CAF Bank has restored its online banking service after an outage lasting more than 10 days that followed attempted fraud on a small number of accounts and a separate attack designed to remove some users' online logins. The bank said it first detected fraudulent activity on July 21, temporarily suspended online access on July 22 and July 24, and later identified additional malicious activity on July 25. Its investigation found a previously unknown vulnerability in third-party software connected to the online banking portal.
The bank said its core banking systems were not affected and that customer funds remained secure, but warned that online access could remain intermittent as it manages traffic during recovery. The disruption caused concern among charity customers that rely on the bank to pay staff and suppliers, and added to frustration over the reliability of its newer online platform. CAF Bank said it will waive monthly account charges for August and September as a goodwill measure.

See attribution, scope, and your downstream exposure.
7 events from the most recent confirmed update back to the earliest known activity.
CAF Bank said it detected a different kind of malicious activity aimed at removing a small number of individual online user logins and making them unavailable. The bank said it quickly detected the activity and removed access to the online service again.
CAF Bank again temporarily suspended online banking access as its investigation continued. This second suspension followed the earlier withdrawal of service during the fraud response.
While investigating the attempted fraud, CAF Bank temporarily withdrew or suspended access to its online service. The sources explicitly say this happened on July 22 and again on July 24.
CAF Bank said it first detected attempted fraudulent activity affecting a small number of accounts. The bank began investigating the incident with external specialists.
In response to the disruption, CAF Bank said it would waive monthly customer account charges for August and September 2026. The waiver was presented as a goodwill measure for affected customers.
CAF Bank reopened and restored its online banking service after an outage lasting more than ten days. It warned customers that access could remain intermittent during recovery as traffic might need to be limited.
CAF Bank said its investigation identified a previously unknown vulnerability in how some third-party software connects to the online banking portal. The bank also stated that its core banking systems were not affected and customer funds remained secure.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.