Full Report
Customers told traffic may be limited at certain times following more than ten days offline
Analysis Summary
# Incident Report: CAF Bank Multi-Stage Online Service Disruption
## Executive Summary
CAF Bank, a subsidiary of the Charities Aid Foundation, experienced a prolonged outage of its online banking platform lasting over ten days following a series of cyber attacks. The incident involved initial fraud attempts followed by a targeted attack on user logins leveraging a previously unknown third-party software vulnerability. While core banking systems and funds remained secure, the operational impact on charity clients was severe, leading to fee waivers and manual traffic throttling during recovery.
## Incident Details
- **Discovery Date:** July 21, 2026
- **Incident Date:** July 21, 2026 – August 4, 2026
- **Affected Organization:** CAF Bank
- **Sector:** Financial Services (Non-profit/Charity Banking)
- **Geography:** United Kingdom
## Timeline of Events
### Initial Access
- **Date/Time:** July 21, 2026
- **Vector:** Unknown (Described as "attempted fraudulent activity")
- **Details:** Bank identified suspicious activity targeting a small number of accounts.
### Lateral Movement / Secondary Attack
- **Date:** July 25, 2026
- **Details:** Attackers pivoted to a "malicious activity of a different kind" using a zero-day vulnerability in third-party software connecting to the banking portal. This stage aimed at removing/disabling specific user logins.
### Data Exfiltration/Impact
- **Details:** No evidence of mass data exfiltration or loss of funds reported. Impact was primarily "Availability" (Denial of Service) through the removal of login credentials and subsequent emergency system shutdowns.
### Detection & Response
- **July 21:** Initial fraud detected.
- **July 22 & 24:** Bank voluntarily withdrew online access for investigation.
- **July 25:** New malicious activity detected; portal shuttered again.
- **July 26 – Aug 3:** Systems remained offline for "essential work" with third-party specialists.
- **August 4:** Service restored with warnings of intermittent availability and traffic limiting.
## Attack Methodology
- **Initial Access:** Fraudulent activity targeting individual accounts.
- **Persistence:** Not explicitly disclosed; likely maintained via the identified third-party vulnerability.
- **Discovery:** Exploitation of a "previously unknown vulnerability" (Zero-day) in third-party software integration.
- **Lateral Movement:** Transition from account-level fraud to portal-wide login manipulation.
- **Impact:** System exhaustion/Availability loss. Attackers targeted the availability of specific online user logins.
## Impact Assessment
- **Financial:** Monthly account charges (£5/month) waived for all customers for two months (August/September 2026).
- **Data Breach:** Limited to a "small number of individual online user logins."
- **Operational:** Total loss of online banking for 10+ days; significant strain on call centers; inability for charities to pay staff/suppliers.
- **Reputational:** High; significant criticism from the charity sector following a recent, reportedly "unreliable" platform migration to Temenos Transact.
## Indicators of Compromise
- **Behavioral indicators:** Unusual login failures; unauthorized deletion/modification of user account profiles; high traffic/connection errors originating from third-party software hooks.
## Response Actions
- **Containment:** Intentional shutdown of the online banking portal on multiple dates (July 22, 24, and 25).
- **Eradication:** Identification and patching of a previously unknown vulnerability in third-party software.
- **Recovery:** Gradual restoration of services with "traffic limiting" (throttling) to manage load and monitor for stability.
- **Compensatory:** Waiving of customer fees for two months.
## Lessons Learned
- **Third-Party Risk:** Vulnerabilities in middle-ware or third-party integrations can bypass core banking security and disable access to the entire platform.
- **Platform Migration Stability:** The incident occurred shortly after a migration to a new platform, suggesting that new system architectures may have introduced or exposed unforeseen attack vectors.
- **Communication Gaps:** Customers reported frustration with phone delays, highlighting the need for better-scaled support during digital outages.
## Recommendations
- **Third-Party Audit:** Conduct a comprehensive security audit of all third-party software components and APIs connecting to the banking portal.
- **DDoS/Traffic Management:** Implement robust rate-limiting and traffic scrubbing to prevent malicious attempts to "remove" or lock logins at scale.
- **Business Continuity:** Develop "offline" emergency payment procedures for charity clients to ensure payroll can be met during extended portal outages.
- **Vulnerability Management:** Enhance "Zero-day" detection capabilities through behavior-based monitoring rather than signature-based detection.