Friday, April 25, 2025

October 15, 2019

Oops – Discovery Bank Finds Major Security Flaw

Discovery acted swiftly after discovering a potentially massive flaw in its credit card transaction system.

While everyone was panicking about the fact that Discovery wasn’t letting them earn Vitality points using TomTom watches, the company was hard at work putting the final touches on their new bank.

The Discovery Bank operates from their new headquarters in Johannesburg, a towering R23 million-a-month rental in Sandton.

As is common with all new ventures, there are still a couple of wrinkles in the system that Discovery is ironing out.

One ‘wrinkle’ in particular had the potential to really mess things up for the new bank.

Business Insider received a tip that it was possible to make credit card payments online without the correct CVV (Card Verification Value) number.

Yesterday morning, they did a little digging:

On Monday morning Business Insider South Africa was able to make two credit card payments on two different e-commerce platforms with the incorrect CVV number, simply using a sequences such as “000”.

Business Insider

In one instance, Discovery Bank also didn’t require further authorisation in the form of a one-time pin.

From next year, Discovery Vitality will start rewarding members who look after their mental health, so take this opportunity to practice your meditation and calm down, because the problem has been solved.

By Monday evening, Business Insider tried to recreate the transaction we completed in the morning, but our efforts were rejected.

A call centre agent also soon phoned us after the transaction to alert us that an incorrect CVV number had been used.

Hey, at least they solved the problem quickly.

[source:businessinsider]