FCA fines Tesco Bank fined £16.4m for cyber security failures

Published on

The Financial Conduct Authority has fined Tesco Bank £16,400,000 for failing to exercise due skill, care and diligence in protecting its personal current account holders against a cyber attack which took place in November 2016.

The regulator found that cyber attackers exploited deficiencies in Tesco Bank’s design of its debit card, its financial crime controls and in its Financial Crime Operations Team to carry out the attack. Those deficiencies left Tesco Bank’s personal current account holders vulnerable to a largely avoidable incident that occurred over 48 hours and which netted the cyber attackers £2.26m.

Mark Steward, executive director of enforcement and market oversight at the FCA, said: “The fine the FCA imposed on Tesco Bank today reflects the fact that the FCA has no tolerance for banks that fail to protect customers from foreseeable risks.

“In this case, the attack was the subject of a very specific warning that Tesco Bank did not properly address until after the attack started. This was too little, too late. Customers should not have been exposed to the risk at all.

“Banks must ensure that their financial crime systems and the individuals who design and operate them work to substantially reduce the risk of such attacks occurring in the first place. The standard is one of resilience, reducing the risk of a successful cyber attack occurring in the first place, not only reacting to an attack.

“Subsequently, Tesco Bank has strengthened its controls with the object of preventing this type of incident from being repeated.”

The FCA found that Tesco Bank breached its Principle 2 because it failed to exercise due skill, care and diligence to:

  • Design and distribute its debit card.
  • Configure specific authentication and fraud detection rules.
  • Take appropriate action to prevent the foreseeable risk of fraud.
  • Respond to the November 2016 cyber attack with sufficient rigour, skill and urgency.

Following the attack, Tesco Bank immediately put in place a comprehensive redress programme and devoted significant resources to improving the deficiencies that left the bank vulnerable to the attack and instituted a comprehensive review of its financial crime controls.

The FCA said Tesco Bank has made significant improvements both to enhance its financial crime systems and controls and the skills of the individuals who operate them.

Tesco Bank provided a high level of cooperation to the FCA, the regulator said. Through a combination of this level of cooperation, its comprehensive redress programme which fully compensated customers, and in acknowledgment that it stopped a significant percentage of unauthorised transactions, the FCA granted the bank 30% credit for mitigation.

In addition, Tesco Bank agreed to an early settlement of this matter which qualified for a 30% (Stage 1) discount under the FCA’s executive settlement procedure. But for the mitigation credit and the Stage 1 discount, the FCA would have imposed a penalty of £33,562,400.

COMMENT ON MORTGAGE SOUP

We want to hear from you!
Leave a comment and get the conversation started.
You need to register to post, so please login or sign up below.

Latest articles

Afin Bank officially enters UK mortgage market with underserved borrower focus

Afin Bank has launched a range of residential and buy-to-let products aimed at some...

HTB backs later-living community with £13.3m refinance deal

Hampshire Trust Bank has completed a £13.3 million facility to support the refinance and...

Aspen provides £1.6m bridging loan for Barnes luxury conversion

Aspen Bridging has funded a £1.6m heavy refurbishment loan to a Chinese developer undertaking...

Chetwood Bank appoints Rob Pomphrett to board as non-executive director

Chetwood Bank has strengthened its board with the appointment of Rob Pomphrett as a...

Altura MD takes on Ultra Challenge for Motor Neurone Disease charity

Rob Gill, managing director of London-based Altura Mortgage Finance, is preparing to take on...

Latest opinions

Why the mortgage industry must digitise for the customer, not just for compliance

Home buyers today can manage their finances, verify their ID and even order a...

The BBC’s exposé isn’t news to mortgage advisers – but it might be to the public

Let’s be honest, for mortgage advisers, the recent Panorama investigation into conditional selling by...

Rachel Reeves rolls back mortgage rules: return to risk or reasonable reform?

Rachel Reeves is to roll back bureaucratic red tape introduced since the 2008 financial...

Reeves’ reforms are a welcome boost but the housing market must modernise

Rachel Reeves’ announcement marks a clear shift in housing policy, with measures that could...

Other news

Afin Bank officially enters UK mortgage market with underserved borrower focus

Afin Bank has launched a range of residential and buy-to-let products aimed at some...

HTB backs later-living community with £13.3m refinance deal

Hampshire Trust Bank has completed a £13.3 million facility to support the refinance and...

Aspen provides £1.6m bridging loan for Barnes luxury conversion

Aspen Bridging has funded a £1.6m heavy refurbishment loan to a Chinese developer undertaking...