‘We’re being attacked all the time’: how UK banks stop hackers

A picture


It is every bank boss’s worst nightmare: a panicked phone call informs them a cyber-attack has crippled the IT system, rapidly unleashing chaos across the entire UK financial industry.As household names in other industries, including Marks & Spencer, grapple with the fallout from such hacks, banking executives will be acutely aware that, for them, the stakes are even higher.Within hours of a successful bank hack, millions of direct debits could fail, leaving rents, mortgages and wages unpaid.Online banking may be blocked, cash machine withdrawals denied, and commuters left in limbo as buses and petrol stations reject payments.News of the attack could spark panic, leading to a run on rival lenders, as customers pull money from their accounts amid fear the disruption could spread.

This situation may seem far-fetched but it is not a long way off from the government’s “reasonable worst-case scenario” if a sophisticated cyber-attack hit a big UK bank.With the financial industry among 14 sectors categorised as “critical national infrastructure”, it is no surprise that a hack is listed on the national risk register, which models some of the biggest threats facing the UK.Billions of pounds are being spent preventing the kind of devastating attacks that shut down systems at three retailers, Harrods, the Co-op and M&S, this spring.“The amount of money [that] banks, all of us, will be spending on our systems is enormous today.And it has to be,” the UK chief executive of HSBC, Ian Stuart, told MPs last month.

“We are being attacked all the time.”HSBC alone is having to invest hundreds of millions of pounds to protect itself, Stuart said.“This is our biggest expense.”Globally, banks are expected to allocate 11% of their IT budgets to cybersecurity in 2025, according to an EY study.With those IT budgets forecast to hit $290bn (£214bn) this year, according to the research body Celent, banks could end up shelling out $32bn on cybersecurity by December.

It is a new era for high street banks, as attempted heists evolve from criminals in balaclavas hitting physical branches and vaults to state-sponsored hackers and independent cybergroups looking for ransom payments or merely to cause mass disruption.“Banks have understood the risk far better than probably a lot of other industries.They’ve invested far more in security,” said Stuart McKenzie, a managing director for Mandiant Consulting, a Google-owned cybersecurity company that works closely with a number of lenders in the UK.Last month the governor of the Bank of England told the BBC that cybersecurity was a risk that was never going away because it continually evolved.“We’re dealing with bad actors who will continually refine the lines of attack.

And I always have to say to institutions: ‘You’ve got to continue to work at this,’” Andrew Bailey said.However, protecting systems is a complex task.Most high street banks operate on an onion-like IT system, with layers upon layers of updates, patches and add-ons.Throw third-party software and cloud providers into the mix, and banks are left playing whack-a-mole.“We call it the attack surface,” Alan Woodward, a professor and cybersecurity expert at the University of Surrey, said.

“The attack surface has actually increased, so the opportunities for attackers to try to look for ways in have also increased.”No bank hacks to date have been disruptive enough to bring a country to an economic standstill – although April’s power blackout across the Iberian peninsula exposed how reliant modern societies are on digital payments.Where hackers have been successful, they have more often than not targeted banks’ customer data and accounts.In 2021, attackers on the US bank Morgan Stanley stole personal information belonging to its corporate clients by hacking into a server used by a third-party consulting company.A year earlier, at the start of the Covid pandemic, attackers got hold of staff mailboxes at the Italian state-owned bank Monte dei Paschi, and sent emails to clients with voicemail attachments.

Meanwhile, one of the most devastating hacks on a UK bank came in 2016, when criminals found a way to guess bank card details and steal almost £2.5m from 9,000 accounts at Tesco Bank.Tesco was forced to halt all online and contactless card transactions after struggling to block fake purchases taking place around the world, including Spain and Brazil.Tesco Bank eventually reimbursed customers in full.The National Cyber Security Centre says customers who suspect a hack should contact their bank using their official website or social media channels, and avoid using any links or contact details they have been sent.

The organisation should be able to confirm if a hack has actually taken place, how they have been affected and what they need to do next.The Bank of England has tried to stay a step ahead.Policymakers officially recognised cybersecurity as a risk to financial stability in 2013 and started to implement cyber resilience standards for all regulated banks and insurers under its supervision.Sign up to Business TodayGet set for the working day – we'll point you to all the business news and analysis you need every morningafter newsletter promotionThat involved the launch of “CBEST”, a world-first scheme in which ethical hackers test a single bank’s potential vulnerabilities with a cutting-edge attack.“Nothing is 100% secure,” Woodward said, but the UK banking system comes close.

“A lot of it has to do with the oversight”, particularly by the central bank.“They gather threats and intelligence from MI5, GCHQ, NCSC, all the usual people, and then they actually try real scenarios out to see how robustly a bank can withstand that,” he said.The central bank also coordinates multiday cyberwar games as part of its SIMEX – simulation exercise – programme every two years to test City companies’ security.Authorities are tested, too, and the Bank, the Financial Conduct Authority, the Treasury and the National Cyber Security Centre review their response to a range of devastating scenarios.Regulators are not just checking banks’ preventive measures.

Policymakers assume a cyber-attack will eventually be successful and are therefore pushing banks to prepare their response and recover plans that would avoid long-lasting outages that could bring pockets of the economy to a standstill.The Cross Market Business Continuity Group, which brings together regulators and members of the bank industry body UK Finance, boasts the ability to summon about 100 companies for emergency group calls in under an hour to discuss a potential attack.Fending off a hack is seen as vital to protect an industry that ultimately trades on trust: customers expect lenders to keep their information, wages and life savings protected from outside threats.“If somebody breaks in there and manages to make a fraudulent transaction … you’re not going to trust that bank again with your money, are you?” Woodward said.Banks have already experienced the backlash that can erupt from mere IT outages, without any malicious actors trying to disrupt the banking system or steal data and cash.

TSB has for years been working to restore its reputation after its IT meltdown in 2018, caused by its botched separation from Lloyds’ internal systems, which left millions of banking customers locked out of their accounts for weeks.The lender was subsequently fined £48m for “widespread and serious” failings.Outages have continued to plague customers of Britain’s largest banks and building societies, who suffered the equivalent of more than a month of IT failures between January 2023 and February 2025, according to the data gathered by the parliamentary Treasury committee.“The security of customer money and data is of paramount importance to banks, not just because it’s a requirement under regulation but because it’s the way that banks do business,” Laura Catterick, a director focused on resilience and cybersecurity at UK Finance, said.“I would say, never rule out a cyber-attack.

But I would say, there should be confidence in the amount of cyber defences in place.”
societySee all
A picture

Senior health figure accuses NHS of racism over care given to dying mother

A senior figure in the health service has criticised it for deep-seated racism after his mother “got a black service, not an NHS service” before she died.Victor Adebowale, the chair of the NHS Confederation, claimed his mother Grace’s lung cancer went undiagnosed because black people get “disproportionately poor” health service care.The NHS’s failure to detect her cancer while she was alive shows that patients experience “two different services”, based on the colour of their skin, Adebowale said.His mother, Grace Amoke Owuren Adebowale, a former NHS nurse, died in January aged 92. He highlighted her care and death during his speech this week at the NHS Confederation’s annual conference as an example of “persistent racial inequalities in NHS services”

A picture

People in Australia: tell us your experiences with IVF

After a second embryo implant bungle at Monash IVF, the entire industry is under new scrutiny amid concerns the for-profit model doesn’t always putting families first.Experts worry that clinics might be pushing extra IVF cycles that have little chance of working, and add-on treatments that lack evidence of their efficacy. There are also concerns that people don’t always understand how quickly their chances of a successful pregnancy drop with age.We would like to hear your experiences of IVF. Were you given an accurate idea of your chances of conceiving? Do you feel you were “oversold” extra cycles or non-essential add-ons? How much did you pay and could you afford it? Did Medicare cover part or all of your fee?You can share your experiences with IVF using this form

A picture

MPs back bill changes to prevent medics raising assisted dying with under-18s

Medics would not be allowed to raise assisted dying as an option with under-18s, and advertising it would be banned under changes backed by MPs before a final vote expected next week.The Commons voted on Friday on amendments to the assisted dying bill, which would legalise the option for terminally ill adults in England and Wales who have been told they have fewer than six months to live.The final Commons vote is scheduled for 20 June, with support and opposition finely balanced amid growing scrutiny of timelines, loopholes and who would ultimately deliver the system.A majority of MPs approved a clause tabled by the Labour MP Meg Hillier, an opponent of the bill, to ensure health professionals cannot raise the topic of assisted dying with under-18s.A separate amendment from Hillier to bar health workers from raising the option with adult patients before they have brought it up themselves was voted down

A picture

Resident doctors have good reason to strike over pay | Letters

I write in response to the letter from senior clinicians urging resident doctors to vote against strike action (8 June). During my 22-year career we have seen fundamental changes in medical training, including the introduction of tuition fees for medical school, loss of free accommodation for first-year doctors, the lack of expansion in training numbers, and pay erosion over 15 years.This has left many resident doctors with crippling debt on graduation, spiralling costs of training, deteriorating pay, and the prospect of unemployment. I, and the authors of the letter, were fortunate enough not to face such hardships during training.Hence I urge colleagues not to influence the negotiations between the British Medical Association (BMA) and the government regarding resident doctors’ pay

A picture

Suman Fernando obituary

My friend and colleague Suman Fernando, who has died aged 92, had an international reputation in the field of critical psychiatry, particularly in relation to advocating for race equity in mental health.As well as being a consultant psychiatrist in the NHS for more than 20 years, Suman wrote 14 books and many articles in which he consistently and methodically challenged institutional racism in British mental health provision.In his first book, Race and Culture in Society (1988), he explored the role that race and culture play in how people experience mental health issues and services. In his breakthrough 1991 book, Mental Health, Race and Culture, he challenged the dominance and singularity of the medical model, and argued that any service response for minority communities should also focus on social, cultural and institutional issues.Suman often juxtaposed the western, individualised notion of mental illness with those of the global south or indigenous healing systems that see fragmentation of community cohesion as causal, with responses that are more spiritual and community-based

A picture

Robert Tollemache obituary

My father, Robert Tollemache, who has died aged 88, was a well-respected psychotherapist, best known for his work at the Open Door young people’s mental health charity, the Inner City Centre psychotherapy service and the medical foundation Freedom from Torture.He completed his training at the Lincoln Clinic and Centre for Psychotherapy in 1985, and for 40 years maintained a private practice in Highbury, north London. Alongside his clinical work, he campaigned tirelessly to raise awareness on environmental issues, completing a PhD, aged 79, on climate change denial. He was still working for the Islington Climate Centre weeks before his death.Born at the Royal Marines barracks in Plymouth, Robert was the youngest of the four children of Nora (nee Taylor) and Maj Gen Sir Humphry Tollemache