Back Print this page
CompliNEWS   |   Financial Service Intelligence Watch Saturday 04 May 2024

Tesco Bank fined £16.4 million for cyber-security failings

The UK's Financial Conduct Authority (FCA) announced at the start of November 2018 that it had fined Tesco Bank £16.4 million for a cyber-attack that occurred exactly two years ago.

ReedSmith's article notes that in November 2016, 8,261 personal current accounts at Tesco Bank were compromised. Attackers obtained customers’ debit card details and entered into thousands of unauthorised transactions.

This is the first cyber-attack-related fine to be imposed on a UK bank by the FCA. The fine was reduced from the initial draft penalty of £23.5 million on the basis that Tesco Bank agreed to settle at an early stage, to be cooperative, and to compensate customers.

The FCA set out its findings and enforcement action in its Final Notice dated 1 October 2018.

The fine was issued on the basis that Tesco Bank breached the FCA’s Second Business Principle, which provides that a firm must conduct its business with due skill, care and diligence.

The FCA criticised Tesco Bank, saying that the cyber-attack was 'largely avoidable'. The failings of Tesco Bank to conduct its business with due skill, care and diligence included:

  • issuing debit cards with sequential card numbers, meaning that hackers could more easily work out details of active cards;
  • configuring its authorisation system to check only that a card’s expiry date was in the future, and not that the date was correct;
  • taking action to block the specific type of fraudulent transaction for its credit cards, but failing to do the same for its debit cards; and
  • not responding to the attack with sufficient 'rigour, skill and urgency'.

This is because Tesco Bank ineffectively contacted its fraud strategy team – contrary to procedure, used an incorrect code to block the unauthorised transactions, and failed to monitor the rule’s operation and therefore notice that the code was not working properly. The Final Notice concludes by acknowledging that Tesco Bank’s cyber-crime framework was appropriate but that it was, in fact, individuals within the bank who had failed to exercise the required due skill, care and diligence.

Tesco Bank has since changed its issuing practice and no longer issues cards with sequential card numbers. It has also changed its authorisation system, and now checks that the expiry date is correct.