Charities remain locked out of CAF Bank online accounts
- ID
- 9656
- Status
- summarized
- Published
- 31 Jul 2026, 9:55 PM
- Fetched
- 31 Jul 2026, 10:54 PM
- Provider
- The Register
- Category
- technology
- Original URL
- https://www.theregister.com/security/2026/07/31/charities-remain-locked-out-of-caf-bank-online-accounts/5281711
- Source URL
- https://www.theregister.com/headlines.atom
Summary
- Score
- 3.5
- Created
- 31 Jul 2026, 10:56 PM
- Tags
- Audience
- developerssaas_founders
What happened
CAF Bank has suspended online banking for a week with no restoration date, leaving 14,000 UK charity customers unable to process payments including payroll. The bank detected attempted fraud and found a previously unknown vulnerability in the connection between its systems and third-party software, but has not disclosed technical details of the flaw or a fix timeline.
Why it matters
For builders integrating third-party software into payment or banking systems, this is a concrete reminder that a single unknown integration vulnerability can take down an entire customer-facing service for over a week with no recovery date. If you operate SaaS or fintech infrastructure in Malaysia, review your third-party connection points and have an incident response plan that includes a communication protocol for extended outages—CAF Bank's vague updates are eroding customer trust.
Discussion angle
How would you communicate a week-long outage to customers when you genuinely don't know when the fix will land—and what architectural choices (e.g., isolating third-party integrations behind circuit breakers) could have contained this?