On 1 October 2018 the Financial Conduct Authority fined Tesco Bank £16.4 million for failures that allowed a cyber attack in November 2016. Over 48 hours, attackers stole £2.26 million from 9,000 account holders by exploiting weaknesses in the bank's debit card design and financial crime controls.
Tesco Bank refunded every victim in full before the fine landed, so no account holder suffered a permanent loss. The penalty closed the FCA's enforcement action against the bank, a subsidiary of Tesco PLC, the UK's largest retailer.
The FCA found Tesco Bank breached two of its Principles for Businesses. The first demands due skill, care and diligence. The second requires an adequate risk management framework. The regulator called the failings serious and widespread, noting the bank ignored specific warnings about its control gaps before the attack.
The FCA set a base penalty of £23,428,571 and then cut it by 30 percent because Tesco Bank settled early. Without that settlement discount the fine would have been nearly half as large again. The bank paid in full when the FCA published its decision.

How the Attack Worked
The attackers made unauthorized contactless and online payments using stolen debit card credentials. The FCA flagged deficiencies in how Tesco Bank designed and distributed its cards, alongside gaps in its financial crime controls. Together those failures left the bank unable to detect the fraudulent transactions or block them during the 48-hour window.
The FCA did not name the perpetrators or pinpoint the exact technical vulnerability. It said Tesco Bank's platform was not resilient enough to repel a coordinated strike.
The regulator also faulted the bank's incident response: Tesco Bank did not move quickly enough to halt the theft while it was still unfolding, leaving account holders exposed.
Regulatory Findings and the FCA's Rationale
The two breached principles
The enforcement action rested on a breach of two FCA Principles for Businesses. The first obliges firms to act with due skill, care and diligence. The second requires a firm to run its affairs responsibly with an adequate control framework.
Systemic, not one-off
The regulator said Tesco Bank's failings were not isolated. They touched the design of card products, the transaction monitoring toolkit, and the way the bank responded once the attack began. The FCA labelled these systemic rather than the result of a single oversight.
Deterrence drove the penalty
By levying a sharp fine on a significant retail bank, the FCA signaled it expects all institutions to maintain rigorous cyber-fraud defenses. Refunding accountholders did not reduce the penalty. The fine punished the bank's conduct, not the losses individuals suffered.
Customer Impact and Reimbursement
Across 9,000 accounts, £2.26 million was taken through unauthorized contactless and online payments. The fraud required no physical card access and moved entirely through the bank's payment rails.
Tesco Bank repaid every victim in full well ahead of the FCA's October 2018 fine. No cardholder lost money permanently.
The FCA stressed that reimbursement did not erase the bank's failure to secure those accounts. The enforcement focused on conduct rather than outcome, meaning the penalty stood even though no accountholder suffered a net financial loss.
Broader Consequences for Tesco Bank
A landmark fine
The penalty ranked among the largest the FCA had imposed on a retail bank for operational shortcomings at the time. It drew extra attention because Tesco Bank had already repaid victims and cooperated with the investigation. The 30 percent early-settlement discount acknowledged that cooperation, but the headline base penalty stayed high.
Reputation, not balance sheet
Tesco Bank is a subsidiary of Tesco PLC, a business that operated thousands of UK stores at the time. The £16.4 million fine was a sliver of group revenue, yet the reputational cost was heavy. The FCA's public statement detailed the bank's lapses, and UK news outlets covered the case extensively.
Firm punished, not individuals
The FCA did not impose personal sanctions on senior management or the CEO. The action targeted the firm itself. Tesco Bank did not appeal and paid in full. As of October 2018 the matter was closed, and no further enforcement action tied to this incident has been announced since.
Key Facts
- Fine imposed (after 30% settlement discount): £16.4 million, set by the FCA on 1 October 2018
- Base penalty before discount: £23,428,571, a 30% reduction applied for early settlement
- Amount taken: £2.26 million, drawn from customer accounts via unauthorized payments
- Accounts hit: 9,000
- Attack window: 48 hours, November 2016
- FCA fine date: 1 October 2018
- Rules breached: Principle 2 (due skill, care and diligence) and Principle 3 (adequate risk management framework)
- Refunds: Every affected account holder fully reimbursed by Tesco Bank before the penalty
- Regulator: Financial Conduct Authority (FCA)
- Parent group: Tesco PLC
Frequently Asked Questions
Why was Tesco Bank fined £16.4 million?
The FCA fined Tesco Bank for falling short of two FCA Principles for Businesses. The bank's debit card design and distribution lacked adequate security, and its financial crime controls could not spot or stop a coordinated attack that ran across 48 hours in November 2016.
Did customers lose money permanently?
No. Tesco Bank returned the full amount taken to all 9,000 account holders before the fine was imposed. No one suffered a lasting financial loss from the fraud.
How was the fine calculated?
The FCA began with a base penalty of £23,428,571. A 30 percent reduction for early settlement brought the final figure to £16.4 million. For the band and methodology, refer to the FCA's published penalties policy.
What type of fraud was involved?
Attackers used stolen debit card credentials to make unauthorized contactless and online payments. They never needed the physical cards. The fraudulent transactions moved entirely through Tesco Bank's payment infrastructure.
Were any individuals prosecuted?
The FCA did not name the perpetrators or confirm whether anyone was charged. The enforcement action targeted Tesco Bank as a firm, not its employees or executives.








