2026 Lloyds Banking Group — faulty mobile update; ~450K customers’ transaction data exposed to other users
Data compromised
Other customers’ mobile-visible transaction and account-display data (varies by session); not a reported download of Lloyds’ central database by an external actor
Technical writeup
On March 12, 2026, Lloyds Banking Group (Lloyds Bank, Halifax, Bank of Scotland) experienced a serious but non-ransomware IT incident: an overnight software/API change introduced a defect that broke isolation between customer accounts in mobile banking, so some users briefly saw other customers’ transactions and related on-screen details (e.g., names, postcodes, salaries, benefit payments, and in some reports sort codes, account fragments, or national insurance numbers) when viewing transaction lists. Parliamentary and press summaries later cited on the order of ~447,936–450,000 customers affected across the incident window (e.g., ~03:28–08:08 GMT in some accounts), with a subset clicking through to detailed transaction views—not “millions” of users at the scale suggested in some informal social reframes. Lloyds attributed the issue to its own change (not an external cyberattack), resolved it the same morning, and faced FCA/ICO scrutiny. Treat as a confidentiality/privacy incident (cross-customer visibility) rather than a classic centralized database exfiltration.
Root cause
Faulty software/API update in mobile banking channel (internal change defect)
References
- https://www.reuters.com/sustainability/boards-policy-regulation/nearly-half-million-customers-hit-by-lloyds-it-glitch-that-exposed-transaction-2026-03-27/
- https://www.bbc.com/news/articles/c70dqk2vjv8o
- https://www.reuters.com/business/finance/britains-lloyds-apologises-after-customers-able-see-others-transactions-2026-03-12/
- https://www.theregister.com/2026/03/27/lloyds_app_glitch_turned_transactions/
- https://www.theregister.com/2026/03/12/lloyds_banking_group_glitch/
- https://www.bbc.com/news/articles/c4g23npxpwgo