CAF Bank says 14,000 charity customers in the UK are still locked out of online banking a week after the service was shut down over a security incident. The bank says it detected attempted fraud on some accounts and found a previously unknown vulnerability in the connection between its systems and third-party software; no CVE, affected product name, or restoration date has been disclosed, and the core banking system is said to remain unaffected.
Why it matters: This is disrupting real-world payments, including payroll and supplier bills, for charities that depend on the bank’s online services. Affected organizations need to use contingency payment processes now and watch for further updates from CAF Bank because normal access has no published return date.
2026.08.04
97% relevant
This is a direct update on the same CAF Bank incident, adding that online banking has been partially restored, that further intermittent outages are expected, and that the bank linked the disruption to attempted fraud on a small number of accounts followed by different malicious activity aimed at disabling some user logins via a previously unknown third-party software vulnerability.
2026.07.31
100% relevant
This article establishes a concrete new security incident: attempted fraud led CAF Bank to suspend online banking, and the bank attributes the outage to a previously unknown vulnerability involving third-party software integration.
← Back to all stories