Don’t do SECURITY. Do business SECURELY.

Tesco Bank suspends online payments after attack on customer accounts

Tesco Bank froze online debit transactions after attackers stole money from thousands of current accounts in a weekend attack.

Tesco Bank suspended online transactions from current accounts after fraudsters took money from thousands of customers over a weekend in November 2016. The attack later led to a £16.4m fine from the Financial Conduct Authority.

What happened

  • The bank disclosed the attack on 6 November 2016 and refunded affected customers.
  • The Financial Conduct Authority later found that £2.26m had been taken.
  • The FCA said the attackers exploited weaknesses in the bank’s debit card design, financial crime controls, and fraud detection rules, and that the bank had not properly acted on a specific warning.
  • In October 2018 the FCA fined Tesco Bank £16.4m, after a 30% discount for early settlement and credit for its co-operation and redress.

Why it mattered

The case showed that UK financial regulators would treat cyber resilience as a conduct issue and hold firms accountable for foreseeable fraud risks. It also highlighted the importance of fraud detection controls that can adapt to fast-moving attacks.

Lessons for organisations

Act on threat intelligence promptly, test fraud controls against realistic attack scenarios, and rehearse incident response so that decisions are made quickly.

Source: Financial Conduct Authority

Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights