<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic UK: FCA fines Tesco Bank £16.4m for failures in 2016 cyber attack in Industry News</title>
    <link>https://community.isc2.org/t5/Industry-News/UK-FCA-fines-Tesco-Bank-16-4m-for-failures-in-2016-cyber-attack/m-p/15121#M1649</link>
    <description>&lt;P&gt;&lt;SPAN&gt;The Financial Conduct Authority (FCA) has fined Tesco Personal Finance plc (Tesco Bank) £16,400,000 for failing to exercise due skill, care and diligence in protecting its personal current account holders against a cyber attack.&amp;nbsp;The cyber attack took place in November 2016.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Cyber attackers exploited deficiencies in Tesco Bank’s design of its debit card, its financial crime controls and in its Financial Crime Operations Team to carry out the attack.&amp;nbsp;Those deficiencies left Tesco Bank’s personal current account holders vulnerable to a largely avoidable incident that occurred over 48 hours and which netted the cyber attackers £2.26m.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The FCA found that Tesco Bank failed to exercise due skill, care and diligence to:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Design and distribute its debit card.&lt;/LI&gt;&lt;LI&gt;Configure specific authentication and fraud detection rules.&lt;/LI&gt;&lt;LI&gt;Take appropriate action to prevent the foreseeable risk of fraud.&lt;/LI&gt;&lt;LI&gt;Respond to the November 2016 cyber attack with sufficient rigour, skill and urgency.&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;for more read the &lt;A href="https://www.fca.org.uk/news/press-releases/fca-fines-tesco-bank-failures-2016-cyber-attack" target="_self"&gt;FCA Press Release&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 09 Oct 2023 08:58:04 GMT</pubDate>
    <dc:creator>leroux</dc:creator>
    <dc:date>2023-10-09T08:58:04Z</dc:date>
    <item>
      <title>UK: FCA fines Tesco Bank £16.4m for failures in 2016 cyber attack</title>
      <link>https://community.isc2.org/t5/Industry-News/UK-FCA-fines-Tesco-Bank-16-4m-for-failures-in-2016-cyber-attack/m-p/15121#M1649</link>
      <description>&lt;P&gt;&lt;SPAN&gt;The Financial Conduct Authority (FCA) has fined Tesco Personal Finance plc (Tesco Bank) £16,400,000 for failing to exercise due skill, care and diligence in protecting its personal current account holders against a cyber attack.&amp;nbsp;The cyber attack took place in November 2016.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Cyber attackers exploited deficiencies in Tesco Bank’s design of its debit card, its financial crime controls and in its Financial Crime Operations Team to carry out the attack.&amp;nbsp;Those deficiencies left Tesco Bank’s personal current account holders vulnerable to a largely avoidable incident that occurred over 48 hours and which netted the cyber attackers £2.26m.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The FCA found that Tesco Bank failed to exercise due skill, care and diligence to:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Design and distribute its debit card.&lt;/LI&gt;&lt;LI&gt;Configure specific authentication and fraud detection rules.&lt;/LI&gt;&lt;LI&gt;Take appropriate action to prevent the foreseeable risk of fraud.&lt;/LI&gt;&lt;LI&gt;Respond to the November 2016 cyber attack with sufficient rigour, skill and urgency.&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;for more read the &lt;A href="https://www.fca.org.uk/news/press-releases/fca-fines-tesco-bank-failures-2016-cyber-attack" target="_self"&gt;FCA Press Release&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 08:58:04 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/UK-FCA-fines-Tesco-Bank-16-4m-for-failures-in-2016-cyber-attack/m-p/15121#M1649</guid>
      <dc:creator>leroux</dc:creator>
      <dc:date>2023-10-09T08:58:04Z</dc:date>
    </item>
  </channel>
</rss>

