Insights for consumers
Consumers should take steps to ensure they understand and put in place all account security options offered by a financial services platform to prevent unauthorised access to their account and potential financial losses.
What happened?
Ella used an online investment platform to buy and sell shares. One day, a hacker gained access to her account, sold her shareholdings, and used the proceeds to buy cryptocurrency on the platform. The platform sent transaction alerts, which prompted Ella to immediately log in, sell the cryptocurrency, convert the funds back into New Zealand dollars, and transfer the remaining money from her account.
Ella was lucky not to lose all the money she had invested on the platform. However, she did incur trading fees, currency conversion costs, and losses associated with exchange rate movements. She also lost her investment positions, and markets dropped. Ella estimated her losses were about USD $2,500 and wanted the platform to pay her compensation for those losses.
Ella said the investment platform’s security controls were inadequate and contributed to her losses. She argued that unusual activity on her account should have triggered stronger security measures and that the platform should have made additional security measures like two-factor authentication (2FA), passkeys, or other safeguards mandatory because they would have prevented the unauthorised access to her account.
The platform said there was no evidence their systems, infrastructure, or security controls had been compromised. The unauthorised transactions were carried out using Ella’s login credentials, including her IP address. Ella’s personal information had already been compromised, and that information was used to gain access to her investment account.
The investment platform also noted that they offered customers enhanced security features, including 2FA and passkeys, but these were optional, and had not been activated on Ella’s account before the incident.
What was FSCL’s view?
Financial service providers must take reasonable steps to protect customer information and accounts from unauthorised access. However, the relevant contractual and regulatory requirements were principles-based. They did not require specific controls such as mandatory 2FA, device verification, or transaction approval processes.
Additional security measures can reduce the risk of unauthorised access to accounts and would likely have prevented access to Ella’s platform account in this case, if those additional security measures had been in place.
However, different providers can legitimately adopt different security models and risk settings, and there was no obligation for the platform to make 2FA and passkeys mandatory. The fact that some organisations use stronger controls does not necessarily mean another provider’s approach is unlawful or contrary to good industry practice.
Importantly, the platform in this case did make enhanced security measures available to customers, including 2FA and passkeys, although these were not mandatory. They also had transaction alerts in place, which enabled Ella to quickly identify the unauthorised activity and take steps to limit further loss
Because the platform had not breached a legal obligation, and there was no evidence that the loss resulted from a deficiency in their security systems, FSCL found it would not be fair to require the platform to compensate Ella for her trading losses, currency conversion costs, foreign exchange losses, or stress and inconvenience.
In summary
Although Ella suffered losses after a hacker accessed her investment account on a share trading platform, there was no evidence that the platform’s systems had been compromised or that they had failed to take reasonable security measures. The platform was not legally required to make 2FA or similar protections mandatory, so we did not uphold the complaint.






