Lloyds Banking Group has admitted that an IT glitch in its mobile and online services exposed other customers’ transactions – and, in some cases, personal details – to almost half a million people.
In a letter to the Treasury Select Committee, the group said the incident on 12 March affected up to 447,936 customers across Lloyds Bank, Halifax and Bank of Scotland. The bank confirmed that 114,182 users actually accessed other people’s transactions, potentially viewing sensitive data such as account details, national insurance numbers and payment references.
Lloyds said the problem was caused by a “software defect” introduced during an overnight update to its systems. The glitch affected the group’s online services, briefly allowing some customers to see transactions belonging to others.
The bank also acknowledged that transaction data relating to people who are not Lloyds Banking Group customers may have been visible. Lloyds told MPs it self‑reported the incident to the Financial Conduct Authority on the morning of 12 March and notified the Information Commissioner’s Office within the required 72‑hour window.
So far, Lloyds has paid £139,000 in compensation to 3,625 customers to recognise “distress and inconvenience” caused by the breach. That works out at an average of around £38 per person, with the bank stressing that no customers have yet been identified as having suffered any direct financial loss.
Jasjyot Singh, Lloyds’ chief executive for consumer relationships, said there was “currently no evidence of misuse or malicious activity as a result of the incident through our fraud and cyber monitoring process.” He added that the bank would continue to monitor accounts and urged customers to delete any screenshots or information they may have captured showing other people’s transactions.
The disclosure has intensified scrutiny of banks’ resilience as more customers are pushed towards digital channels. A Treasury Committee report last year found that the UK’s nine largest banks had suffered at least 33 days of IT outages over a two‑year period.
In Case You Missed It:
Dame Meg Hillier, chair of the Treasury Committee, described the Lloyds incident as an “alarming breach of confidentiality.” “Modern banking methods mean we can now perform a variety of tasks on our phones in a matter of seconds, and almost anywhere,” she said, adding: “What this incident brings into focus is the fact that there is a trade‑off. By moving more interactions with our bank online, we place our faith in technology which can suffer unpredictable errors.”
Hillier has asked Lloyds for further updates on the fallout from the glitch in one month and again in six months’ time. She said it was “critical that consumers understand” the risks involved in online banking and that banks are transparent when things go wrong.
Lloyds, meanwhile, is continuing to contact affected customers and says it will keep monitoring for any sign of fraud linked to the breach. For the UK’s biggest retail banking group, the incident has become a test of how quickly it can restore trust in the reliability of its digital services.





