Lloyds Banking Group has confirmed that almost half a million customers were affected by a recent mobile banking app incident that allowed some users to see transactions belonging to other people.
The issue occurred on 12 March 2026 and affected the mobile apps used by customers of Lloyds Bank, Halifax and Bank of Scotland. The bank has now revealed that up to 447,936 customers may have been impacted.
The disclosure was made in a letter sent by the bank to the UK Parliament’s Treasury Select Committee, which has been examining what happened and how customers were affected.
What the bank has now confirmed
According to Lloyds Banking Group, the incident was caused by a software defect introduced during an overnight IT update.
The error meant that some customers who logged into their banking apps briefly saw transactions and financial information belonging to other individuals.
The bank said that 114,182 customers actively clicked on transactions that were not their own, which may have revealed additional information such as payment references or account details.
In some cases, this reportedly included National Insurance numbers used as payment references for Department for Work and Pensions payments.
The bank has apologised for the incident and said it fixed the issue quickly after it was identified.
Compensation payments so far
Lloyds Banking Group says it has already made goodwill payments to some affected customers.
As of 23 March, the bank said it had paid out around £139,000 to 3,625 customers, which equates to an average payment of about £38 per person.
The bank described these payments as compensation for distress or inconvenience caused by the incident. It has not confirmed whether further payments will be made or whether additional customers may be eligible.
Regulators are now reviewing the incident
The issue has attracted attention from UK regulators.
- The Financial Conduct Authority (FCA) has confirmed it is actively engaging with Lloyds Banking Group following the incident.
- Meanwhile, the Information Commissioner’s Office (ICO) — the UK’s data protection regulator — has said it is making enquiries with the bank.
If regulators determine that personal data was exposed to unauthorised users, the incident could potentially fall within the scope of UK data protection laws. For customers affected by the glitch, the full implications of the incident may only become clearer once regulatory enquiries are completed. Lloyds Banking Group says it will cooperate fully with regulators as investigations continue.
Modern banking increasingly relies on mobile apps and digital systems, which allow customers to manage their finances quickly and easily. But the Lloyds incident highlights how technical failures can also raise concerns about data security and customer trust.
If personal data was exposed or shared without authorisation, it could potentially raise questions under UK data protection law.
vJoin the Claim is monitoring developments and will provide updates if any investigations or legal actions arise.