Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - Tesco Bank Fraud Attack Suggests Serious Flaws In Bank’s Fraud Prevention Strategy
News & Analysis

Tesco Bank Fraud Attack Suggests Serious Flaws In Bank’s Fraud Prevention Strategy

ISBuzz TeamBy ISBuzz TeamNovember 8, 2016Updated:July 4, 20245 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Handcuffs frame the word 'fraud' among newspaper cuttings
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Following the news that Tesco Bank has been the latest target of a hacking attack, with the bank temporarily suspending all online transactions after thousands of customers were affected. It has been reported that one in three customers of the bank were affected, with several customers tweeting that hundreds of pounds were missing from their bank accounts. IT security experts from Digital Guardian, ACI Worldwide, AlienVault, Synopsys and Prevoty commented below.

Thomas Fischer, Threat Researcher and Security Advocate at Digital Guardian:

Thomas Fischer“The fact that 40,000 cards seem to be affected points less to card fraud executed via skimmers (or similar) and more to a large-scale data leak of the bank’s customers’ card information. Typically, large data leaks are caused by malicious internal parties or malicious external parties that have compromised someone on the inside. In both cases, the insider could also be at a third party supplier. It is therefore important for companies to focus data protection programmes not only on their own infrastructure, but also on third party suppliers.

“The incident serves as a reminder to all organisations to have a good understanding of critical assets (in this case credit card numbers and personal information) and how this information is used across all business units and operations. One way to ensure this is to put in place one consistent data protection policy across all parties that come into contact with these critical assets. This includes auditing third parties to ensure they have equivalent levels of protection.

“It was interesting that the malicious party chose to conduct the fraudulent transactions during the weekend. Traditionally, organisations are under-staffed and are therefore slower to respond during these hours. Businesses should make sure they have the proper detection mechanisms and incident responses processes in place. If the business has a 24×7 operational remit, security processes should be applied systematically at all times of the day, every day of the week.”

Jay Floyd, Head of Fraud Strategy and Solutions EMEA at ACI Worldwide:

Jay Floyd“The fact that Tesco’s fraud prevention systems identified suspicious activity but failed to decline many fraudulent transactions raises serious questions about the bank’s IT systems and fraud prevention capabilities.”

“Compromising 40,000 customer accounts and being able to steal money from half of those accounts suggests that there are serious flaws on the side of the bank and its fraud prevention processes.”

“There are several potential explanations for this attack. It could be a case of internal fraud, where someone with access to the relevant databases has leaked data, or internal team breach, whereby employees working for fraudsters or fraudsters themselves work within call centres and harvest the data over a specific time period. The breach could have also originated via internal offshore operations, in countries with lower fraud prevention processes and employee checks, or it could simply be due to external fraud conducted by hackers.

“An attack like this needs to kick-start a complete review of the bank’s internal fraud prevention strategy. Examining the timing of the fraud will also be key; the fact that the attack happened over the weekend when fraud departments can be thin on the ground, is an important factor which needs to be looked at.”

Javvad Malik, Security Advocate at AlienVault:

Javvad Malik“Judging by the vast scale of this attack it is likely that a main banking system that was compromised. I wouldn’t be surprised if it turns out to be linked to either a compromised third party or an insider.

“Online banking is generally safe enough and fit for purpose. There are improvements being made, with many banks deploying card-reader or one-time-password tokens to customers which are needed to logon or to pay a new account. I say safe enough, because there is compensation, insurance, and other coverage in place. So as long as customers are refunded their money, and the losses remain within the banking fraud appetite, it remains a viable business model.

“One of the biggest challenges banks in the UK have are around legacy software and systems. Many core banking applications run on old architecture build around mainframes. While these are robust systems and do well in crunching the numbers, the added functionality of online banking, faster payments, etc. all has to be ‘bolted on’ – with many systems resembling a Frankenstein architecture. Years of mergers, acquisitions, and divestments have all compounded the issue.”

Mike Ahmadi, Global Director – Critical Systems Security at Synopsys:

mike-ahmadi“Banks are where the money is and remain a prime target.  The financial industry has been dealing with the pallor of fraudulent activities for a long time, and has implemented what is arguably the most organised and effective means of identifying compromise, and disseminating the information to the financial industry and customers.  In this highly technical and digital age the most mature approach is always to assume compromises will happen, and have an effective cybersecurity management plan in place in order to address challenges as they arise.  Despite being a cybersecurity professional, I use online banking and mobile technologies almost exclusively.”

Kunal Anand, CTO and Co-Founder at Prevoty:

kunal-anand“It’s one thing to steal your identity, it’s another thing to steal your money. There is even more pressure on financial services organizations like Tesco to have more controls within their networks, endpoints and applications, including RASP, to monitor and protect against fraud. The raw data from these controls, combined with anomaly detection, could allow organizations to react faster and help reduce overall fraud. Tesco must acknowledge and address the security gap that allowed this attack in the first place.”

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read

Meta’s Smart Glasses Privacy Scandal Expands After Sama Credentials Found on the Dark Web

March 10, 20264 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}