Sector study · scan of 26 September 2026

How UK Banks and Building Societies Look to an External Scan

A September 2026 baseline of 152 websites across the UK’s banks and building societies, scanned from the outside on 26 September 2026 using only what anyone on the internet can see.

22 of 148

have staff passwords on criminal lists (147 records)

0

software weaknesses on the known-exploited list

27

cannot tell mail systems to refuse email forged in their name

77.0

average exact score out of 100

What we found

This is a strong estate by the standards of what we measure, and the list of serious findings is short. Stolen staff passwords are circulating for 22 of the 148 organisations reported, 147 records in total, about seven on a typical affected organisation. That is narrow rather than deep, and each organisation can reset those logins today.

Twenty-seven organisations cannot instruct receiving mail systems to refuse email forged in their name. For a bank or building society that matters more than the number suggests, because a forged message about someone’s own account gets acted on quickly, often by the people least able to absorb a loss.

Four organisations have a database port answering the public internet on an address of their own, among six with some risky port answering. Six more show the same ports only on addresses shared with unrelated organisations, and we report those separately because only the provider can close them. One organisation is named on a ransomware leak site, which is a criminal group’s claim and needs matching to the right entity and date before anyone draws a conclusion.

Five organisations run software whose version number suggests a recorded weakness. We checked every one against the public list of weaknesses criminals are known to be exploiting, and none is on it.

How to read the scores

115 websites have an exact score, averaging 77.0. 33 have a floor score, because they turned an automated visitor away, which is a security control working rather than a fault. Counting those at their floor, the average across all 148 is 73.9. Banks average 76.4 and building societies 78.4 on exact scores. The lists differ in size and composition, so that gap is not a ranking. Four websites produced no usable score and are excluded.

What this is, and what it is not

We looked at each website from the outside, the way any customer could. We did not log in anywhere, try any password or exploit anything. Nothing here means an organisation has been broken into, nothing here is a compliance judgement, and the report names no organisation. Everything inside these organisations, from fraud monitoring to incident response, is invisible from outside and is not assessed.

Where to start

Reset and protect any staff logins found in criminal collections, with multi-factor authentication. Publish an email policy set to refuse or spam-file forged mail. Close or restrict any database or remote-access port answering the internet on your own address.

Read the full report

Download the full report (PDF, 25 pages)Check your own organisation’s domain

This analysis was produced with MyDomainRisk, a product of Huro Data Technologies Ltd, which has a commercial interest in it. It is not independent certification, an audit, or legal or regulatory advice.