Dear Spark

Your “Tell us how we went” email has sat in my inbox for some weeks, waiting for me to get to it. Also, I suppose, waiting for some late reply to my last message that might have rescued the situation. Of course that didn’t end up happening. So, this message in your feedback form, which will be too long to fit. So I’m also posting publicly on my blog.

The lapse in your provision of service was relatively small in the grand scheme of things. However, it’s the nature of the failure that has stuck with me. And the more I tried to dig into it, the worse it all seemed, to the point that we are considering leaving Spark entirely.

Here is what happened.

My wife and I have been Spark customers for a long time. You provide us with broadband and mobile phone accounts (also a landline that we no longer use after recent renovations). We have been happy as your customers.

On June 17, my wife and I both received emails from mysparksupport@spark.co.nz titled We’ve removed an account from your Spark ID:

“Hi [NAME],
You no longer have access to Spark account [NUMBER].
If you think you’ve received this in error, please let us know.
Thanks!
From the Spark team”

This brief message was somewhat lost in the welter of emails we receive, and quite frankly it looks like some kind of spam or error. I tried to log into the Spark dashboard to see if I could understand what was going on.

This was unsuccessful in the most unhelpful ways. My password was simply not accepted, as if it was incorrect. I attempted to reset the password, but these attempts failed with no explanation. Finally, when I tried to use Google as a login method, the site gave a different message, that my email identity was locked out.

This began a lengthy process of investigation. My wife had created our account, and so I couldn’t even get any functional responses from support because I hadn’t been given account authority by her (something we had never previously needed or understood we might ever need). She had to spend a lengthy period, many hours, on the phone to establish who she was and figure out what was happening. Once she was able to set me up with authority, I took over and several more hours were spent on calls to get our account access back.

Throughout all the above, your helpdesk workers were unfailingly helpful and responsive. We are very happy with the direct service we received from these staffers. The problem was the limited information they had, the limited understanding they had, and the questions we have remaining at the end of this process.

We were, eventually, told that our accounts had been removed by the fraud prevention team, to protect us, because there were signs of access by a third party. Our account access was fully restored.

I persisted in email conversation with the fraud prevention team, trying to get more information, but there was very little forthcoming. At the end of this process I remain utterly infuriated.

To be clear: your fraud prevention systems are not fit for purpose and we are extremely dissatisfied.

We know that fraud prevention detected an attempt to log into our MySpark account from an international IP address. It was blocked, and an action of some kind was taken that removed access from our email address logins. This in turn generated the emails. Later, when we eventually proved our identities over the phone, our email addresses were linked back to the accounts.

Here are my problems:

What was the trigger event that led to access to our accounts being removed? Fraud prevention provided unclear information here. Fraud prevention could not tell me: which email address was used in a login attempt; was the login just an attempt with an email address, or did they have the correct password as well; were there multiple login attempts; where did these attempts take place; was there a successful login before access was revoked; or any other details at all. I find it hard to understand how this is possible; that our accounts were at such risk that they were taken out of our hands, but the information behind this action is so vague and undefined.

How was the decision made to remove access to our accounts? Was this decision made according to a standard procedure? (In which case, why is there no standard procedural followup?) Was this decision made by a person, or by an automatic process? Is fraud prevention of this nature managed by an AI system or entirely by a human team?

Why didn’t you check with us first? If there was a problem with our accounts from overseas, why didn’t you ever take the step of asking us about it? You have our phone numbers right there! You can verify our identities immediately! Surely the appropriate way to deal with a problem like this is to call and speak to someone, not delete our access, send an email, and abandon us to your FAQ and helpdesk to figure out what to do?

If access was at such risk that our emails were removed, why were they immediately restored? After establishing our identities, our emails were back on the accounts with the same passwords. Belatedly I received a comment from fraud prevention that we might want to change our passwords to be extra safe. But if our account details had been compromised, surely they were still compromised? How had the threat changed? And if it hadn’t changed, why was everything suddenly restored to normal as if nothing had happened? None of this makes any sense at all. Logically, either the initial action or the remedy was faulty. To be enitrely clear about what is at stake here: Are our personal details exposed, or not?

Why was your communication throughout nearly nonexistent? Such a significant event as removal of access for both account users generated a short email with no explanation, and nothing else. Figuring out what had happened took hours. Your systems created a huge problem for us, and then offloaded on to us every aspect of trying to solve it. I’m fairly sure your organisation would agree that “creating a messy problem for us to solve” is not an acceptable customer experience.

What is the risk being mitigated here? Fraud prevention also could not tell me what an intruder might do if they did gain access to our account. Presumably a malicious actor wants to do more than change our mobile phone plans! While this is a secondary issue, our continued ignorance on this point demonstrates just how poorly you have managed our experience.

It has been over a month since this event and I remain thoroughly dissatisfied by what transpired, and I have no confidence at all that the same poor experience will happen to other customers or, indeed, to us again in the future.

I expect a clear explanation, in writing, as to what exactly has happened here, from beginning to end.

Within this, I expect clear answers to these questions: Have our email addresses and passwords been exposed internationally? What information do you have that demonstrates this? If they have been exposed, why were our accounts restored with no changes? If not, why did this intervention happen in the first place? (Note that this information, our email addresses and passwords, counts as personal information under The Privacy Act 2020.)

Also, I want an indication that you understand and accept that your processes dropped the ball here. Our experience as your customers has been well below the standard we should expect from you. It is simply not good enough.

I await your response.

One thought on “Dear Spark”

Leave a Reply

Your email address will not be published. Required fields are marked *