CaixaBank down: what an online banking outage teaches us about digital continuity
Thousands of users reported problems accessing CaixaBank online banking and mobile application. The entity has not communicated that this was a security incident, and the episode leaves a clear lesson for any company: digital continuity is prepared beforehand, not during.

News summary
The fact that CaixaBank went down for a few hours once again brought an uncomfortable reality to the table: when a mass digital service stops responding, there is no improvised plan B that works. Users reported access errors to online banking and the mobile application, and the entity restored the service without communicating that it was a cyberattack. It is worth underlining: without official information, attributing a specific cause is speculation.
What is relevant for a Spanish company is not the technical detail of a specific entity, but the pattern. More and more business processes —payments, reconciliations, payroll, invoicing, customer collections— depend on services we do not control. When one of them stops, the downtime is transferred in full to our operations even if our infrastructure is functioning perfectly.
Seintec analysis is that most organisations have well identified the risk of their own server going down, but not that of a critical third party. There is no maintenance window, no internal SLA, nor a team to call: just waiting. And that waiting costs money when it coincides with a month-end closing, a remittance expiry, or a peak in orders.
The reasonable response is not to stop using external services, but to treat them as what they are: dependencies with a direct impact on the P&L account. That implies knowing which ones they are, how much it hurts for each one to stop, what alternative exists, and who decides to activate it.
In practice, the companies that best manage these episodes share three things: a real inventory of external dependencies, manual contingency procedures agreed with finance and operations, and internal communication prepared so as not to leave teams guessing what is happening.
A downtime of several hours in a major provider is a cheap warning. The question it leaves behind is simple: if the service upon which your billing depends stops tomorrow, how long would it take you to continue working by other means?
Source: El Español — 7 September 2026
What happened
Users reported errors accessing CaixaBank's online banking and mobile app for several hours. The bank restored the service without stating that it was a cyberattack, so there is no official confirmation of the cause. What is verifiable is the unavailability of digital access for a limited period.
The episode fits a wider pattern: more and more business processes at Spanish companies —payments, reconciliations, payroll, collections— depend on digital platforms they don't directly control.
What it teaches a mid-sized business
When a large-scale digital service stops responding, the disruption transfers in full to whoever depends on it, even if their own infrastructure works fine. There's no maintenance window of your own and no internal team to call: only waiting for the provider to restore service.
That wait is especially costly when it coincides with month-end closing, a payment run deadline or an order peak. Most organisations have clearly identified the risk of their own server going down, but not the risk of a critical third party, such as a bank, going down.
What to review
Measures that reduce the impact of an external provider outage:
- A real inventory of external dependencies critical for payments, collections and invoicing.
- A manual contingency procedure for each dependency, agreed with finance and operations.
- Internal communication prepared so teams aren't left guessing during the incident.
- A calculation of what each hour of downtime costs for each dependent service.
Frequently Asked Questions
- Was the CaixaBank outage a cyberattack?
- There is no official confirmation. The bank restored the service without reporting a security incident, so attributing a specific cause would be speculation.
- How can an SME protect itself from an outage at a provider it doesn't control?
- By identifying critical dependencies, defining an alternative procedure for each one and testing it before it's needed.
- How long did the outage last?
- Users reported errors for several hours until the bank restored the service; no exact official duration has been published.
If the downtime of an external service can stop your invoicing, it deserves a plan and not improvisation. At Seintec, we review your critical dependencies and design a realistic continuity and recovery plan for your size. Speak with our team.
Contact SeintecRelated service
Disaster Recovery
Recovery with defined RTO and RPO objectives.