Skip to Content
logologo
AI Incident Database
Open TwitterOpen RSS FeedOpen FacebookOpen LinkedInOpen GitHub
Open Menu
Discover
Submit
  • Welcome to the AIID
  • Discover Incidents
  • Spatial View
  • Table View
  • List view
  • Entities
  • Taxonomies
  • Submit Incident Reports
  • Submission Leaderboard
  • Blog
  • AI News Digest
  • Risk Checklists
  • Random Incident
  • Sign Up
Collapse
Discover
Submit
  • Welcome to the AIID
  • Discover Incidents
  • Spatial View
  • Table View
  • List view
  • Entities
  • Taxonomies
  • Submit Incident Reports
  • Submission Leaderboard
  • Blog
  • AI News Digest
  • Risk Checklists
  • Random Incident
  • Sign Up
Collapse

Incident 428: BBC Reporter's Twin Brother Cracked HSBC's Voice ID Authentication

Description: HSBC’s voice recognition authentication system was fooled after seven repeated attempts by a BBC reporter's twin brother who mimicked his voice to access his bank account.

Tools

New ReportNew ReportNew ResponseNew ResponseDiscoverDiscoverView HistoryView History

Entities

View all entities
Alleged: Nuance Communications developed an AI system deployed by HSBC UK, which harmed HSBC UK customers and Dan Simmons.

Incident Stats

Incident ID
428
Report Count
3
Incident Date
2017-05-19
Editors
Khoa Lam
Applied Taxonomies
MIT

MIT Taxonomy Classifications

Machine-Classified
Taxonomy Details

Risk Subdomain

A further 23 subdomains create an accessible and understandable classification of hazards and harms associated with AI
 

2.2. AI system security vulnerabilities and attacks

Risk Domain

The Domain Taxonomy of AI Risks classifies risks into seven AI risk domains: (1) Discrimination & toxicity, (2) Privacy & security, (3) Misinformation, (4) Malicious actors & misuse, (5) Human-computer interaction, (6) Socioeconomic & environmental harms, and (7) AI system safety, failures & limitations.
 
  1. Privacy & Security

Entity

Which, if any, entity is presented as the main cause of the risk
 

Human

Timing

The stage in the AI lifecycle at which the risk is presented as occurring
 

Post-deployment

Intent

Whether the risk is presented as occurring as an expected or unexpected outcome from pursuing a goal
 

Intentional

Incident Reports

Reports Timeline

+2
BBC fools HSBC voice recognition security system
Twin brother’s voice cracks bank security
BBC fools HSBC voice recognition security system

BBC fools HSBC voice recognition security system

bbc.com

HSBC voice recognition system breached by customer's twin

HSBC voice recognition system breached by customer's twin

theguardian.com

Twin brother’s voice cracks bank security

Twin brother’s voice cracks bank security

thetimes.co.uk

BBC fools HSBC voice recognition security system
bbc.com · 2017

Security software designed to prevent bank fraud has been fooled by a BBC reporter and his twin.

BBC Click reporter Dan Simmons set up an HSBC account and signed up to the bank's voice ID authentication service.

HSBC says the system is secu…

HSBC voice recognition system breached by customer's twin
theguardian.com · 2017

HSBC’s voice recognition ID system used by half a million customers for secure access to their bank accounts has been breached by a customer’s twin mimicking his voice.

When it was launched last year HSBC’s head of retail banking claimed th…

Twin brother’s voice cracks bank security
thetimes.co.uk · 2017

HSBC's voice recognition security system has been tricked by an account holder's twin brother mimicking his speech.

The system is used by half a million customers and when it was introduced last year the bank's head of retail banking said t…

Variants

A "variant" is an incident that shares the same causative factors, produces similar harms, and involves the same intelligent systems as a known AI incident. Rather than index variants as entirely separate incidents, we list variations of incidents under the first similar incident submitted to the database. Unlike other submission types to the incident database, variants are not required to have reporting in evidence external to the Incident Database. Learn more from the research paper.

Similar Incidents

By textual similarity

Did our AI mess up? Flag the unrelated incidents

Facial Recognition Trial Performed Poorly at Notting Hill Carnival

Facial Recognition Trial Performed Poorly at Notting Hill Carnival

Aug 2017 · 4 reports
Passport checker Detects Asian man's Eyes as Closed

Passport checker Detects Asian man's Eyes as Closed

Dec 2016 · 22 reports
Hackers Break Apple Face ID

Hackers Break Apple Face ID

Sep 2017 · 24 reports
Previous IncidentNext Incident

Similar Incidents

By textual similarity

Did our AI mess up? Flag the unrelated incidents

Facial Recognition Trial Performed Poorly at Notting Hill Carnival

Facial Recognition Trial Performed Poorly at Notting Hill Carnival

Aug 2017 · 4 reports
Passport checker Detects Asian man's Eyes as Closed

Passport checker Detects Asian man's Eyes as Closed

Dec 2016 · 22 reports
Hackers Break Apple Face ID

Hackers Break Apple Face ID

Sep 2017 · 24 reports

Research

  • Defining an “AI Incident”
  • Defining an “AI Incident Response”
  • Database Roadmap
  • Related Work
  • Download Complete Database

Project and Community

  • About
  • Contact and Follow
  • Apps and Summaries
  • Editor’s Guide

Incidents

  • All Incidents in List Form
  • Flagged Incidents
  • Submission Queue
  • Classifications View
  • Taxonomies

2023 - AI Incident Database

  • Terms of use
  • Privacy Policy
  • Open twitterOpen githubOpen rssOpen facebookOpen linkedin
  • 30ebe76