Skip to content

Designing a secure login and preparing customers for change

UX CASE STUDY | DAMIEN LUTZ

Overview

About

Challenge:
Rising fraud and scams put customer data and money at risk

Client:
Vodafone Australia

B2C

My Role:
Lead Product Designer

UXUI

Key Outcomes

90% completed login with ease

No prior experience of the new flow needed

Password reset calls dropped sharply

“Forgot password” was one of the most common contact reasons — magic links removed it almost entirely

Fraud risk down, friction low

After some initial friction, customers adapted fast

A smartphone showing the log in screen for the My Vodafone App
A smartphone showing the log in screen for the My Vodafone App

Understanding the problem

Passwords were now the risk, not the protection

Vodafone needed to move customers off passwords entirely. The Fraud Team’s preferred fix: a magic link. The user enters their number or email, gets sent a link by SMS or email, and clicks through to finish logging in.

  1. The user enters their number or email at login
  2. If it’s recognised, an SMS or email is sent with a link
  3. They open it and click through to finish logging in

Magic links also wipe out almost all authentication-related support calls — no more “I forgot my password.”

Null

The secure login link concept

Market scan for best practices

Research into login security design set the bar for what good looked like.

Let people choose how they get the link

SMS and email, not just one

Send people straight to their own mail app

Based on what’s installed on their device

Design for cross-device journeys

Started on desktop, finished on mobile, and back again

Build in link expiry

Every magic link needs a use-by date

Never confirm an email or number is invalid

Confirming it exists hands fraudsters a way to test stolen data

Keep the journey consistent across channels

Same tone and pattern whether the link arrives by SMS or email

Service-by-service and user types journey mapping caught new gaps

Working with Fraud and dev, I mapped the login flow across every service type. The gap that mattered most: NBN and broadband customers often don’t know the mobile number tied to their account — the one detail the whole flow depends on.

Assessing login scenarios for web, app, mobile, and for new and exsiting customers, and for after updates

Journey mapping for various service and user types

Mapping insights

NBN and broadband customers didn’t know their own numbers

Design and testing

A design jam reminded us trust was as importnat as comprehension

Running a design jam with the team reframed the problem. It wasn’t just about whether people would understand a magic link—it was whether they’d trust losing their password at all.

Ideas and insights from the design jam I ran with my team

Design jam insights

Copy carried more weight than the UI

Change aversion needed direct handling

Unhappy paths we hadn’t spotted yet

Friction specific to single journeys

Prototyping two designs for testing

Inspired by the journey maps and design jam insights, I designed two prototypes with a goal to test the level of direction and/or simplification the screen could have.

Initial hi-fi UX and journey designs

Preparing copy versions for testing

The copy was extremely important in reducing change aversion and abandonment due to lack of clarity, so I worked vary closely with the copywriter to ensure testing insight was used at every instance of copy along various entry points to the login journey.

Preparing copy variations fro the secure link login testing

Copy variations for multiple login points

Testing answered the trust question directly

Secure link user testing results colour coded for pass, fail, and needing improvement

Key testing insights

More explanation beat less

Detail reduced change shock more than a stripped-back screen did

90% completed with ease

English-as-second-language users struggled somewhat — everyone valued not needing a password

People assumed “their” number

Most expected the link to go to the number on file with their account

The final design

Design mock-ups of Vodafone Secure Login, angled version

Preparing customers for the change

The dashboard had to carry the message, not the login screen

Some customers could skip login entirely via an off-net method, so the login screen alone couldn’t be trusted to reach everyone. The dashboard became the main channel for change messaging.

Off-net users needed dashboard messaging

Login screens alone wouldn’t reach them

NBN and broadband needed number guidance

Many didn’t know where to find it

Emails had to be current

Customers needed a prompt to check and update

Messaging had to stay live

People needed to see it more than once before launch

Vodafone secure login prelaunch comms

Outcomes

The magic link replaced passwords across web and app with minimal disruption and a measurable drop in fraud risk.

90% completed login with ease

No prior experience of the new flow needed

Password-related support calls dropped sharply

“Forgot password” and reset requests were among the most common contact reasons

Change aversion stayed low

Clear in-product messaging and tightly tested copy meant customers understood the change before they hit it

Edge cases caught before launch

NBN and broadband number confusion was solved in testing, not in a support queue