Sunday, October 4, 2026

Why are Financial Institutions, Discount Brokers and the Government not Doing More to Protect Us?


On all bank and discount broker’s websites are “Security Guarantees” claiming that your money is protected. But if you read carefully, what they actually say is that they will return your money if their systems are hacked but you are on your own if your online access is hacked. More and more sophisticated hacks are being reported on a regular basis in both bank and trading accounts. The scams have migrated from merely draining bank accounts to infiltrating self-directed trading accounts and triggering large losses. There have been two reports of such scams perpetrated against TD Direct Investing customers within the past year alone!  In the case of each hack, invariably the institution where the account is held denies any responsibility. It is clear that these “security guarantees” are not only misleading but blatant false advertising. 

When there is so clearly a problem with the poor consumer being at risk, why are these institutions not urgently taking more steps to protect their customers and why is the Federal government not stepping in to legislate more safeguards to be mandated?

It used to be that apps were designed to increase a user’s convenience in completing a task by allowing them to bypass security steps. In today’s reality, those shortcuts are now dangerous and should no longer be an option. I would gladly take a few extra seconds to validate my identity rather than making it easier for some hacker steal my money more quickly. I am sure most people would agree with that sentiment.

Here are some suggestions that may help:

1.     Make 2-Factor Authentication mandatory for all online banking and trading accounts. Don’t leave it to the consumer to set this up and then blame them for not doing so. Less critical apps including Booking.com, Open Table, Amazon, etc. automatically instituted 2-Factor authentication without requiring their customers to add this to their accounts. Why are financial institutions not required to do the same?

2. Require 2-Factor authentication to take place on every login, not just occasionally

3. Require 2-Factor authentication every time a financial transaction is made including withdrawals or trades, or if an attempt is made to change personal detail, link bank accounts, etc.

4. Add passkeys to all financial applications since this has been touted as the most secure way to protect an account. Currently for major banking and trading apps, only WealthSimple supports passkeys This article explains why passkeys are safer than 2-Factor authentication - https://www.passkeys.com/passkey-vs-2fa

5. Flag and hold any suspicious trades or bank withdrawals that don’t follow a historic usage pattern until the validity of the action can be verified by the account owner

6. For Discount Brokers

a. Add a setting that allows a user to specify the need for a trading password to be entered for EVERY trade, not just the first trade of each login session. Rather than providing this, our discount broker keeps offering options to remove the trading password.  This seems so out of touch to today’s reality.

b. Allow the user to restrict which stock exchanges he wants to be able to trade against and require 2-Factor authentication to change this setting. We only want to trade on the TSX and have no desire to trade on NYSE, Nasdaq, or other off-shore exchanges where stories of pump and dump schemes using foreign penny stocks are more common (as illustrated in the two TD hacks mentioned at the start of this article). 

It is clear why banks and discount brokers are not jumping to add more security since it costs money to make these changes. Thus, our government needs to step in to mandate more protection. I lobby for additional security changes any time I am asked to fill out a survey or am given the opportunity to suggest feature improvements.

If you have more suggestions, please post in the comments. I will add these to the next survey that I fill out. 

It would also be great if we could hear from financial institutions or our government to clarify what plans are being taken to better protect us (not holding my breath). I wrote to the Minister of Finance after our bank accounts were hacked, asking why more security measures were not being legislated. I received what amounted to a form letter assuring me that the government takes their responsibilities seriously and are looking into ways to better protect us.  Several years later, I have not read of any planned changes while the threats to us continue to escalate.

No comments:

Post a Comment