just getting an account started. Thats insane.
Thanks for the heads up!