Tuesday, June 16, 2026

Just Email Us the Documents

Consumer · Field notes REF / SECURITY

How two banks, in the same week, asked me to send my most sensitive documents over the one channel they spend a fortune warning me never to trust — and what happened when I asked for something safer.

Two banks. Same week. Both wanted proof of residency and proof of income. Both, without a flicker of self-awareness, asked me to email it to them.

These are institutions that freeze your card if you buy a coffee in the wrong postcode. That make you authorise a €30 transfer with a fingerprint, a one-time code, and a passive-aggressive push notification. That bury you in literature about phishing, about never sharing details, about how they will never ask you to send sensitive information by email.

And then they ask me to send sensitive information by email.

What’s actually in those documents

Stop and think about what a “proof of residency and proof of income” bundle contains. A utility bill or bank statement with my full name and home address. Payslips or tax documents with my employer, my salary, my national insurance or tax reference number. Often an account number or two thrown in for good measure. Frequently a signature.

That is not paperwork. That is a starter kit for identity theft, assembled and gift-wrapped, sent over the one channel specifically designed in 1971 without a single thought for confidentiality.

Email was never secure and never pretended to be

Here’s the part the average compliance officer seems to have missed. Email is not a sealed envelope. It’s a postcard that may or may not be carried in an armoured van for part of the journey.

Yes, most providers now negotiate TLS between mail servers, so the message is usually encrypted in transit. But “usually” is carrying a lot of weight there — if the receiving server doesn’t support it, plenty of systems silently fall back to plaintext rather than fail. And in-transit encryption does nothing about the rest of the lifecycle:

  • The attachment sits decrypted at rest in my Sent folder, indefinitely.
  • It sits decrypted in their inbox, indefinitely, on infrastructure I will never see and cannot vouch for.
  • It passes through, and is logged by, however many intermediate systems, spam filters, and archiving appliances sit between us.
  • It is exactly one compromised mailbox — mine or theirs — away from being copied wholesale. And email accounts are the single most phished, most credential-stuffed, most reused-password target on the internet.

End-to-end encryption — the thing that would actually fix this — is something neither a high-street bank nor a normal customer has set up. So it isn’t happening. The document is travelling in the clear at both ends of its life, which is most of its life.

The bit that should genuinely worry them

Forget the technical exposure for a second. The worse damage is behavioural.

Banks have spent two decades and untold marketing budgets trying to train customers on one rule: we will never ask you to send personal information by email, so if someone does, it’s a scam. It’s printed on statements. It’s in the app. It’s read out by the hold music.

Then the real bank emails you and asks for personal information by email.

Every time a legitimate institution does this, it sands down the one instinct that protects people. It teaches customers that yes, actually, banks do fire off unsolicited requests for sensitive documents over email, and the right response is to comply quickly. That is the precise reflex every phishing campaign on earth is trying to manufacture — and the banks are manufacturing it for free, on the bank’s own letterhead, making the next fraudulent request indistinguishable from a real one.

You cannot run a customer-education programme that says “this never happens” while operating a back office that does it twice a week.

It isn’t even hard to do properly

The maddening part is that the fix is mature, cheap, and already sitting in most of these organisations:

  • A secure upload portal — a link to an authenticated page on the bank’s own domain where you drop the file. Standard for a decade.
  • In-app document upload. The app I authenticate into with biometrics every single day. The file never touches email at all.
  • Secure messaging inside online banking, where the document stays within their walls end to end.
  • Failing all of that, bring it to a branch — remember those?

This is not a budget problem or a technology problem. It’s an institutional shrug. Email is the path of least resistance for whichever team is chasing the document, so email wins, and the security function that would object either wasn’t asked or was overruled by “the customer just needs to send it.”

So I asked. Reader, it went well.

I didn’t email anything. I asked both banks for a secure alternative, and the responses were instructive.

The first bank actually had a portal — and sent me a link to it. The link was broken. Dead. A 404 where my sensitive documents were supposed to go. This is, in a grim way, the most honest outcome of the lot: the secure capability exists on paper, someone built it, someone is presumably reporting it up the chain as “customers can upload securely” — and it doesn’t work. A broken secure channel is arguably worse than an honest lack of one, because it lets everyone tick the box while the real-world fallback quietly becomes “oh, just email it then.” Security that 404s isn’t security. It’s a screenshot for an audit.

And here’s the kicker. This same bank has a perfectly good secure app — the one I log into with my face, the encrypted channel I’m already trusted to move money through. It just doesn’t support document upload. So the most secure pipe they own, the one I’m holding in my hand, can’t accept the very thing they’re asking me for. The secure channel exists and the broken channel exists, and the only one missing is the join between them. So the document gets routed to email — the least secure option on the menu — not because the secure one is unavailable, but because nobody finished building the on-ramp to it.

The second bank is still thinking about it. But it did offer an alternative while I wait: the post. Send the documents by mail.

And — how, exactly, is that more secure?

Post is a sealed postcard’s more confident cousin, and not much else. Standard mail has no encryption because it has no anything — it’s a physical object handled by a chain of strangers, dropped through a letterbox that, in plenty of buildings, is a communal tray anyone can reach into. There’s no tracking unless you pay for it, no proof of delivery, no audit trail, and no way to know it arrived until it doesn’t. It can be lost, misdelivered, or simply lifted — mail theft is a real and growing route into exactly this kind of identity fraud. And in my case the documents would be crossing a border to get there, which adds days of exposure, more hands, and more depots.

So the menu I’ve been offered is: an insecure digital channel (email), a secure digital channel that doesn’t load (the dead portal), or a Victorian analogue channel with no security model at all (the post). The only option deliberately designed with confidentiality in mind is the one that’s broken.

Security theatre, meet security tragedy

We’ve all rolled our eyes at security theatre — the elaborate, visible rituals that make you feel protected while achieving very little. Forced 90-day password rotation. The transaction you have to approve from three different directions.

This is the inverse, and it’s worse. It’s a real, serious risk handled with total informality, behind a façade of an institution that talks about security constantly. The performance is all front-of-house. Out the back, your tax documents are going out as a Gmail attachment — or, when someone finally builds the proper channel, sitting behind a link that 404s while the bank suggests you pop them in the post instead.

Everything secure about the bank stopped exactly where I needed it most.

If your bank asks you to email proof of income, don’t. Ask for the secure portal — and then check it actually loads, because apparently that’s on you now too. And if the fallback they offer is the post, ask them, as I did, how a chain of strangers and an unlocked letterbox is the more secure option. Make them sit with the question. Somewhere in that organisation is a secure channel that works. They just haven’t been asked often enough to go and find it.

Ends

Tuesday, June 9, 2026

The button marked “Add extra baggage” that adds no baggage

Consumer · Field notes REF / BAGGAGE

How British Airways, Qatar Airways and the Civil Aviation Authority built a perfect little trap — and each, quite correctly, denied responsibility for it.

There is a particular kind of modern absurdity that only reveals itself when you try to give a company money and discover you can’t. This is a story about that — about a checked bag I tried to buy ten months early, the airline website that cheerfully invited me to buy it, the two airlines that then spent a fortnight explaining why I couldn’t, and the regulator that wrote back to say the whole thing was none of its business.

It is, I think, a small but perfect example of how a system can be working exactly as designed and still be ridiculous.

The setup

I booked a long-haul return trip using Avios — a reward booking on flights operated end to end by Qatar Airways , but ticketed and sold by British Airways . This is an entirely normal thing to do. Millions of people redeem miles on partner flights every year. Because of how these redemptions work, the booking can only be made by telephone; the website won’t do it.

Fine. I made the call, the Avios came off, the tickets were issued, and a confirmation arrived listing a generous baggage allowance and noting — reasonably enough — that I “may also be charged for extra or overweight checked bags.” Extra bags, then, were a thing one could arrange. Good to know, because I wanted one.

The button that does nothing

So I went to manage the booking on the British Airways website, where the airline presents a tidy grid of things you can do: choose a seat, request a special meal, upgrade your cabin, and — right there, with its own little suitcase icon — Add extra baggage .


British Airways “Manage My Booking.” “Add extra baggage” is offered as a service, alongside seat selection, meals and cabin upgrades.

I clicked it.

It did not let me add extra baggage. It took me to a general information page explaining that baggage on partner-operated flights is governed by the operating airline, with a link sending me off to Qatar Airways’ site. No purchase. No price. No bag. Just a door marked “Add extra baggage” with a brick wall behind it.


Where the button leads: an information page about partner-airline allowances. No purchase, no price — just a redirect to the operating carrier.

This, it turns out, is the whole story in miniature.

The bounce

Following the trail, I asked British Airways directly. Its escalations team — and I want to be fair here, because they were genuinely helpful and human throughout — told me in writing that extra baggage “can be booked directly through” Qatar Airways’ website.

So we rang Qatar Airways. They said no: extra baggage can’t be added to a ticket issued by another airline, and the only option is to pay at the airport on the day. We rang again. Same answer. And again. Three times. Eventually they put it in writing: prepaid baggage is available only on Qatar Airways’ own ticket stock, this restriction “applies strictly in all circumstances,” and no exception would be made.

One airline tells you, in writing, to go and buy the bag from the other. The other tells you, in writing, that it will never sell it to you. Both are correct about their own rules.

The passenger is simply standing in the gap between two policies that don’t meet.

The price you’re not allowed to know

Here is the part that tips it from frustrating into faintly insulting. Because I couldn’t prepay, the only route left was the airport excess-baggage desk — which, on this route, runs to around fifty US dollars per kilo . A single extra suitcase would cost north of a thousand dollars. Buying the same allowance in advance online — the option I was structurally barred from — would have been up to 20% cheaper.

And when we asked Qatar Airways simply to tell us what the airport charge would be, so we could at least budget, the answer was that it would be “the rules and rates applicable at that time.” You cannot buy the thing in advance. You cannot find out what it will cost. You can only turn up on the day and discover the number at the precise moment you have no alternative.

(The rational move, for the record, is to ignore the airline entirely and post the suitcase home, which costs roughly a tenth as much. When shipping a bag across the planet by courier is an order of magnitude cheaper than checking it in, something in the pricing has come loose.)

Credit where it’s due

I said I’d be fair, and I mean it, because the contrast is the point. British Airways actually engaged. A named human looked at the case, phoned me, took it to Qatar Airways himself, and was honest about the limits of what he could do. He couldn’t fix it — but he tried, and he didn’t hide.

Qatar Airways did the opposite. It recited a policy, linked to a webpage, and declined four times to engage with the substance, including a flat refusal to quote a price. One airline ran out of road. The other built the roadblock and put up a sign saying the road was someone else’s responsibility.

The bit nobody discloses

Strip away the back-and-forth and the real fault is singular: none of this is told to you when you book. Not on the phone, not in the confirmation, not anywhere a normal person would look before paying. You find out only afterwards, when you try to buy a bag and hit the wall. A reward booking that millions of people make comes with a quiet, undisclosed catch — that one of the most ordinary purchases in air travel is closed to you, and that the fallback is the most expensive version of it, at a price you’re not permitted to see in advance.

That’s not a service hiccup. That’s a transparency failure, and a structural one, because Qatar Airways confirmed in writing that it applies to every ticket not issued on its own stock. Which is to say: to everyone in my position, every time.

And the regulator?

You might think this is what a regulator is for. I did too. So I referred it to the Civil Aviation Authority — carefully framed not as “fix my booking” but as “here is a market-wide practice worth looking at.”

The CAA wrote back to say it no longer handles complaints about airlines that belong to a dispute-resolution scheme, and — my favourite sentence of the entire saga — that it “has no legal powers to impose a solution on an airline.” It directed me to that scheme, the Centre for Effective Dispute Resolution (CEDR), instead.

But CEDR only does one thing: it makes binding decisions on individual claims. It cannot touch the underlying practice. It can, at best, order one airline to refund one passenger one fee. It cannot ask why the door marked “Add extra baggage” leads to a wall, or why a price can’t be quoted in advance, or why none of this is disclosed at the point of sale.

So the systemic problem has no home. The regulator says it’s the scheme’s job; the scheme only does individuals; and the practice itself sails on, undisclosed, for the next person who clicks the button. I’ve now reported it to the Competition and Markets Authority , which — under the new consumer-protection regime — is the one body that can actually look at a practice rather than a single complaint. We’ll see.

The point

I will probably end up posting the suitcase. The fee, in the end, is survivable. What isn’t quite so easy to shrug off is the shape of the thing: a button that promises a purchase it can’t deliver, two airlines each pointing at the other, a price you can’t discover until it’s too late to avoid, and a regulator that has quietly arranged to have no responsibility for any of it.

Everything here is working as designed. That’s exactly what’s wrong with it.

We've opened a secure channel. Please email us the password.

Consumer · Field notes REF / SECURITY — FOLLOW-UP A follow-up. Of the two banks that asked me to email my identity and income document...