惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

WordPress大学
WordPress大学
B
Blog RSS Feed
The GitHub Blog
The GitHub Blog
爱范儿
爱范儿
博客园 - 司徒正美
J
Java Code Geeks
酷 壳 – CoolShell
酷 壳 – CoolShell
Engineering at Meta
Engineering at Meta
大猫的无限游戏
大猫的无限游戏
D
Docker
Blog — PlanetScale
Blog — PlanetScale
Recent Announcements
Recent Announcements
罗磊的独立博客
Microsoft Azure Blog
Microsoft Azure Blog
博客园 - 聂微东
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
人人都是产品经理
人人都是产品经理
Stack Overflow Blog
Stack Overflow Blog
M
MIT News - Artificial intelligence
腾讯CDC
T
The Blog of Author Tim Ferriss
小众软件
小众软件
U
Unit 42
T
Tailwind CSS Blog

The Register - Off-Prem

Enterprise cloud infrastructure uptake shows no sign of slowing The majority of corporate IT is now off premises for the first time Microsoft fiber foul-up cut off Azure California for almost five hours Web app turns your old phone into a new smart display Anyone with a shed, an extension cord, a couple of GPUs and an overdraft is building datacenters. Fujitsu just offloaded five Iran says it Google Cloud outage shows it’s still hard to understand hyperscalers’ real resilience regimes AWS customer learns the hard way how even the smallest oversight can be mission-critical Billing software error sends billion-dollar AWS estimates Top EU court clips YouTube AWS CloudFront outage serves errors instead of websites India’s tech services giant HCL is getting into the AI datacenter business Britain Microsoft shifts to annual exchange rate price revision for cloudy products Amazon’s Mechanical Turk to stop accepting new customers – and not even AI can save it Fire burns Google Cloud India’s network, which remains slow a week later EU sovereignty push gives tech buyers a new alphabet soup to swallow Google, Canonical team up to certify Ubuntu images for TPU VMs Arm moves into the heart of the cloud stack Snowflake to burn $6B on AWS Graviton CPUs and AI accelerators Big Tech extracts retirement-scale wealth from UK internet users, research shows Open Compute urges local government to bask in the warm glow of excess datacenter heat Google Cloud suspended major customer Railway.com without cause, causing outage Broadcom finds a VMware customer willing to stick around: London Stock Exchange Baidu says the quiet part out loud – you can’t build AI infrastructure, so clouds can cash in AWS racks M3 Ultra Macs that boast specs you can’t currently buy Tencent admits GPUs only pay for themselves when powering personalized ads Red Hat blasts RHEL 10.1 into orbit aboard Voyager's micro datacenter Sovereign cloud is only possible if you’re Chinese or American: Gartner Cloudflare to fire 1,100 staff whose jobs just aren’t AI enough
Lloyds app glitch exposed transactions to almost 500K users
Carly Page Carly Page · 2026-03-27 · via The Register - Off-Prem

Software

Lloyds app glitch turned transactions into shared experience for 447k users

A botched update mixed up transaction data across accounts, with thousands now receiving goodwill payouts

A botched overnight software update at Lloyds Banking Group left up to 447,000 customers briefly seeing other people's transactions in its mobile apps, with the bank now acknowledging the scale of the incident and compensating affected users.

Details of the incident emerged in a letter from Jasjyot Singh, the bank's CEO of consumer relationships, to the Treasury Committee, following questions about the March 12 glitch that affected Lloyds, Halifax, and Bank of Scotland users.

According to Singh, the issue was triggered by an IT change pushed overnight between March 11 and 12, introducing a software defect in the API handling transaction data. Between 03:28 and 08:08 that morning, customers logging into the apps could end up seeing fragments of other people's account activity if they accessed their transaction lists at almost exactly the same moment as another user.

Lloyds says no one could move money or access accounts, but users were able to see transaction amounts, dates, and payment references, which can include personal identifiers. Those who drilled into individual payments could potentially view sort codes, account numbers, and any text entered alongside a transaction, including National Insurance numbers or vehicle registration details where these had been used as references.

Out of 21.5 million mobile banking users, 1.67 million logged in during the affected window. Lloyds said as many as 447,936 customers may have been exposed to other people's transaction lists, while up to 114,182 could have seen more detailed payment information. The crossover works both ways: some customers saw other people's transactions, while others had their own details briefly shown to strangers.

"In some cases, the transaction information visible may have related to individuals who are not Lloyds Banking Group customers, for example in an instance where a payment was made from a Lloyds Banking Group customer account to an account holder at another bank," Singh admitted.

Singh says the exposure was brief and unlikely to lead to fraud, with no financial losses so far. Even so, the bank has told customers to delete any screenshots or notes they may have taken and says it's monitoring for misuse.

So far, Lloyds has paid out just over £139,000 to around 3,625 customers as goodwill for distress and inconvenience, rather than compensation for losses. It says it will consider further claims if any financial harm emerges.

The bank said it notified regulators on the morning of the incident and followed up with a formal notification to the ICO within the required 72-hour window.

The root cause, Lloyds says, was a flaw in how the updated API handled simultaneous requests, effectively breaking the isolation between accounts when two users hit the same function within fractions of a second. The bank is now reviewing how that defect slipped past its design, testing, and quality assurance processes.

In response to Lloyd's update, chair of the Treasury Committee, Dame Meg Hillier, said: "Modern banking methods mean we can now perform a variety of tasks on our phones in a matter of seconds, and almost anywhere.

"What this incident brings into focus is the fact that there is a trade-off. By moving more interactions with our bank online, we place our faith in technology which can suffer unpredictable errors. It's critical that consumers understand this, and that's why my Committee continues to push banks to be transparent when things go wrong."

Banking apps are built on one basic rule: your account is yours. For a few hours on March 12, that rule didn't hold. ®