Tesco Bank suspended online transactions from current accounts after fraudsters took money from thousands of customers over a weekend in November 2016. The attack later led to a £16.4m fine from the Financial Conduct Authority.
What happened
- The bank disclosed the attack on 6 November 2016 and refunded affected customers.
- The Financial Conduct Authority later found that £2.26m had been taken.
- The FCA said the attackers exploited weaknesses in the bank’s debit card design, financial crime controls, and fraud detection rules, and that the bank had not properly acted on a specific warning.
- In October 2018 the FCA fined Tesco Bank £16.4m, after a 30% discount for early settlement and credit for its co-operation and redress.
Why it mattered
The case showed that UK financial regulators would treat cyber resilience as a conduct issue and hold firms accountable for foreseeable fraud risks. It also highlighted the importance of fraud detection controls that can adapt to fast-moving attacks.
Lessons for organisations
Act on threat intelligence promptly, test fraud controls against realistic attack scenarios, and rehearse incident response so that decisions are made quickly.
Source: Financial Conduct Authority
Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.