FCA fines Tesco £16m for cyber breach
This is the first time the FCA has penalised a company for online fraud.
The incident took place in November 2016 when it appears the criminals used an algorithm to generate authentic debit card numbers and then used those ‘virtual cards’ to make unauthorised transactions.
The FCA said the attackers “exploited deficiencies in Tesco Bank’s design of its debit card, its financial crime controls and in its Financial Crime Operations Team”.
As a result, Tesco Bank’s personal current account holders were vulnerable to a “largely avoidable incident” that took place over 48 hours and netted the attackers £2.26 million.
The FCA listed a catalogue of errors, including ignored warnings, but it did not involve the loss or theft of customers’ personal data.

We hope you enjoyed this article.
Research Live is published by MRS.
The Market Research Society (MRS) exists to promote and protect the research sector, showcasing how research delivers impact for businesses and government.
Members of MRS enjoy many benefits including tailoured policy guidance, discounts on training and conferences, and access to member-only content.
For example, there's an archive of winning case studies from over a decade of MRS Awards.
Find out more about the benefits of joining MRS here.
0 Comments