Tesco Bank Suffer The Largest Ever FCA Fine For Cyber Attack

16 November 2018by Abdallah Alhajeid

Tesco Personal Finance plc (Tesco Bank) has been fined £16,400,000 by the Financial Conduct Authority (FCA) for failing to exercise due skill, care and diligence in protecting its personal current account holders against a cyber attack in 2016.

 

Deficient cyber security controls

On the 1st October, the FCA announced that in 2016, cyber attackers exploited deficiencies in Tesco Bank’s design of its debit card, its financial crime controls and in its Financial Crime Operations Team response to the attack. These deficiencies left Tesco Bank’s personal current account holders vulnerable to a largely avoidable incident that occurred over 48 hours and which netted the cyber attackers £2.26m.

Mark Steward, Executive Director of Enforcement and Market Oversight at the FCA, said:

“The fine the FCA imposed on Tesco Bank today reflects the fact that the FCA has no tolerance for banks that fail to protect customers from foreseeable risks. In this case, the attack was the subject of a very specific warning that Tesco Bank did not properly address until after the attack started. This was too little, too late. Customers should not have been exposed to the risk at all.

‘Banks must ensure that their financial crime systems and the individuals who design and operate them work to substantially reduce the risk of such attacks occurring in the first place. The standard is one of resilience, reducing the risk of a successful cyber attack occurring in the first place, not only reacting to an attack. Subsequently, Tesco Bank has strengthened its controls with the object of preventing this type of incident from being repeated.”

Tesco Bank confirmed that the attack did not involve the theft or loss of any customers data but did lead to transactions in which funds were debited from accounts, and other customers having their normal service disrupted.

 

Anatomy of the cyber attack

As reported in The Register, Tesco Bank called on the National Cyber Security Centre (NCSC) to probe the attack on the 5th November 2016 that ultimately saw a total of £2.26m stolen from 9,000 customer accounts over 48 hours. Tesco had been forced to suspend online and contactless transactions in the immediate aftermath of the breach as it probed the root cause.

Tesco Bank had received a fraud alert from Visa earlier in November 2015, roughly a year before the attack, about fraudulent transactions like the one that eventually hit their business.

The exact technical details of the attack have not been revealed. The Register believes that cyber criminals most likely employed an algorithm that generated authentic debit card numbers, and these “virtual” cards were then used for unauthorised transactions. The FCA confirmed that the hackers took advantage of deficiencies in the “design” and “distribution” of Tesco’s debit card. It also highlighted other failings including the way the bank configured specific authentication and employed fraud detection rules. It is unclear if this information was acquired by cyber criminals  ‘breaking in’ to Tesco Bank or simply by the fraudulent use of information that was already in the public domain.

 

Slow response and inadequate cyber readiness

The FCA also criticised Tesco Bank for failing to “take appropriate action to prevent the foreseeable risk of fraud” and for failing to “respond to the… cyber attack with sufficient rigour, skill and urgency”. It is known that Tesco Bank’s financial crime operations team emailed the fraud strategy inbox rather than phoning the on-call Fraud Strategy Team as required by internal regulations. It took over 21 hours for the two teams to make contact and nothing was done in the interim to halt the attack.

 

Not just a large fine

While the punitive regulatory action was expected, the size of the FCA fine has sent a shock-wave around the UK financial service community. Top UK law firm, Eversheds Sutherland provides a timely briefing on the cyber risk of regulatory enforcement action in their contribution to The Lawyer Nov 2018. They also outline the considerable additional risks of litigation, reputational damage and loss of customers. There is no doubt that Tesco Bank has and will experience the pain of the effects of the very damaging 2016 cyber attack for some time to come.

Abdallah Alhajeid

WordPress Developer

WIZARD CYBER
Headquarters
Providing enterprises with bespoke & powerful managed solutions to protect against all forms of cybercrime
OUR LOCATIONS
Where to find us?
world map
GET IN TOUCH
Latest Updates
Stay up to date with the latest news from Wizard Cyber and the cybersecurity industry
https://wizardcyber.com/wp-content/uploads/2026/04/ISO-QSL-Cert-ISO-27001-scaled.png
https://wizardcyber.com/wp-content/uploads/2026/04/ISO-QSL-Cert-ISO-9001-scaled.png
WIZARD CYBER
Headquarters
Providing enterprises with bespoke & powerful managed solutions to protect against all forms of cybercrime
OUR LOCATIONS
Where to find us?
world map
GET IN TOUCH
Latest Updates
Stay up to date with the latest news from Wizard Cyber and the cybersecurity industry

Copyright by Wizard Cyber. All rights reserved.

Copyright by Wizard Cyber. All rights reserved.

Contact Us
×
Contact Us
Need Cybersecurity Guidance? Get in touch with us!

Our experts are ready to help with your cybersecurity questions—book a conversation with us by clicking the button.

Book a Meeting
Funded Workshops
×
Funded Workshops
Explore Our Funded Microsoft Security Workshops

Click to learn more about each Microsoft-supported engagement

Book a Consultation