← BACK TO FEED
TAG

third party risk5 articles

Charity Bank Pulls the Plug on Online Services After Third-Party Software Vulnerability Discovered

CAF Bank, which serves 14,000 charities and holds £1.45 billion in deposits, has suspended its online banking services since July 24 after discovering a security vulnerability in the connection between third-party software and its online portal, following reports of suspicious activity on some customer accounts. The outage has disrupted organisations' ability to run payroll and other transactions, though the bank says core banking services and customer funds remain safe. CEO Alison Taylor apologised for the disruption and said online access will not be restored until the issue is fully resolved, while the bank continues to handle urgent payments by phone.

29 Jul 2026

Charity Bank Takes Down Online Services After Third-Party Software Flaw Exposed

CAF Bank, which serves 14,000 charities and holds £1.45 billion in deposits, has suspended its online banking services since July 24 after discovering a security vulnerability in how third-party software connects to its banking portal, following reports of suspicious activity on some customer accounts. The outage has caused significant disruption, with some charities unable to process payroll, though the bank insists core banking services and customer funds remain safe. CEO Alison Taylor has apologised for the disruption and says the bank is working with external experts to resolve the issue, while prioritising time-sensitive payments by phone.

29 Jul 2026

EY Breach Exposes Client Tax Data Including SSNs and Card Numbers

Ernst & Young (EY) has begun notifying clients of a data breach involving a third-party service management platform used for tax-related work, with hackers gaining access between March 28 and April 12 after the incident was discovered on April 23. The compromised data includes sensitive personal and financial information such as names, addresses, Social Security numbers, and credit/debit card numbers. EY states it is unaware of any misuse of the data and is offering affected clients two years of free credit monitoring and identity protection services.

20 Jul 2026

AdaptHealth Blames Social Engineering After Patient Data Walks Out the Door

Medical equipment provider AdaptHealth suffered a cyberattack in which criminals used social engineering to compromise a third-party contractor and gain access to the company's cloud systems. Attackers stole sensitive patient data, including personally identifiable information, protected health information, and a password file linked to insurance billing, though Social Security numbers and payment details are believed to be unaffected. AdaptHealth disclosed the breach to the SEC on June 27, deeming it material due to the potential volume of data at risk, while investigations into the full scope of the incident are ongoing.

8 Jul 2026

Why Cyber Resilience Has Swallowed Business Continuity Planning

Modern business disruption increasingly originates from cyber threats such as ransomware, identity compromises, and supplier or cloud failures, making cyber resilience the new foundation of business continuity planning. Effective continuity requires organisations to map critical processes and dependencies, integrate governance, incident response, and supplier management into a unified framework, and ensure systems can recover within agreed timeframes. Crucially, continuity plans must be regularly tested against realistic scenarios to verify they hold up under real pressure, not just on paper.

20 May 2026