
Anonymous submission. This is worse than I could ever imagine. Original text follows:
---
Your bank re-works their website. Here's what you have to do to log in:
- Use existing username + password: prompt “activate your account!”
- Enter name, birthdate, email, and... member number?
- Dig around files. Member number is not printed on card, not on checks.
- Login page has a button: “find member number” Fine, I'll use that.
- Button is JS that takes you to a new domain. No longer the bank's website!
- Url looks like <30 random chars>.my.site.com. Had to double-check—this looks malicious. It was not.
- Checkbox: “are you an individual”? Yes??? Continue.
- Enter: name, birthdate, email, FULL SSN (wtf?! remember, we are now on a third-party site)
- Do you get your member number now? Of course not!
- You get to meet ANA instead, and must ASK A CHATBOT to parrot your member number. (screenshots)
- Acquire member number, can finally log in.
I hope my SSN didn't make it into the chatbot's context.










