The Good, The Bad, And The Ugly – Customer Experience At A Premium Credit Card Provider

February 2025

To say it up front, I haven't experienced much good. But let me start at the beginning and share my perception of the way the premium credit card provider (in short: the provider) implemented the mandatory validations of customer identities in Germany.

The initial situation: I have a credit card with partner cards from this provider. All of these cards have their own logins and e-mail addresses.

Fraud?

I received e-mails adressing the partner cardholders and asking me to validate the details of the partner cards. Each e-mail contained a link to a website, a so-called transaction number, and the last five digits of the partner credit card number (access data for short). I was asked to use the link and enter the access data.

The e-mail only offered publicly available data, but nothing to allow me to authenticate it. We all know how easy it is to use a false e-mail address, and everything in me screamed fraud. Instead of following the link, I tried to find a way to validate customer data behind the provider's firewall, but was unable to do so.    

No help in sight!                         

I contacted the provider's call center. The employee was friendly, but only told me that    

  • I had to validate the data because of the European Anti-Money Laundering Act - I was aware of this.
  • I could validate the data behind the firewall (which is either not true or virtually impossible to find - see above).

When I explained that I couldn't find this option, she promised to check and call me back - guess what never happened?

Phishing?

While I was still waiting, I received another request to validate the data soon. There were probably two perceptions of urgency: while it was fine for the provider's call center not to reply at all, I received a reminder. Driven by my curiosity, however, I found a way to continue without the risk of jeopardizing my PC: I set up a Raspberry PI on a separate subnet of my network (please don’t call me paranoid) and followed the link. I saw a completely blank web form that was supposed to capture all the data the provider should already have. Since this looked like a phishing approach, I became very interested in the situation.

The provider's German language web form for data capture

Contact via secure message

I used the provider's website and sent a secure message to explain the situation and in particular my concerns. To be honest, I wasn't overly optimistic, but I thought it was worth a try.    

Internal server error                                   

A few days later, I noticed that I had received a reply and checked my inbox on the provider's website. However, I was unable to access the inbox. Instead, I received an error message. Probably an evil spirit was preventing me from receiving a reply.    

Running out of options                                   

Despite this great experience, I wanted to keep the provider's credit cards. We all like them - but no cards without ID validation. 

Thus, I wrote a letter to the German CEO of the provider describing the situation, explaining the technical issues I was facing (including screenshots), and asking her team for help. I had to wait about two weeks. In the meantime, I received the third reminder.    

A response – wonderful – but exactly what I did not need                                   

The head of customer service for Germany and Austria and a member of the Office of the CEO replied with a letter on beautiful stationery. I received explanations of money laundering law (nothing new), a reminder to submit the information quickly (which I would have liked to do), an explanation of how to use the credentials - whatever. They also offered me to use Post-Ident - a German identification and authentication service normally used for customer onboarding (kind of time consuming).     

But no one explained to me where I could find the validation option behind the firewall. Given the state of the provider's German website, nasty people might assume that the provider didn't find it either, but I personally would never say that.

In the meantime, the reply to my earlier secure message became accessible, but it did not contain substantially new information. But - the letter mentioned an e-mail address for further questions.       

Further questions

Guess what? I sent an e-mail with four questions. Of course, the responses arrived again as a letter on beautiful stationery, and here is a summary:    

  1. Secure portal? The provider considered its portal approach to be secure because of the provided access data (see above), and the lack of displayed customer data. However, they provider didn’t seem at all concerned about both its e-mail being perceived as phishing and using non-encrypted communication. But maybe I am simply too mistrustful when it comes to using internet services.
  2. Behind the firewall? The provider again explained there was a way to confirm the data behind the firewall and offered the related menu items – which didn’t map to my reality. Even when checking my credit card accounts and using further services, I perceived the provider’s website as somewhat confusing. But maybe I am not made for this kind of powerful website experience.
  3. Re-entering available customer data? The provider explained that this was for security reasons and referred to the answer to question 1. In the first letter, I was also informed that GDPRS does not allow stored customer data to be displayed. Why did they even send me an e-mail for partner card holders? Good thing I asked!
  4. Identification of the partner cardholder via the primary cardholder? The provider confirmed to me that this was a mistake: I was supposed to forward the e-mail to the partner cardholders, but I didn't see a related request anywhere. Why didn't the provider use the e-mail addresses stored for the partner cardholders? I don’t know. Did I get any compensation for doing the provider's work? I think even a few bonus points would be too high an expectation.

Did these answers help? Not too much, but it increased the likelihood that this (in my opinion amateurish) combination of e-mail and website was the provider's approach to validating customer data. Threatening to block the credit cards, the provider eventually forced us to resubmit unchanged data inspite of a perception of insecurity. Needless to say, the confirmations of the data transfers arrived in my inbox.

The Bad and The Ugly   

In my humble opinion, there are some odd approaches here (I'm not sure which one to call “bad” or “ugly”), including:

  • The whole validation approach was customer unfriendly and perfectly designed to raise concerns.
  • The provider intended to use the primary cardholder as a go-between without communicating this.
  • This was made worse by the inability of the provider to really help, instead causing delays in the process.

But the worst part was something else: when I asked why the form was not pre-filled, the provider replied that data protection law does not allow this. Given that various financial service providers do pre-fill these fields, I find it hard to believe that this is the real obstacle: perhaps it was the cost, perhaps the need for a speedy implementation, perhaps the inability of legacy systems to provide the data when and as required.

Dear provider, those customers who write letters to the CEO typically want to remain customers - and you should try to understand their issues and concerns. The others simply cancel their contract.

Best Practice?                                         

Germany's Commerzbank, the bank I use as a retail customer, handled its customer validation in a way that is in line with best practice - or at least very, very close to it. I received a printed letter offering two options:

  • Confirmation by mail (data printed on a sheet of paper, no postage, sign the sheet, and you're done).
  • Using (i) a barcode or (ii) following clear instructions to get to the validation option behind the firewall (all fields pre-filled, click on confirm, and you’re done).

I didn't have to spend much time, felt the process was trustworthy, and was happy with it.

The provider could have taken a similarly customer-friendly approach. Why it didn't do this will probably remain its secret. Suffice it to say that my bank account is free, while the provider receives a substantial monthly fee. Does it matter whether this is bad or ugly? At least in the classic western movie, only the good survives the day.       

Source: reddit.com