Explore Problems

Showing 4,194 of 7,473 problems · matching your filters

Bank of America Debit Card Compromised Four Times in Three Months

A Bank of America customer had their debit card compromised four separate times in three months, with the bank's only remedy being card replacement each time. There is no root cause investigation or proactive protection, leaving customers in a loop of account intrusion. The repeated failures indicate a systemic gap in fraud detection and real-time account protection.

1 mentions1 sources
S6.2L6
Security & Compliance · Fraud Prevention

Payday loan payoff balances don't reconcile with amounts already paid

Borrowers on short-term, high-frequency payday loan repayment plans lose track of how much they've paid versus what they still owe, and lenders' balance communications don't clearly reconcile against the payment history. This leaves borrowers confused about whether they're near payoff or still deep in debt.

28 mentions1 sources
S6.2L6
Consumer & Lifestyle · Personal Finance

Wells Fargo Restricts Account for Fraud Alert Then Charges the Disputed Transaction Anyway

After a customer flagged an unrecognized transaction, Wells Fargo restricted their account and issued a new card — then processed the disputed charge anyway. The fraud prevention process caused double harm: account disruption plus no actual protection. Customers are left worse off for engaging with the bank's fraud reporting system.

1 mentions1 sources
S6.2L5
Security & Compliance · Fraud Prevention

Banks send uncashed checks to unclaimed property without adequate notice

When a customer does not cash a check within the bank's internal timeframe, some banks transfer the funds to state unclaimed property without clearly notifying the account holder in advance, even with an active account and current contact information on file. Customers must independently discover the transfer and file a claim to recover their own money.

384 mentions1 sources
S6.2L5
Industry Verticals · FinTech & Banking

The Web Is Built for Human Fingers, Not AI Agents

AI agents capable of autonomous work are blocked at every turn by human-centric web infrastructure: CAPTCHAs, browser-rendered UIs, 2FA flows, and modal-heavy signup gates that assume a human is present. This is a structural gap between agentic AI capability and the web stack it must operate on, creating a compounding bottleneck as agent usage scales.

1 mentions1 sources
S6.2L9
Data & Infrastructure · Cloud & Hosting

AI Chatbots Hallucinate Bookings and Promises in Service Businesses

LLM-based customer service bots in high-ticket businesses (clinics, salons, restaurants) frequently hallucinate compromises, confirm impossible bookings, and promise nonexistent discounts because they are optimized for helpfulness rather than business rule enforcement. This creates liability, lost revenue, and damaged reputation.

1 mentions1 sources
S6.2L8
Productivity · Automation & Workflows

Unbundled Admin Gaps in Professional Services Costing Revenue

Professional service firms in dental, legal, CPA, and property management lose significant revenue and time to repetitive admin tasks that off-the-shelf software handles poorly. Specific unmet gaps include missed-call text-back, prior authorization tracking, scope creep monitoring, and tenant communication logging. These businesses have budget and are willing to pay for focused, lightweight standalone tools.

1 mentions1 sources
S6.2L8
Productivity · Automation & Workflows

Hardened self-hosted servers are compromised via unknown attack vectors with no forensic tooling

Self-hosters and small teams running hardened VPS configurations face server compromises from novel attack vectors — potentially kernel exploits or init system vulnerabilities — that bypass all standard defenses including disabled password auth, fail2ban, and locked root accounts. Post-incident forensics are extremely difficult without enterprise-grade SIEM tooling, leaving self-hosters unable to understand the attack vector or prevent recurrence. This gap between enterprise security tooling and self-hoster budgets is widening.

1 mentions1 sources
S6.2L7
Security & Compliance · Fraud Prevention

Hardcoded API keys and PII leaks in client-side code go undetected

Developers routinely accidentally embed API keys, tokens, and personally identifiable information directly in browser-accessible code repositories. Standard CI/CD pipelines and code review often miss these leaks before deployment. A local, privacy-first scanner that identifies credential and PII exposures without transmitting code to external services addresses a high-severity security gap.

1 mentions1 sources
S6.2L6
Security & Compliance · Application Security

Teams Outgrowing Spreadsheets Need Database-Like Tools with Permissions

Large organizations with 200+ employees struggle to manage complex data in spreadsheets. They need structured database solutions with spreadsheet-like interfaces, granular permissions, and file management capabilities.

1 mentions1 sources
S6.2L6
Business Operations

Debt Collectors Report Conflicting Status, Bureaus Shrug

Debt collectors report account status as simultaneously open and closed, or otherwise inconsistent, and credit bureaus close consumer disputes citing insufficient proof without requiring the collector to substantiate its data. Consumers are left with no path to force a real correction.

18 mentions1 sources
S6.2L5
Customer Experience · Service & Billing Disputes

Contractor-Financier Finger-Pointing Strands Defect Claims

When contractor-installed home improvements such as windows turn out defective, consumers get bounced between the contractor and the third-party lender who financed the work, each denying responsibility. Warranty and dispute processes can drag on for years without the defect ever being remedied.

15 mentions1 sources
S6.2L5
Customer Experience · Service & Billing Disputes

No Unified SDK for Object Storage Across Cloud Providers

Developers must use separate, incompatible SDKs for each cloud storage provider (S3, GCS, Azure Blob, R2), creating vendor lock-in and requiring rewrites when switching or supporting multiple backends. A unified abstraction layer is missing in the JavaScript ecosystem. 229 HN upvotes validates strong developer demand.

1 mentions1 sources
S6.2L8
Developer Tools · APIs & Integrations

AI Citation Traffic Is Invisible to Marketers

Marketers and SEO professionals have no reliable way to track when their content is cited by AI assistants like ChatGPT, Perplexity, or Gemini. This traffic gets misattributed to direct or dark social, leaving an entire growing channel unmanaged. As AI search becomes a dominant discovery method, the measurement gap creates compounding strategy errors.

3 mentions1 sources
S6.2L8
Marketing & Growth · Content & SEO

Shopify removes native features in updates to force merchants into paid app subscriptions

Shopify platform updates routinely remove or degrade previously available native functionality, with the removal justified by directing merchants to third-party apps. Merchants accumulate a fragmented stack of app subscriptions for features that were previously built-in, with each app adding monthly costs and an independent support relationship. When the combined stack breaks, neither Shopify nor individual app vendors accept accountability for the interaction.

2 mentions1 sources
S6.2L7
Business Operations · E-commerce Operations

Shopify gates basic ecommerce features behind mandatory paid app subscriptions

Shopify deliberately excludes standard ecommerce functionality from its core platform, requiring merchants to purchase third-party apps for features competitors bundle as standard. Monthly app costs compound into hundreds of dollars per month on top of Shopify's own fees. During outages or billing disputes, merchants face fragmented accountability with Shopify and each app vendor disclaiming responsibility for the combined failure.

2 mentions1 sources
S6.2L7
Business Operations · E-commerce Operations

Business automation pipelines silently fail with no reliable observability

Companies running critical automations via tools like Zapier, Make, or internal scripts lack reliable monitoring — failures are silent or produce subtly wrong data that is hard to catch. Existing solutions focus on infrastructure monitoring, not business process health. The gap causes real financial and operational harm when automations break undetected.

1 mentions1 sources Trending
S6.2L7
Productivity · Automation & Workflows

Identity Theft Discovered Too Late During Mortgage Application

Multiple fraudulent accounts were opened using a consumer's identity and went undetected until a mortgage lender pulled their credit report. Existing credit monitoring failed to alert the consumer before significant damage was done.

2 mentions1 sources
S6.2L7
Security & Compliance · Identity & Access

Debt Collectors Provide Inadequate Documentation to Validate Disputed Debts

When consumers formally dispute a debt and request itemized validation, collection agencies often respond with only a generic form letter and account ledger rather than proof the underlying charge is legally enforceable. This leaves legitimacy disputes unresolved.

259 mentions1 sources
S6.2L7
Business Operations · Legal & Compliance

Loan servicers misapply payments and mark accounts delinquent

A borrower's automated mortgage payment, materially identical to the prior month's, was placed in a suspense account rather than applied to the loan after an escrow-driven payment increase, resulting in inconsistent treatment of otherwise identical payments. This kind of inconsistent payment application creates unwarranted delinquency risk for borrowers on autopay through servicer or escrow changes.

144 mentions1 sources
S6.2L7
Industry Verticals · FinTech & Banking
Previous204/210Next