Security as a Barrier: HSBC's Sudden Block on Android Private Spaces Leaves Users Locked Out

AI-generated image · US National Wire
In the name of 'security,' HSBC has stripped away user autonomy by blocking its app from Samsung Secure Folder and Android Private Space, creating an accessibility crisis for those who rely on these tools.
OPINION: Once again, we see a financial giant deciding that 'security' is a valid excuse to strip accessibility and autonomy from the very users who rely on these tools to manage their lives. When a bank decides that a user's choice of how to organize their digital life is a 'risk,' the result isn't more security—it's a lockout.
***
As first reported by The Register, HSBC has implemented an unannounced block that prevents its Android app from running within Samsung Secure Folder and Android's Private Space. These features—Samsung's Knox-based encryption and Android 15's Private Space—are designed to isolate and encrypt sensitive data. Instead of supporting these security-focused environments, HSBC has characterized them as unsecured virtual environments, according to a user review on Google Play.
When questioned by The Register, HSBC stated that the block is a "proportionate security control" intended to mitigate "foreseeable security risk." The bank further explained that using the app within these protected spaces could limit the bank's ability to identify certain threats or prevent the delivery of timely fraud notifications.
However, for the users caught in the crossfire, the "security" HSBC is providing looks a lot like a lockout. The Register reports that customers received no advance warning before the change. Some users now see a generic message citing a security problem with their device and are given no option other than to quit the app.
The fallout extends beyond the mobile app. The Register notes that because HSBC requires the mobile app for multifactor authentication, users who relied on the Secure Folder have been cut off from web banking as well. Some customers have reported being "held hostage" from their own accounts, noting they could not activate a new installation of the app outside the secure folder because the process required an authentication code from the now-inaccessible copy.
For those refusing to move the app to the main phone profile, the alternative is a grueling wait. The Register reports that some users were told they would be locked out of desktop and online banking for five to ten working days while they waited for a physical authentication token to arrive by mail. While a Physical Secure Key (PSK) is an option for desktop access, it can also take several days to reach the customer.
This lack of communication has led some users to question if HSBC is violating the Financial Conduct Authority's (FCA) Consumer Duty. As reported by The Register, FCA guidance stipulates that banks should provide advance communication regarding changes and maintain processes to resolve technical problems that prevent account access.
Despite these failures, HSBC's response has been dismissive. A UK spokesperson told The Register that customers are "informed" of the block the moment they try to access the app. Furthermore, The Register reports that HSBC's chatbots and help pages contained no information about the change, and branch staff were unable to explain it.
This is not an isolated incident. The Register recalls an event earlier this year where the bank locked out users who had sideloaded Bitwarden via the open-source F-Droid catalog. Neil Brown, a board member of F-Droid, reported being locked out after the app detected a version of Bitwarden not installed via Google Play.
In the current crisis, the bank's logic remains circular: it claims that blocking the app protects users from missing fraud notifications, yet by blocking the app entirely, it deprives those users of the ability to receive or respond to those very notifications.

