VYPR
breachPublished Jul 28, 2026· Updated Aug 4, 2026· 3 sources

CAF Bank Halts Online Services Over Third-Party Software Vulnerability

CAF Bank has suspended online banking services due to a flaw in third-party software integration, impacting charities' ability to access accounts and process payments.

CAF Bank, a financial institution serving approximately 14,000 charities, has been forced to suspend its online banking services following the discovery of a vulnerability within its third-party software integration. The outage, which began on July 24, has significantly disrupted operations for its charitable clients, many of whom rely on the platform for essential functions such as payroll processing and account management.

The bank, owned by the Charities Aid Foundation, confirmed the ongoing unavailability of its online portal in a message to customers, stating that services would remain offline until further notice. This decision was prompted by reports of suspicious activity observed on some customer accounts. CAF Bank indicated that it detected the issue early and proactively notified affected customers about any attempted fraudulent transactions.

Following an internal investigation, CAF Bank identified an undisclosed vulnerability concerning the connection between external software and its online banking portal. The bank is currently collaborating with its technology partner to develop and implement a fix for the identified flaw. While the core banking infrastructure remains unaffected and customer funds are secure, the bank is undertaking necessary modifications to its online service to ensure its integrity.

In a statement, CEO Alison Taylor expressed her apologies for the disruption, acknowledging the frustration caused to customers. "We are working with external experts to fix an issue we identified with third-party software related to our online banking portal," Taylor stated. "The core bank is not affected. We are acutely aware of the impact this has on our customers and want this to be fixed as soon as possible, but we cannot restore access to the online service until we are assured the issue is safely resolved."

Taylor further assured customers that the bank could still provide support via telephone and was prioritizing time-sensitive transactions, including payroll. When questioned about potential compensation for affected clients, she declined to comment. This incident echoes past difficulties CAF Bank faced last year when a new banking platform launch led to widespread login and transaction issues, for which the bank later issued an apology.

The bank has not disclosed the financial investment made in its platform, but it reported holding £1.45 billion ($1.93 billion) in customer deposits at the close of its 2024/25 financial year. The current outage highlights the critical importance of robust security for third-party integrations, as vulnerabilities in these components can have far-reaching consequences for even well-established financial institutions and their client base.

CAF Bank has confirmed that there is still no estimated time for restoring online banking services to its 14,000 charity customers. The bank reiterated that the outage was triggered by an unknown vulnerability discovered in its connection to third-party software after detecting attempted fraud. While the bank's technical teams are working with external experts to resolve the issue, the disruption continues to impact charities' ability to make essential payments, with some reporting significant difficulties with payroll and supplier payments.

CAF Bank has informed customers that its online banking services have been restored after more than ten days of disruption. The bank is warning that access may remain intermittent and that it might need to limit traffic during peak times. This latest update also details the timeline of the incident, noting that the bank first detected attempted fraudulent activity on July 21st, leading to temporary service withdrawals on July 22nd and 24th for investigation. A subsequent, related malicious activity on July 25th targeted user logins, prompting further service removal while a previously unknown vulnerability in third-party software was identified.

Synthesized by Vypr AI
CAF Bank Halts Online Services Over Third-Party Software Vulnerability · VYPR