Charity Bank Pulls the Plug on Online Services After Third-Party Software Vulnerability Discovered
CAF Bank, the Charities Aid Foundation's banking arm, has taken its online services offline indefinitely after spotting suspicious activity on customer accounts. The bank, which holds deposits for around 14,000 charities, traced the problem to a vulnerability in how third-party software connects to its online banking portal.
The outage started on July 24 and has no confirmed end date. For charities operating on tight margins with minimal admin backup, the timing is brutal. Some organisations have been unable to process payroll.
CEO Alison Taylor issued an apology to customers, confirming that external experts are working on a fix alongside the bank's technology partner. She stressed that the core banking infrastructure is unaffected and customer funds are not at risk. Phone support remains available, with staff told to prioritise time-sensitive payments like wages.
On whether customers will be compensated for the disruption, Taylor declined to answer.
This is not CAF Bank's first public stumble. Last year it drew criticism when a new banking platform rollout left customers locked out of accounts and unable to make payments for an extended period. The bank apologised then too. The fact that a fresh incident has emerged so soon after that migration will raise uncomfortable questions about the robustness of the technology choices being made.
CAF Bank has not disclosed what it spent on the platform. For context, it held £1.45 billion in customer deposits at the close of its 2024/25 financial year. That is real money belonging to organisations that feed people, house the vulnerable, and keep community services running. They deserve better than a second technology crisis in twelve months.