CAF Bank Stalls on Online Restoration
Thousands of UK charities face payroll delays as CAF Bank remains offline a week after detecting a third-party security flaw.
A week has passed since CAF Bank suspended its online portal, leaving 14,000 customers without access to digital financial management tools. The ongoing outage has triggered significant operational hurdles for numerous organizations that rely on the platform to issue payments to staff and essential suppliers.
Unknown Vulnerability Halts Banking
The disruption stems from an investigation into attempted fraud flagged on a selection of customer accounts. Upon reviewing its infrastructure, the bank identified a previously unknown vulnerability residing within the connection between its internal systems and third-party software components.
Technical teams are reportedly collaborating with external security experts and suppliers to patch the security gap. However, the bank maintains that it cannot re-enable online services until it receives full assurance that the environment is secure.
Impacts on Charity Operations
The absence of online banking services has forced many organizations to scramble for alternatives to manage recurring expenses. The situation has drawn sharp criticism from charity leaders who report difficulty reaching bank representatives to address time-sensitive financial obligations.
The core bank is not affected. We are acutely aware of the impact this has on our customers and want this to be fixed as soon as possible, but we cannot restore access to the online service until we are assured the issue is safely resolved.
— Alison Taylor, CEO at CAF Bank
- 14,000 UK charity customers affected by the outage.
- 1 week elapsed since the online banking suspension began.
- £1.45 billion held in customer deposits as of the 2024/25 financial year.
- $1.93 billion total in customer deposits at the end of the 2024/25 financial year.
Consequences for Affected Clients
For the non-profit sector, prolonged lack of access to digital banking can translate into direct administrative costs and potential reputational damage if payroll or vendor payments are missed. This incident highlights the concentration risk inherent in relying on specific third-party software integrations for core financial operations. As organizations await a restoration timeline, the reliance on manual workarounds may continue to strain resources, suggesting that digital dependency remains a critical point of failure for institutions holding significant customer deposits.
Sources
- The Register Original source
Continue Reading
AI Labs Compete Over Rogue Agent Claims
Anthropic and OpenAI trade narratives of accidental sandbox escapes, raising questions about the safety of their frontier models.
GitLab Critical Flaw Allows Unauthenticated Project Deletion
A critical GitLab vulnerability could let unauthenticated attackers modify or delete public projects and user data.
Apple's WebKit Patch Wave Hits 28 Flaws
Apple ships 28-security-fix updates for macOS and iOS, covering two dozen WebKit bugs.