Lloyds Banking Group has admitted that a software defect during an IT update to its mobile banking apps on 12 March exposed the personal data of up to 447,936 customers. The glitch, which affected Lloyds, Halifax and Bank of Scotland apps, potentially allowed users to view payments, account details and national insurance numbers of others for brief moments.
According to a letter published by the Treasury select committee, about 114,182 customers clicked into transactions revealing private information. The bank stated that customers would have needed to be looking at their app within fractions of a second of other users to access details. Even non-customers may have had transaction details exposed.
Lloyds reported the incident to the Financial Conduct Authority on the same morning and notified the Information Commissioner’s Office within 72 hours. The bank has paid £139,000 in compensation to 3,625 customers for distress, but no financial losses have been reported. Chief executive Jasjyot Singh urged any customers who screenshotted or recorded data to delete it, adding there is no evidence of misuse so far.
The incident raises questions about customer protections as banks push digital services. Treasury committee chair Meg Hillier noted the trade-off between convenience and technology risks. Lloyds will provide further updates in April and September.



