cancel
Showing results for 
Search instead for 
Did you mean: 

Citi's new security check

tag
Noctilum
Frequent Contributor

Citi's new security check

So I logged into my Citi credit card account to day and was greeted with a security check point.  Since I work in cyber security it is a sensitive subject for me. 

 

The check point had zero branding on it.  It asked me for the following:

 

- Full name

- Date of birth

- FULL social security number

- FULL credit card details including my CV code

- Secret question

- Secret answer

 

Now, due to my profession, the first thing I am thinking is a session hijack or cross site scripting because no one in their right mind asks for all that information.  May bits and pieces, such as the last 4 of your social or the answer (but not the question) to your secret question. 

 

So I call up Citi and explain what I am seeing.  My English speaking rep then transfers me to 1-800-abu-dhabi who says to just enter the info.  I don't know, maybe I am just paranoid or hard headed, but this doesn't seem to be the appropriate way to do a fraud check when everyone has been trained for 10-15 years that businesses will NEVER ask you for this type of information (unless you are applying for something).  I'm almost ready to cancel the account over it.

 

Message 1 of 9
8 REPLIES 8
llecs
Moderator Emeritus

Re: Citi's new security check

Something doesn't look right. I always login via citicards.com. I've also done citibank.com when I had a checking with them. But I've never seen that.

Message 2 of 9
ccnewcc
Established Contributor

Re: Citi's new security check

Well, if this isn't a joke by the OP, then this is a fraud scam.  Look at the bad grammar and the misspellings.  Those always equal scam.

Message 3 of 9
Noctilum
Frequent Contributor

Re: Citi's new security check

I assure you it is not a joke.

 

I called the number on the back of my card.  I then went through with their online support guy.  He had me close the browser, re-open it and type www.citicards.com and it took me to the usual login page.  Then it started a loading screen which prompted the check point.  He said they upgraded their website to allow for better usability and said it was a one time fraud check and to enter the information.

 

Meanwhile, I can still get in on my Citi app without having to be checked.  Any computer I go to asks me for it though.

Message 4 of 9
p-
Valued Contributor

Re: Citi's new security check


@ccnewcc wrote:

Well, if this isn't a joke by the OP, then this is a fraud scam.  Look at the bad grammar and the misspellings.  Those always equal scam.


Just because it looks like the right URL, don't trust it.  OP, you might have a virus that is causing this.  And never trust CS reps.  They are often not very knolwedgeable.

 

Message 5 of 9
Noctilum
Frequent Contributor

Re: Citi's new security check

I do have to say, that the last field in the credit card box did have the last 4 of my credit card number in there.  I just whited that out so no one would see it. 

 

I am doing scans of all my equipment, but it's coming up on my work computer as well which we have locked down more than most nuclear facilities. 

Message 6 of 9
enharu
Super Contributor

Re: Citi's new security check

The usual citi checks I experienced asked for my debit card number, last 4 digits of social, and checking account number.

And that happened only when I lost my debit card and reported it as lost.

Nothing intrusive or crazy like what you are experiencing. Drop by a citi branch in person and get this resolved. I would never put in all these info
JPMorgan Palladium (100k), AmEx Platinum (NPSL), AmEx SPG (46k), AmEx BCP (42k), Chase Sapphire Preferred (47k), Citi Prestige (31k), Citi Thank You Preferred (27k), Citi Executive AAdvantage (25k), JPMorgan Ritz-Carlton (21k), Merrill+ (15k), US Bank Cash+ (22.5k), Wells Fargo (12k), Bloomingdale’s (12.4k), Chase Freedom (5k), Discover IT (5k).
Message 7 of 9
Noctilum
Frequent Contributor

Re: Citi's new security check

So it looks like all is well now.  No viruses found, but when I logged in with my business card I did not receive the same message.  When I logged in with my personal account afterwards it stopped asking me for it. 

Message 8 of 9
thom02099
Valued Contributor

Re: Citi's new security check

I've logged in to my CITI account several times over the past few days, and just checked again this morning.  No "enhanced" security check for me. 

Message 9 of 9
Advertiser Disclosure: The offers that appear on this site are from third party advertisers from whom FICO receives compensation.