HD.39 case fileEvidence-led analysis

Customer data integrity / Evidence analysis

Shadow Records: Why Deleted Contact Data Still Matters

When a financial institution responds to a cybersecurity complaint, the accuracy of its own customer records becomes part of the evidence. A call placed to an outdated number may appear minor in isolation. In a dispute involving undelivered credit cards, Amazon alerts, and conflicting explanations, however, it raises a more consequential question: which customer record was Riyad Bank actually using—and why?

What began as a complaint concerning the exposure of payment-card data subsequently revealed a separate data-governance issue. Although my current mobile number had been formally updated, calls connected to the credit-card complaint were directed to an old number that I had stopped using for financial dealings.

1. One Case, Multiple Names

As the complaint escalated, I received calls from Riyad Bank’s credit-card department through multiple numbers, including 0117996200 and 0505347400.

According to my contemporaneous notes, the caller identified himself at different times as Abdullah, Adel, and Awad. The conversations also shifted in substance. In one exchange, I was told that the disputed activity had caused no financial loss. In another, the discussion moved toward whether I had previously dealt with Amazon.

Those statements do not answer the central security question: how did the card details become associated with Amazon before the physical cards reached me? Nor do changing names and shifting explanations provide the accountability expected from a controlled complaint-handling process.

Riyad Bank’s call recordings, employee identifiers, case notes, and access logs can establish whether the calls came from one employee or several, and why different names were used. Those records should therefore be preserved and examined.

2. The Outdated Number

The more serious issue is the destination of the calls. Riyad Bank placed three calls to my old mobile number on July 29 at 11:02 a.m. I had previously removed that number from my financial dealings and formally registered my current number through the official channels available to me, including Absher-linked identity procedures.

SMS notification documenting three missed calls from Riyad Bank to the old mobile number on July 29 at 11:02 a.m.
Evidence 01 SMS notification documenting three missed calls from Riyad Bank to the old mobile number on July 29 at 11:02 a.m. The association of the calling number with Riyad Bank is supported by additional communication records retained by the author.

The unresolved issue is therefore not the identity of the institution placing the calls. It is why an outdated number remained available for operational use after the customer’s active information had been updated.

3. What the Calls May Reveal

The use of the old number points to two data-governance possibilities. The bank’s internal audit records should determine which one occurred.

Fragmented or Unsynchronised Customer Data

The bank’s authoritative Know Your Customer record may have contained the current number while a separate card-servicing, complaint-management, or historical system continued to expose the previous number as an active contact field.

If so, the issue is not merely a technical inconvenience. It raises questions about data accuracy, system synchronisation, retention, and purpose limitation under Saudi Arabia’s Personal Data Protection Law. A regulated institution should be able to identify its authoritative customer record, explain how updates propagate across systems, and demonstrate that obsolete data is not mistakenly reused for active communications.

Operational Access to Historical Contact Data

A second possibility is that personnel handling the complaint retrieved historical customer data and used it during an active case.

Retention of historical information is not automatically unlawful; it may serve legitimate regulatory, contractual, security, or evidentiary purposes. But retention is different from operational reuse. The relevant questions are whether the access was authorised, whether its purpose was recorded, and why the obsolete number was selected instead of the verified current number.

4. The Audit Questions

The issue can be resolved through records that should already exist. Riyad Bank and the relevant supervisory authority should establish:

  1. Which mobile number was designated as the authoritative active contact when the calls were made?
  2. Which system supplied the old number to the caller?
  3. Was the number stored as an active field, a historical record, or both?
  4. Which employee account accessed it, at what time, and for what recorded purpose?
  5. Did the bank’s systems log the selection or manual entry of the called number?
  6. How and when was the updated number propagated across KYC, card-servicing, and complaint-management systems?
  7. What retention rule justified keeping the old number, and what control prevented—or failed to prevent—its operational reuse?
  8. Do the call recordings and case notes identify the callers and explain the inconsistent names and statements?

An Open Question for SAMA

If a bank cannot explain why an obsolete phone number remained available for use during a sensitive credit-card investigation, the problem extends beyond customer service. It becomes a question of data governance, access control, auditability, and regulatory confidence.

Customers are repeatedly asked to keep their information current. Financial institutions should be held to the corresponding obligation: to know which data is current, where historical data remains, who can access it, and why it is being used.

HD.39 / Digital Forensics Record