LIVE · cybersecurity feed
Live wire
finance

Charities remain locked out of CAF Bank online accounts

A week into shutdown, 14,000 customers still have no restoration date and some are struggling to pay staff

zeroday.news · 2d ago

CAF Bank's 14,000 UK charity customers remain locked out of their online banking accounts, a week after the service was suspended due to detected attempted fraud. The bank has not provided a timetable for restoring access, leaving many charities unable to make essential payments, including staff payroll and supplier invoices.

The disruption began when CAF Bank identified attempted fraudulent activity on some accounts. In response, the bank quickly suspended online services to prevent further compromise. An ongoing investigation has uncovered a previously unknown vulnerability in the connection between CAF Bank's internal systems and third-party software it utilizes.

CAF Bank has confirmed that its core banking systems are not affected by the issue. Technical teams are reportedly working continuously with suppliers and external experts to develop a secure resolution. However, as of Thursday, July 30, 2026, the bank stated it could not safely restore online services.

The prolonged outage has caused significant distress among the bank's charity clientele. Kevan Hodges, chief executive of the Down's syndrome charity 21 Together, expressed concerns about staff wages not being paid, describing the situation as "appalling." Bali Rodgers, chief executive of Safer Communities Alliance, noted a decline in trust among the grassroots organizations her alliance represents.

CAF Bank CEO Alison Taylor apologized for the disruption earlier in the week, emphasizing the bank's commitment to restoring access only when safety can be assured. The current incident follows a previous period of customer dissatisfaction last year, when the introduction of a new banking platform led to login and transaction issues for users.

At the close of its 2024/25 financial year, CAF Bank held approximately £1.45 billion in customer deposits. The bank has not disclosed the cost associated with the new banking platform introduced last year.

finance
ShareXLinkedInWhatsAppFacebook

More News

view all →
security

Google Chrome may soon block New Tab hijacker extensions by default

Google is preparing a new Chrome security feature that would block policy-installed extensions from hijacking the New Tab page or changing the default search engine. [...]

breach

Week in review: Claude breached three companies during tests, AD CS domain-takeover PoC released

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Nono: Open-source sandbox for AI agents AI coding agents run with the same permissions as their users, meaning they can access sensitive files, credentials, and production systems. A prompt injection, hallucinated command, or simple mistake can quickly turn that access into a security incident. To red

breach

CISA Urges Utilities to Remove Internet-Exposed PLCs After Minnesota Attacks

After attacks hit 30+ Minnesota water systems, CISA urged utilities to remove internet-exposed PLCs and strengthen OT security. Between Sunday and Monday, July 26 and 27, a coordinated cyberattack hit operational technology (OT) systems at more than 30 community water utilities across the state, according to Minnesota IT Services (MNIT). “A coordinated cyberattack targeted operational technology [

security

Atomic MacOS (AMOS) stealer infection, (Sun, Aug 2nd)

Introduction

vulnerability

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. Galaxy Research mapped the sweep and tied it to a firmware flaw in Coldcard, the Bitcoin-only hardware wallet made by Canadian firm Coinkite. A March 2021 firmware integration error routed seed generation to a deterministic software pseudorandom number generator (PRNG

vulnerabilitycritical

Rails patches critical Active Storage flaw with RCE potential

A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE). [...]