BBVA Spain uses weak 6-character login and DNI

BBVA maintains online banking access via NIF and a short password, amid rising fraud cases involving thousands of euros.

English · Original discussion in Spanish · Published

BBVA Spain uses weak 6-character login and DNI
BBVA continues to use DNI and a 6-character key for access

Access to BBVA accounts is protected by two pieces of data: the holder's NIF (tax ID) and a six-character alphanumeric password. That is all. The security of BBVA's online banking relies on this combination, unchanged for a decade, and daily users describe it bluntly as inadequate for an institution of its size. The core issue isn't operating funds, but logging in.

What security does BBVA require for account access?

Logging into BBVA's online channel requires the user's NIF and a six-character alphanumeric password. While not unique among Spanish banks, it is particularly striking given the entity's volume. Other banks trinc identical or worse patterns: Openbank asks for the DNI and four digits, while Banco Sabadell allows access with just four digits, like a PIN.

The NIF is not secret. It appears in leaked databases, payslips, or contracts. Therefore, the only real protection factor is that short key. Beyond that, everything depends on whether the password has been reused or if the user fell for a fake website.

How long does it take to sustancia ilegal a 6-character password?

If an attacker obtains the database of users and passwords, the six-character key ceases to be an obstacle. Technical analysis circulating suggests that with hashes in hand, dictionary or brute-force attacks expose them easily. Some estimate a week for the entire customer base, admitting it could be less. A six-character alphanumeric string is VERY weak, according to the analysis itself. The only remaining barrier would be two-factor authentication, where the next vulnerability begins.

The "irreversibly encrypted" password the bank requests in parts

BBVA states on its website that it never stores passwords in plain text and that they are irreversibly encrypted. However, the same page explains that when customers call the Contact Center, they will be asked for two random positions of their key, never the full password. The question answers itself: how can two loose positions of a theoretically non-stored readable password be validated? Reconstructing it must be possible.

This inconsistency adds to internal reports from former employees: part of customer communications—emails, PDFs, notices—has historically been handled with outdated tools and templates rewritten manually whenever changes were needed. Regarding outsourcing, there are opposing views: some argue that chaining subsidiaries and consultancies multiplies access to sensitive data, while others claim that an internal employee with privileges knows the weak points even better.

Two frauds of thousands of euros and a bank that washes its hands

Specific cases highlighting the issue involve real money. One client had around 4,000 euros stolen; she ended up in court because the bank initially refused to respond. Another client was defrauded of 3,000 euros via SMS, and according to his testimony, the entity washed its hands of the matter. Other accounts mention messages impersonating BBVA that slip into conversations alongside authentic SMS, making it impossible to distinguish which is which. A participant also mentions a reprimand from the Spanish Data Protection Agency (AEPD) to the entity.

SMS, SIM duplication, and the hole in two-factor authentication

The second front is authentication for transactions. There are reports of transfers made from the app without requesting a PIN or additional confirmation; two-factor authentication, when present, arrives via SMS. And SMS is interceptable, according to the most repeated account: it suffices to call the carrier, impersonate the holder—who already has victim data if they accessed the account earlier—and request a SIM card replacement sent to another address. When the owner reacts, they have lost coverage and the account drains away. The shared defense is setting a PIN with the carrier. This separates a scare from a complete drain.

FIDO2: Authenticating without mobile or SMS

A technical alternative has existed for some time: FIDO2 and WebAuthn security keys. They allow authentication by inserting a physical key, entering a PIN, and touching the device, without relying on the mobile phone, SIM, or message codes. It is also noted that classic coordinate cards abusa European strong customer authentication regulations, PSD2, because they are easy to clone with a simple photo. Yet, banking remains anchored in the username-password pair and SMS codes.

What would need to happen for a bank like BBVA to change an access system that has dragged on for a decade? For now, cases continue to fall on the side of the customer. The question is not whether banks can afford better security, but why they haven't implemented it yet.

Summary of a discussion on Burbuja.info - Foro de economía, actualidad y política., translated from Spanish and reviewed before publication. Read the full discussion (162 replies).

More summaries

All summaries in English →

Back