Lloyds IT Glitch Exposed Nearly 450,000 Customer Records

Lloyds says a March 12 software defect let some users see others’ banking data. Up to 447,936 customers were affected; regulators are probing.

Atlas Newsdesk ·

Lloyds IT Glitch Exposed Nearly 450,000 Customer Records

Lloyds Banking Group has disclosed that a technology fault in its digital banking systems exposed customer information, affecting up to 447,936 people across its brands including Halifax and Bank of Scotland.

The bank said the incident occurred on March 12 and stemmed from a software defect introduced during an overnight IT change. As a result, some customers using banking apps were able to view information that did not belong to them.

What happened and what was exposed

In its account of the event, Lloyds said the error enabled certain users to see other individuals’ transaction records and account details. The bank also stated that National Insurance numbers were among the personal data that could be viewed.

The group has not detailed how long the exposure lasted, how many customers actually saw other people’s information, or whether any data was saved or shared. Those points remain unclear based on the disclosure to date.

Compensation and regulatory scrutiny

Lloyds said it has begun compensating customers, describing the payments as goodwill. As of March 23, it had distributed about £139,000 to 3,625 affected customers, which works out to an average of £38.34 per person.

The bank said it is cooperating with financial regulators, naming the Financial Conduct Authority (FCA) and the Information Commissioner’s Office (ICO). It also stated that both regulators are actively investigating the incident.

Why the disclosure matters now

The disclosure followed scrutiny from the Treasury Select Committee, which prompted Lloyds to provide details. The committee highlighted a tension between the ease of modern banking services and the risk that complex systems can fail in unexpected ways.

The episode adds to the operational and compliance pressures facing banks as more customer activity shifts to apps and online platforms. For large retail banks, technology changes made overnight can affect millions of logins, making quality controls and incident reporting central to customer trust and regulatory expectations.

Market and policy relevance

For investors and policymakers, the immediate focus is on operational resilience and data protection, particularly when sensitive identifiers are involved. Regulatory investigations by the FCA and ICO can lead to requirements for remediation, governance changes, and closer supervision, depending on findings.

What remains unknown is the full scope of exposure in practice versus the maximum number of potentially impacted customers, as well as whether further customer notifications or additional compensation will be needed. Lloyds has not provided those details in the information disclosed so far.

More stories