Over the weekend, disruptions to financial transfers plagued dozens of banks, including Capital One, in an episode that highlighted the issues of technical resilience and third-party risks, two matters that regulators have given special attention in recent years.
Capital One and 26 other banks experienced outages starting Wednesday that caused some deposits, payments and transfers to be delayed. Financial services vendor Fidelity Information Services, better known as FIS, said Monday that a power outage initiated the disruption.
FIS provides banking operations and payments services to more than 5,800 companies and processed $12 trillion in 2023. A spokesperson for the fintech said the outage was "due to a local area power loss and a hardware failure" that occurred on Wednesday.
The spokesperson specified that the outage "was not the result of any cyber incident" and that FIS "sincerely apologizes to our clients and their customers who were impacted by this system outage."
The Bank of Oklahoma said in
Social media reaction
The disruptions, especially those affecting Capital One customers, created a social media stir. Customers complained that their direct deposits had not hit their accounts and that they sat on hold for upwards of an hour with customer service representatives.
On Wednesday, day one of the outage, Capital One's customer service account on social media platform X said the bank was dealing with a technical issue with a third-party vendor that was disrupting several services. In an email to customers the next evening, the bank said the outage "delayed processing of some transactions including direct deposits and Early Pay credit for direct deposits, as well as electronic payments and transfers (ACH)."
Two days later, a Friday when many people were expecting their paycheck to be deposited, Down Detector reported that the Capital One outage had generated more than 280,000 reports, with the main issue being problems with deposits.
Capital One customers who couldn't access their paychecks fumed on X. Some got creative with cartoons and GIFs.
Capital One🏦 My Direct Deposit's NOT in my Wallet! 🤨 pic.twitter.com/IYq3ruEPMh
— MamiSpeaks (@mamispeaks) January 17, 2025
Capital One customers who couldn't access their paychecks fumed on X.
all ik is capital one better make sure i got my deposit by the end of today. or else pic.twitter.com/3LDbQjVWgn
— MISS MUTABLE ☿ (@thedollxayla) January 17, 2025
As is often the case, the outage tied up Capital One's customer service representatives.
I think this @CapitalOne issue is larger then they are letting on, been on hold for over an hour and fifteen minutes already #CapitalOneDown pic.twitter.com/eekCsh42xJ
— John Lemp (@duckworth) January 17, 2025
On LinkedIn and X, customers provided links to the web page people could use to complain about Capital One to the Consumer Financial Protection Bureau.
If you have Capital One checking like I do and are affected by the outage, here is the link to file a complaint.https://t.co/FbdzqEYHqt
— John Doe (@Shaka51548586) January 17, 2025
On Sunday, Capital One emailed customers to say that the issue had been resolved and impacted systems had been restored.
"We sincerely apologize for the disruption and any impact on your ability to access certain Capital One services," the company wrote. "We also understand how frustrating this situation may have been, and we're committed to making it right."
Attention to third-party risks and resilience
Regulators both in the U.S. and Europe have called on banks to take greater responsibility for the security and resilience of third-party vendors. As exemplified by the FIS-caused outages over the weekend, a failure at a third party can cascade into failures at multiple other companies, even whole industries.
Last year, a much more visible example that affected multiple industries came in the form of the Crowdstrike outages. In that example, days-long disruptions caused some airlines to delay and cancel flights, some broadcasters to temporarily go off air, and some consumers to report problems logging into their bank accounts or using other digital banking services.
Regulators and lawmakers in recent years have looked to minimize the systemic risks posed by large numbers of banks relying on the same third-party vendors for core banking services such as payments and transfers.
Most recently, in the European Union, the Digital Operational Resilience Act went into effect Friday, implementing rules designed to protect the bloc's financial sector from large-scale failures that might result from cyberattacks or technical outages, such as those that affected Capital One and others over the weekend.
In the U.S., resilience efforts have largely focused on cybersecurity threats rather than technical outages, such as the ones caused last week by FIS, or resilience more generally.
Financial regulators have
Namely, banks and other companies have been waiting on the Cybersecurity and Infrastructure Security Administration (CISA) to issue
Melinda Huspen contributed reporting to this story.