The numbers
What happened
A software defect during an overnight update temporarily allowed customers to see other customers' financial information in the app or online banking. The initial estimate, just under 450,000 people, was revised upward to over 500,000 after further investigation β one of the largest recent banking data incidents in the UK, despite not being a cyberattack.
β οΈWhy this distinction matters
A software bug and a hack produce the same result for the victim β data seen by someone who shouldn't see it β but the implications differ widely. Here, no data left the bank's perimeter toward a malicious third party; the exposure happened between legitimate customers of the same institution, inside the system. That changes nothing about the inconvenience for those affected, but it changes everything for assessing the risk of later impersonation: nobody resold this data on a forum.
What it changes for you
If you're a Lloyds, Halifax, or Bank of Scotland customer, the main risk isn't the leak itself but the media coverage it can attract: a message or call posing as "the bank following the security incident" to "verify your information" exploits exactly this kind of press coverage. That's the mechanism documented in From Leak to Scam β which applies even when the original leak isn't malicious.
Frequently asked questions
Was Lloyds Bank hacked?
No. It was a software defect during an overnight update, with no hacker or external intrusion.
Why does this case file appear on the Threat Laboratory if it isn't a hack?
To clearly distinguish an internal technical error from a malicious leak β a confusion that benefits scammers.
Did I lose money if I'm an affected customer?
No, according to Lloyds, which recorded no financial losses linked to this incident.
Related reading
Egidio β The Threat Laboratory, "Lloyds Bank: a software bug, not a hack," egidio.app/en/laboratoire/lloyds-bug-not-a-breach/. Licensed CC BY 4.0.
Free to reuse, including commercially, with attribution. Reuse terms.