UK bank suspends online payments after fraud hits 20,000 accounts

Almost one in three of Tesco Bank's checking accounts saw suspicious transactions

The banking arm of U.K. supermarket chain Tesco has suspended online payments for its 136,000 checking account customers following a spate of fraudulent transactions.

The bank suspended its payment service for all checking account customers after 40,000 experienced suspicious transactions, bank CEO Benny Higgins told BBC Radio 4 on Monday.

"Around half of them had money taken from the account," he said.

The bank will bear any losses as a result of the fraudulent activity and customers are not at financial risk, he said.

But they might be inconvenienced until the bank has secured its systems.

"We are stopping online transactions until we can bring things back under full control," Higgins said.

Customers will still be able to use the online banking service and make card payments in stores, he said.

The bank began sending text messages to customers on Sunday, alerting them to the problem and inviting them to call for further information. However, the bank's call center was quickly overwhelmed, to judge by reaction to the bank's blog posting about the incident. Many commenters reported that their calls had gone unanswered.

The U.K.'s National Crime Agency, which hosts the country's national cybercrime unit, said it is coordinating law enforcement response to what it described as "the Tesco Bank data breach."

The Information Commissioner's Office, the U.K.'s data protection authority, is aware of the incident and is looking into the details, a representative said.

The cause of the incident is unclear.

Tesco Bank referred to "online criminal activity" and "fraud" in a statement about the incident, but did not use the word "hack" in relation to the missing funds.

The bank uses the 3D Secure standard, also known as Verified by Visa or MasterCard SecureCode, to authenticate online payments. This requires customers to provide a password other than their four-digit PIN or the three-digit CVV printed on the reverse of their cards in order to complete online payments.

The losses could be due to a compromise of Tesco Bank's online banking system, or a malware infection on bank clients' PCs or mobile devices, spread through targeted spear-phishing attacks or a social engineering campaign, suggested Ilia Kolochenko, CEO of web security company, High-Tech Bridge.

"A massive skimming campaign cannot be excluded either," he said via email, referring to the possibility that criminals had obtained customers' bank card details and PINs when they used a rogue ATM or payment terminal.

Join the newsletter!

Error: Please check your email address.
Rocket to Success - Your 10 Tips for Smarter ERP System Selection
Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Peter Sayer

IDG News Service
Show Comments



Sansai 6-Outlet Power Board + 4-Port USB Charging Station

Learn more >



Back To Business Guide

Click for more ›

Most Popular Reviews

Latest Articles


PCW Evaluation Team

Louise Coady

Brother MFC-L9570CDW Multifunction Printer

The printer was convenient, produced clear and vibrant images and was very easy to use

Edwina Hargreaves

WD My Cloud Home

I would recommend this device for families and small businesses who want one safe place to store all their important digital content and a way to easily share it with friends, family, business partners, or customers.

Walid Mikhael

Brother QL-820NWB Professional Label Printer

It’s easy to set up, it’s compact and quiet when printing and to top if off, the print quality is excellent. This is hands down the best printer I’ve used for printing labels.

Ben Ramsden

Sharp PN-40TC1 Huddle Board

Brainstorming, innovation, problem solving, and negotiation have all become much more productive and valuable if people can easily collaborate in real time with minimal friction.

Sarah Ieroianni

Brother QL-820NWB Professional Label Printer

The print quality also does not disappoint, it’s clear, bold, doesn’t smudge and the text is perfectly sized.

Ratchada Dunn

Sharp PN-40TC1 Huddle Board

The Huddle Board’s built in program; Sharp Touch Viewing software allows us to easily manipulate and edit our documents (jpegs and PDFs) all at the same time on the dashboard.

Featured Content

Product Launch Showcase

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?