FCA fines Tesco Bank £16.4m after 2016 cyber attack

'Customers should not have been exposed to the risk at all'

Mike Sheen
clock • 2 min read

The Financial Conduct Authority (FCA) has fined Tesco Bank £16.4m for its failure to adequately protect customers from a 2016 cyber attack, which saw fraudsters claim over £2.2m worth of transactions over a 48-hour period.

Tesco Bank failed to exercise due skill, care and diligence in protecting its personal current account holders in a "largely avoidable" attack that saw cyber criminals exploit deficiencies in the design of its debit card, its financial crime controls and the competence of its Financial Crime Operations Team. 100 days to GDPR: The legislation that wealth managers say will have the biggest impact in 2018 According to the regulator's 1 October enforcement notice, the attackers are understood to have used an algorithm that generated authentic Tesco Bank debit card numbers and, using those...

To continue reading this article...

Join Investment Week for free

  • Unlimited access to real-time news, analysis and opinion from the investment industry, including the Sustainable Hub covering fund news from the ESG space
  • Get ahead of regulatory and technological changes affecting fund management
  • Important and breaking news stories selected by the editors delivered straight to your inbox each day
  • Weekly members-only newsletter with exclusive opinion pieces from leading industry experts
  • Be the first to hear about our extensive events schedule and awards programmes

Join now

 

Already an Investment Week
member?

Login

More on Regulation

Trustpilot