Skip to main content
Emerging Threats

CAF Bank Reopens Online Service After Fraud Attempt

Bank interior with people waiting, laptop on counter in foreground.

“We have completed the essential work with our technology partners and our online banking service is now available,” said Alison Taylor, CAF Bank CEO.

Alison Taylor confirms service restored, investigation continues

In a statement quoted by The Register, Alison Taylor said the bank has reopened its online banking service after more than ten days of disruption and that work with technology partners is complete. She acknowledged customer frustration and long telephone wait times, adding that a “thorough investigation into the incident will continue so that we, our partners and our industry can learn from it.”

Timeline: attempted fraud on July 21, multiple access withdrawals July 22–25

CAF Bank told customers—via an email update seen by The Reg—that it first noticed “attempted fraudulent activity” on July 21 affecting a small number of accounts. The bank said it called in “external specialists” and temporarily withdrew access to online services on Wednesday July 22 and again on Friday July 24 while those investigations were under way.

On Saturday July 25 the bank detected “related malicious activity of a different kind,” the email said, describing it as activity “aimed at removing a small number of individual online user logins, making those logins unavailable.” The bank said it “caught this quickly and removed access to the online service.” The online service remained offline for more than ten days before the restoration Taylor announced.

Root cause: a previously unknown vulnerability in third‑party connectivity

The customer email attributed the disruption to a previously unknown vulnerability in “how some third-party software connects to the online banking portal.” CAF Bank stressed the “core bank” was not affected, adding that “money is safe and secure in accounts.” The bank warned customers that access could remain intermittent and that it “might need to limit the amount of traffic to the website” at certain times, conceding: “There are likely to be periods where online banking is not available. We will try to keep this to outside business hours.”

Charities vocal after migration to Temenos Transact and new outage

The Charities Aid Foundation-owned bank had already faced criticism after a long-running migration to a new platform based on Temenos Transact (formerly T24). In an open letter about the latest outage, charities described the new online banking platform as “significantly more time-consuming to use, placing an unnecessary administrative burden on already stretched small charities” and “often unreliable.”

Kevan Hodges, chief executive at Kent-based Down's syndrome charity 21 Together, told the BBC: “People are concerned that wages won't get paid because of this, and that's just stressful when they have bills to pay.” Those concerns reflect the practical pressures charities say the outages create for paying staff and suppliers.

What this means for charities, customers, and technology partners

  • Charities: Continue to monitor access and contingency payroll arrangements closely; the latest outage amplifies worries about timely payment of wages and suppliers after the Temenos Transact migration.
  • Customers: Should expect intermittent availability and possible traffic limits outside standard hours, but can note the bank’s assurance that customers’ money is “safe and secure.” The bank has also sought to compensate account holders by waiving monthly charges.
  • Technology partners: Will remain engaged in the ongoing investigation after the bank identified a previously unknown connectivity vulnerability and after CAF called in “external specialists.” The bank framed the investigation as an opportunity for the partners and the wider industry to learn.

CAF Bank also told customers that “due to the disruption, as a small thank you for your patience, we will be waiving our monthly customer account charge for all customers for August and September 2026.” The Reg can confirm those charges are £5 a month.

The facts delivered so far are concrete: a spike of attempted fraud on July 21, two temporary withdrawals of the online service on July 22 and July 24, further malicious activity on July 25 that targeted individual logins, an identified vulnerability in third‑party connectivity, and a reopened portal accompanied by warnings of intermittent access. The bank promises continued investigation and industry learning; charities and customers will watch whether fixes to the third‑party connection restore reliable, timely access after a migration that many have already judged burdensome.

Original story: https://www.theregister.com/security/2026/08/04/caf_bank_reopens_online_service_but_warns_of_further_outages/5282668