Lloyds Banking Group
Incident posture
Linked entities
- Victim
- Lloyds Banking Group
- Threat actors
- 0 actors
- Sources
- 3 sources
Timeline
Summary
Lloyds Banking Group experienced an IT bug caused by a defect in the code used to update its mobile app API, which allowed simultaneous users to view each other’s transaction details. Approximately 447,936 customers may have been exposed to another user’s transactions, with about 114,182 clicking to see details that could include amounts, dates, payment identifiers, National Insurance numbers, sort codes, account numbers, vehicle registration numbers or reference field text. The bank stated that no full account access or unauthorized money movement occurred, balances were unaffected, and it made goodwill payments of roughly £139,000 to around 3,625 affected customers while notifying regulators and cooperating with investigations.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On 12 March 2026, Lloyds Banking Group discovered that an overnight IT change made between 11 and 12 March introduced a software defect in the design of the code used to update the application programming interface (API) used by its mobile banking app. The defect allowed two customers who accessed their accounts simultaneously to view each other’s transaction details. The issue was identified after customers reported seeing unfamiliar transaction information on their screens. Lloyds stated that the problem was resolved at 08:08 on 12 March and has not recurred since.
The bank reported that of its 21.6 million mobile app users, approximately 447,936 customers may have been presented with another user’s transactions or had their own transactions shown to another user, and of those, 114,182 customers may have clicked to view transaction details during the incident. The exposed data included transaction amounts, dates, payment identifiers that could contain National Insurance numbers, and, if a transaction was opened, sort codes, account numbers, National Insurance numbers, vehicle registration numbers and any text entered in the reference field. In some cases the visible information related to individuals who were not Lloyds Banking Group customers, such as when a payment was made to an account at another bank. Lloyds emphasized that customers’ account balances were not affected and that no unauthorized actions or money transfers could be performed on another person’s account. Lloyds added that its assessment indicated it was very unlikely the viewed information could be used to carry out fraudulent activity more widely.
Lloyds notified the relevant financial authorities and the UK Information Commissioner’s Office of the incident and stated it was fully cooperating with any further enquiries. The bank informed its customers about the issue through social media channels and issued an apology saying, “We’re really sorry – the issue was fixed quickly and there’s no action needed. We’re reviewing what happened to make sure it doesn’t happen again.” As a goodwill gesture, Lloyds paid roughly £139,000 (approximately US$183,600) to around 3,625 affected customers for distress and inconvenience. The company said it was reviewing the incident to prevent recurrence.
Sources
Sources available to members: 3 sources.