# How a hacker can drain your account and bank: step by step

**URL:** <https://community.trading212.com/t/how-a-hacker-can-drain-your-account-and-bank-step-by-step/22569>\
**Category:** 💬 Trading 212 chat\
**Created:** [October 9, 2020, 8:29pm UTC](https://community.trading212.com/t/how-a-hacker-can-drain-your-account-and-bank-step-by-step/22569 "2020-10-09T20:29:31Z")\
**Posts on this page:** 20\
**Page:** 3

<div class="post-metadata">

**Author:** ![obrienciaran](https://dub1.discourse-cdn.com/flex013/user_avatar/community.trading212.com/obrienciaran/32/2705_2.png) [@obrienciaran](https://community.trading212.com/u/obrienciaran)\
**Post date:** [October 10, 2020, 7:41am UTC](https://community.trading212.com/t/how-a-hacker-can-drain-your-account-and-bank-step-by-step/22569/41 "2020-10-10T07:41:18Z")

</div>

Good idea until the “hacker” in said scenario is using your phone. The authentication code will be delivered to the device (s)he is using.

Added email authentication sent to the address you used when signing up would solve the issue or having new cards added or old cards removed.

Granted it’s not as secure as requiring email authentication on every withdrawal, but in my scenario, the worst that can happen is the hacker withdraws money back into your own bank account. Perhaps at a loss, yes, but my personal risk tolerance wouldn’t mind that. I’d feel it a bit of a nuisance having to check my email every time I withdraw.

---

<div class="post-metadata">

**Author:** ![Izk](https://dub1.discourse-cdn.com/flex013/user_avatar/community.trading212.com/izk/32/3844_2.png) [@Izk](https://community.trading212.com/u/Izk)\
**Post date:** [October 10, 2020, 8:42am UTC](https://community.trading212.com/t/how-a-hacker-can-drain-your-account-and-bank-step-by-step/22569/42 "2020-10-10T08:42:12Z")

</div>

@Vedran i’ve noticed your _anti-security_ discussions/comments in other threads including this one and they leave me shocked/perplexed…

Most of our clients(enterprises) use 2FA at all levels and depending on their roles and access 2FA is mandatory/required, some even with multiple conditional access requirements. Based on my experience i would say it reduced exposure by at least 90%, easily.

Moving on, I’m not sure about this case scenario OG mentioned but 2FA “ **IS** ” long due and @Team212 knows this. It reduces exposure by a lot and builds confidence in the crowds. Not only in the scenario where your password is compromised but the actual servers are (even if you say they are 99.99% secure because of XYZ).

Long story short, we need the option of opting in/out instead of no option.

---

<div class="post-metadata">

**Author:** ![JD1](https://avatars.discourse-cdn.com/v4/letter/j/46a35a/32.png) [@JD1](https://community.trading212.com/u/JD1)\
**Post date:** [October 10, 2020, 9:04am UTC](https://community.trading212.com/t/how-a-hacker-can-drain-your-account-and-bank-step-by-step/22569/43 "2020-10-10T09:04:14Z")

</div>

For Cryptocurrency

I use an email generated code, and 2FA, when I simply log in!

There should be a wealth of options available, to everyones tolerance.

---

<div class="post-metadata">

**Author:** ![obrienciaran](https://dub1.discourse-cdn.com/flex013/user_avatar/community.trading212.com/obrienciaran/32/2705_2.png) [@obrienciaran](https://community.trading212.com/u/obrienciaran)\
**Post date:** [October 10, 2020, 9:28am UTC](https://community.trading212.com/t/how-a-hacker-can-drain-your-account-and-bank-step-by-step/22569/44 "2020-10-10T09:28:33Z")

</div>

Crypto is another beast though. It’s too complicated.

- I log in with 2fa to my platform of choice (Bitstamp) to buy Bitcoin.
- If I want Alt coins, I then log into Binance with a captcha and 2fa and move my Bitcoin from BitStamp to Binance, again with 2fa from Bitstamp’s side to confirm the send.
- Then to store crypto in my wallet I have to enter a 6 digit code on my ledger and log into my ledger app, and send the crypto from Binance to that, with yet again 2fa from Binance to confirm the send.

Then more or less the reverse if I want to send the money back to fiat currency.

Overkill if you ask me. And crypto advocates wonder why it hasn’t taken off!

---

<div class="post-metadata">

**Author:** ![Darko](https://dub1.discourse-cdn.com/flex013/user_avatar/community.trading212.com/darko/32/1667_2.png) [@Darko](https://community.trading212.com/u/Darko)\
**Post date:** [October 10, 2020, 11:03am UTC](https://community.trading212.com/t/how-a-hacker-can-drain-your-account-and-bank-step-by-step/22569/45 "2020-10-10T11:03:20Z")

</div>

I suppose that you got notification (e-mail) when account is funded, so only thing that could happen is that you get free money from the “hacker”. 😀

It’s even a good thing, for example my mother wants to put some money in her granddaughter pie, but she lives on small island without bank branch so she has to go to local post and withdraw money and send it to me so I told her keep money in her bank account. I planned to help her open her account at t212, maybe it’s better long term solution.

---

<div class="post-metadata">

**Author:** ![Vedran](https://dub1.discourse-cdn.com/flex013/user_avatar/community.trading212.com/vedran/32/182_2.png) [@Vedran](https://community.trading212.com/u/Vedran)\
**Post date:** [October 10, 2020, 11:33am UTC](https://community.trading212.com/t/how-a-hacker-can-drain-your-account-and-bank-step-by-step/22569/46 "2020-10-10T11:33:41Z")

</div>

> [@Izk](#):
>
> i’ve noticed your _anti-security_ discussions/comments in other threads including this one and they leave me shocked/perplexed

Indeed, I have contrary opinion. That is shocking. We should all think alike. 🚎

> [@Izk](#):
>
> Most of our clients(enterprises) use 2FA at all levels and depending on their roles and access 2FA is mandatory/required, some even with multiple conditional access requirements. Based on my experience i would say it reduced exposure by at least 90%, easily.

Instead of selling products, folks should get proper education and common sense. 2fa used by uneducated person has same strengths if not less then educated person with passphrase.

It is basically similar to door locks, you can buy the best one, if someone wants to rob your home badly and he is skilled he will probably break in. No matter what you have as home security.

But anyway this topic is getting chewed over and over.

When t212 release 2fa, you use it, I won’t. Will feel safe nonetheless.

🥳

---

<div class="post-metadata">

**Author:** ![Grim-Up-North](https://dub1.discourse-cdn.com/flex013/user_avatar/community.trading212.com/grim-up-north/32/7631_2.png) [@Grim-Up-North](https://community.trading212.com/u/Grim-Up-North)\
**Post date:** [October 10, 2020, 3:10pm UTC](https://community.trading212.com/t/how-a-hacker-can-drain-your-account-and-bank-step-by-step/22569/47 "2020-10-10T15:10:47Z")

</div>

I must admit, the more and more funds I lump into T212, the more concerned I get that no 2FA is available. I use Face ID to log into the app, which I know is fairly secure but obviously if my login details are comprised via a hacker attack of some kind, having that 2FA either via Google Authentication App or via text / email is just another layer of security. I would prefer a combination. So Face ID / password plus google auth code plus the option of either email / text OTPC on top… just to add several levels of extra security.  
This should be on log in and on any withdrawals when already in the app or website.

Would be nice for T2T to issue a response on this once they have had the time to look into it.

---

<div class="post-metadata">

**Author:** ![Darko](https://dub1.discourse-cdn.com/flex013/user_avatar/community.trading212.com/darko/32/1667_2.png) [@Darko](https://community.trading212.com/u/Darko)\
**Post date:** [October 10, 2020, 3:11pm UTC](https://community.trading212.com/t/how-a-hacker-can-drain-your-account-and-bank-step-by-step/22569/48 "2020-10-10T15:11:02Z")

</div>

I tried to fund $1 with other card (different person), didn’t work, funding failed.

---

<div class="post-metadata">

**Author:** ![Col1948](https://dub1.discourse-cdn.com/flex013/user_avatar/community.trading212.com/col1948/32/7433_2.png) [@Col1948](https://community.trading212.com/u/Col1948)\
**Post date:** [October 10, 2020, 3:31pm UTC](https://community.trading212.com/t/how-a-hacker-can-drain-your-account-and-bank-step-by-step/22569/49 "2020-10-10T15:31:57Z")

</div>

Johnny did you do it the way the OP on a different PC and replicating a stolen password then saved the credit card to deposit etc?

Col.

---

<div class="post-metadata">

**Author:** ![kali](https://avatars.discourse-cdn.com/v4/letter/k/a88e57/32.png) [@kali](https://community.trading212.com/u/kali)\
**Post date:** [October 10, 2020, 3:44pm UTC](https://community.trading212.com/t/how-a-hacker-can-drain-your-account-and-bank-step-by-step/22569/50 "2020-10-10T15:44:25Z")

</div>

> [@Izk](#):
>
> Based on my experience i would say it reduced exposure by at least 90%, easily

Yet another proof that 83% of statistics are made on the spot (\<- including this one)  
So from the 1000 clients you have, before 2FA 300 were getting hacked after 2FA only 30 are getting hacked.

Nothing improves security more than education of your users, that is why ISMS (iso 27001) does not mandate anything like 2FA instead it enforces education about security most notably for social engineering and phishing.

I got nothing against 2FA, its great and I use it when available **but** for an attackers point of view it is another layer of obscurity and yeah security through obscurity works up until a point.

It is shown in quite a few studies, some of the industry wide “security features” does not improve but actually hurt security. (not talking about 2FA) For example forcing users to change passwords periodically, or coming up with a pseudo secure limitation like “no dates, at least one number, 1 special character, lower and upper case characters”

How many of those users than go for “ **Passw0rd\_1** ” next month “ **Passw0rd\_2** ” Having a password like “ **icannotdancewithunderwear** ” beats the above 2 strategies

but… I digress… what were we talking about on this soggy saturday?

---

<div class="post-metadata">

**Author:** ![Veevas](https://dub1.discourse-cdn.com/flex013/user_avatar/community.trading212.com/veevas/32/6514_2.png) [@Veevas](https://community.trading212.com/u/Veevas)\
**Post date:** [October 10, 2020, 3:58pm UTC](https://community.trading212.com/t/how-a-hacker-can-drain-your-account-and-bank-step-by-step/22569/51 "2020-10-10T15:58:41Z")

</div>

Very worrying if this happens to be true. Whilst funding from other card should be fine, any withdrawals should generate a OTP to Phone/email to confirm withdrawal in addition to account password. This may add another layer of security IMHO!

---

<div class="post-metadata">

**Author:** ![nickspacemonkey](https://avatars.discourse-cdn.com/v4/letter/n/eb8c5e/32.png) [@nickspacemonkey](https://community.trading212.com/u/nickspacemonkey)\
**Post date:** [October 10, 2020, 4:00pm UTC](https://community.trading212.com/t/how-a-hacker-can-drain-your-account-and-bank-step-by-step/22569/52 "2020-10-10T16:00:46Z")

</div>

It’s not true, don’t worry.

Edit: This has actually been discussed to death:

> [@Why no Two-Factor Authentication?](https://community.trading212.com/t/why-no-two-factor-authentication/1169):
>
> Hi, 2FA or MFA have become a security standard nowadays. Even simple websites use it, not to mention online brokers. I believe this is a big minus for Trading 212 in regards to the competition, it sends an untrustworthy message. And the solution should be quite simple. Is there a plan to introduce this feature? On both mobile app and website of course. It’s somewhat funny that even this community forum has 2FA option, but not the actual platform… where security breaches’ impacts are astronomic…

> [@\[URGENT\] Add 2 Factor Authentication on main site/app](https://community.trading212.com/t/urgent-add-2-factor-authentication-on-main-site-app/20910):
>
> Hi, I don’t see a way to enable 2FA on your main site ( [https://live.trading212.com](https://live.trading212.com) ). A bit absurd, the community package you’re using here (Discourse) supports it. Given the amount of assets and value handled by your main site, it is in your best interest to protect both your users and yourself by implementing a way to enable 2FA as soon as possible. Ideally, users should be able to enable 2FA by scanning a barcode through a mobile app (much like it happens here in the community forums) and…

---

<div class="post-metadata">

**Author:** ![EquityInvestor](https://avatars.discourse-cdn.com/v4/letter/e/8491ac/32.png) [@EquityInvestor](https://community.trading212.com/u/EquityInvestor)\
**Post date:** [October 11, 2020, 10:09am UTC](https://community.trading212.com/t/how-a-hacker-can-drain-your-account-and-bank-step-by-step/22569/53 "2020-10-11T10:09:51Z")

</div>

It would be interesting to get a response from @team212 on this on Monday, even if it was just done with 10 GBP (it might not work for larger amounts as pointed out above). A message from them clarifying this for everyone’s peace of mind. 🙂

---

<div class="post-metadata">

**Author:** ![sedateme](https://dub1.discourse-cdn.com/flex013/user_avatar/community.trading212.com/sedateme/32/4420_2.png) [@sedateme](https://community.trading212.com/u/sedateme)\
**Post date:** [October 11, 2020, 10:20am UTC](https://community.trading212.com/t/how-a-hacker-can-drain-your-account-and-bank-step-by-step/22569/54 "2020-10-11T10:20:10Z")

</div>

A couple of weeks ago I withdrew £16k from my account.

I’d recently added a new card, but had only used that card to add a relatively small amount. The system wouldn’t let me withdraw to the newer card on that occasion. However it has subsequently.

There clearly are some fairly good systems in place but soon the better on Multi factor authentication 🙂

---

<div class="post-metadata">

**Author:** ![Venetia1993](https://dub1.discourse-cdn.com/flex013/user_avatar/community.trading212.com/venetia1993/32/13564_2.png) [@Venetia1993](https://community.trading212.com/u/Venetia1993)\
**Post date:** [October 11, 2020, 10:45am UTC](https://community.trading212.com/t/how-a-hacker-can-drain-your-account-and-bank-step-by-step/22569/55 "2020-10-11T10:45:14Z")

</div>

Maybe having you authicate the payment with a PIN Number after you selected the amount would be better?

It is really easy to put funds in your account and an accidental 0 could make all the difference.

---

<div class="post-metadata">

**Author:** ![laguiar](https://dub1.discourse-cdn.com/flex013/user_avatar/community.trading212.com/laguiar/32/275_2.png) [@laguiar](https://community.trading212.com/u/laguiar)\
**Post date:** [October 11, 2020, 1:11pm UTC](https://community.trading212.com/t/how-a-hacker-can-drain-your-account-and-bank-step-by-step/22569/56 "2020-10-11T13:11:34Z")

</div>

> [@kali](#):
>
> Nothing improves security more than education of your users

Sorry, although I agree, but it’s a big fallacy.

Users never were proper educated and won’t be ever, so relying on this is a big mistake.

If even a well educated Twitter employee were hacked, so image the average dude used to Facebook and Instagram only.

---

<div class="post-metadata">

**Author:** ![Tefal](https://avatars.discourse-cdn.com/v4/letter/t/2bfe46/32.png) [@Tefal](https://community.trading212.com/u/Tefal)\
**Post date:** [October 12, 2020, 6:29pm UTC](https://community.trading212.com/t/how-a-hacker-can-drain-your-account-and-bank-step-by-step/22569/57 "2020-10-12T18:29:34Z")

</div>

“Nothing improves security more than education of your users,”

Oh God no, if you’ve ever worked in anything that required health and safety you’d have come across the least effective solutions are education and behaviour modification. Literally anything that doesnt rely on the user/operator, is safer.

---

<div class="post-metadata">

**Author:** ![Seyboe88](https://avatars.discourse-cdn.com/v4/letter/s/b3f665/32.png) [@Seyboe88](https://community.trading212.com/u/Seyboe88)\
**Post date:** [October 12, 2020, 8:22pm UTC](https://community.trading212.com/t/how-a-hacker-can-drain-your-account-and-bank-step-by-step/22569/58 "2020-10-12T20:22:43Z")

</div>

Robin Hood has been hacked now too

---

<div class="post-metadata">

**Author:** ![laguiar](https://dub1.discourse-cdn.com/flex013/user_avatar/community.trading212.com/laguiar/32/275_2.png) [@laguiar](https://community.trading212.com/u/laguiar)\
**Post date:** [October 13, 2020, 12:10am UTC](https://community.trading212.com/t/how-a-hacker-can-drain-your-account-and-bank-step-by-step/22569/59 "2020-10-13T00:10:04Z")

</div>

They don’t!  
Users are having their accounts “hacked”, probably their emails are compromised (pretty easy to happen if you use gmail and chrome) and they do not have 2FA enabled.  
As far as I managed to read, Robinhood servers were not affected, it’s really focused on users.

---

<div class="post-metadata">

**Author:** ![Tony.V](https://dub1.discourse-cdn.com/flex013/user_avatar/community.trading212.com/tony.v/32/21437_2.png) [@Tony.V](https://community.trading212.com/u/Tony.V)\
**Post date:** [October 13, 2020, 7:19am UTC](https://community.trading212.com/t/how-a-hacker-can-drain-your-account-and-bank-step-by-step/22569/60 "2020-10-13T07:19:17Z")

</div>

Hello,

So in regards to the question about the account funds, I believe that I covered most of the part in the following:

> [@Why no Two-Factor Authentication?](https://community.trading212.com/t/why-no-two-factor-authentication/1169/63):
>
> That’s literally impossible. If you deposit $10,000 via card 1234, and later on you deposit $1 using card 6789 (presumably the fake one), then we will not refund $10,000 towards card 6789. Its a standard [AML precaution](https://helpcentre.trading212.com/hc/en-us/articles/360007081537-What-are-the-available-withdrawal-methods-). Neither someone can remove that easily the card 1234 from our system - we’ll need a document [issued by your bank](https://helpcentre.trading212.com/hc/en-us/articles/360007139958-How-do-I-update-my-payment-methods-), which confirms that the card has expired/stolen/etc. Moreover, an email confirmation is sent upon withdrawal. So you’ll be notified additionally. And if someone d…

Along with that:

> [@Support for multi factor authentication](https://community.trading212.com/t/support-for-multi-factor-authentication/22823/2):
>
> 2FA is coming tomorrow.

[Previous page](https://community.trading212.com/t/how-a-hacker-can-drain-your-account-and-bank-step-by-step/22569.md?page=2)

[Next page](https://community.trading212.com/t/how-a-hacker-can-drain-your-account-and-bank-step-by-step/22569.md?page=4)
