Advertisement
SecurityDeveloping Story

CAF Bank Shuts Online Portal After Breach

A critical third-party software flaw forces the charity-focused bank to suspend digital access for 14,000 organizations.

··1 hour ago·2 min read
A padlock and dollar bills rest on a computer keyboard.
Photo by Sasun Bughdaryan on Unsplash
Advertisement

CAF Bank has taken its online banking platform offline following the discovery of a vulnerability within the software used to link external applications to its portal. The disruption, which began on July 24, has impacted 14,000 organizations that rely on the institution for financial management.

Third-Party Software Vulnerability Discovered

The bank confirmed that the decision to suspend services followed the identification of suspicious activity on select customer accounts. Internal security teams detected the issue early and notified affected users of attempted fraud. A subsequent investigation pinpointed a previously undetected vulnerability located in the interface between the bank’s portal and integrated third-party software.

While the bank maintains that its core services remain secure, the necessity of patching this connection has forced a total blackout of online banking functions. The organization is currently working with an undisclosed technology partner to implement a fix before restoring public access.

Impact on Charitable Payroll

The outage has created significant operational challenges for many charities, particularly those attempting to process time-sensitive payroll transactions. While the bank is offering support via telephone, the shift from automated digital processes to manual intervention has caused frustration among clients.

We have informed CAF Bank customers that the online banking service will be unavailable until further notice. I am very sorry for the disruption and understand the frustration this can cause for our customers. We are working with external experts to fix an issue we identified with third-party software related to our online banking portal. The core bank is not affected. We are acutely aware of the impact this has on our customers and want this to be fixed as soon as possible, but we cannot restore access to the online service until we are assured the issue is safely resolved.

— Alison Taylor, CEO at CAF Bank

Financial Scale and Past Issues

This incident follows previous service instability at the institution. In 2025, CAF Bank came under fire from customers during a transition to a new banking platform, which resulted in login failures and transaction delays. Regarding the current situation, the bank has not provided details on potential compensation for affected customers.

  • 14,000: The number of organizations impacted by the service suspension.
  • July 24: The date when online banking services were officially taken offline.
  • £1.45 billion: The total amount of customer deposits held by the bank at the end of the 2024/25 financial year.

Risk Management Implications

For organizations, this incident highlights the risks inherent in deep integration with third-party software providers. When a dependency within a banking portal is compromised, the reliance on automated workflows can become a liability, forcing users to rely on manual, phone-based workarounds. Businesses should consider the necessity of maintaining manual contingency plans for critical financial operations, as the technical security of a primary platform remains contingent upon the integrity of all connected third-party components.

#banking#cybersecurity#data-breach#third-party-risk

Sources

Xploitwire Editorial Team

Xploitwire Newsroom

This article's narrative text was drafted by AI (Google Gemini) from the sources listed above, and passed through our automated fact-check gate before publication. It has not been individually reviewed by a human editor prior to going live. Our AI Policy →

← Back to all stories
Advertisement