Lloyds Data Breach Exposes Nearly Half a Million Customers

Lloyds said a March 12 app defect exposed customer data across its brands, with 114,182 viewing transactions; £139,000 paid in redress.

Atlas Newsdesk ·

Lloyds Data Breach Exposes Nearly Half a Million Customers

Lloyds Banking Group disclosed that a software fault briefly exposed customers’ personal and financial information inside its mobile banking apps on March 12. The issue meant some users could see other customers’ payment and account information, including national insurance numbers.

The incident came to light publicly after the Treasury select committee revealed it on Friday. Lloyds said the problem was linked to a defect introduced during an overnight technology update affecting its Lloyds, Halifax, and Bank of Scotland mobile applications.

What happened

Lloyds stated that up to 447,936 customers may have been able to view private information belonging to other users because of the defect. The bank also said around 114,182 individuals clicked into transaction screens where sensitive details became visible.

The exposed information included payments and account details, and in some cases national insurance numbers. Lloyds said it has not identified financial losses linked to the incident.

Regulatory notifications and customer redress

Lloyds reported the issue to the UK Financial Conduct Authority on March 12. It also notified the Information Commissioner’s Office within 72 hours, which the bank said was in line with required reporting timelines.

The bank said it has compensated 3,625 customers, paying a total of £139,000 for distress and inconvenience. Lloyds added that, to date, it has seen no evidence of misuse or malicious activity connected to the exposure.

Why it matters now

The episode underscores operational and compliance risks as retail banking shifts further toward app-based services. Lloyds’ update-related defect also highlights how routine software releases can create sudden data-protection incidents, even without an external attack.

The bank linked the broader backdrop to rising dependence on digital banking alongside a reduction in physical branch access. That combination can increase the impact of app outages or defects because more customers rely on mobile channels for everyday transactions.

Limits, uncertainties, and next questions

Lloyds said there is no evidence so far of malicious use, but the bank did not provide details on how long the defect persisted or how quickly it was fully contained. It also did not specify whether all exposed fields appeared for every affected customer, beyond noting that national insurance numbers were among the data types visible.

For regulators and customers, the key unresolved issues include the precise duration of exposure, the effectiveness of controls around software changes, and whether additional remediation steps will be required. The incident is likely to keep attention on how major banks manage technology updates while meeting data-protection expectations.

More stories