[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fFSwHVqZTjG_lkZf3VxfcragVMKeo_NyDbVcY59jZqhg":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":18,"created_at":19,"published_at":20,"article":21,"tags":25,"podcasts":38},"0db6e503-e1ab-488e-94c5-d5df5d530536","lloyds-banking-app-update-exposes-450000-customer-records-due-to-access-control-failure","a8672d68-2428-4979-a63a-a753c773630a","Lloyds Banking App Update Exposes 450,000 Customer Records Due to Access Control Failure","A routine mobile app update at Lloyds Banking Group contained a software defect that broke privacy barriers between customer accounts, allowing over 114,000 users to access sensitive information belonging to others. This incident demonstrates how application-layer access control failures can have massive scope in financial services, affecting nearly half a million customers across multiple brands. The breach resulted in exposure of highly sensitive data including National Insurance numbers and payment references, leading to regulatory investigations and significant compensation costs. Proper testing of access controls before deployment and robust application security measures are critical to preventing such widespread data exposure incidents.","**Immediate actions:**\n- Implement mandatory access control testing in all pre-production environments before app releases\n- Establish emergency rollback procedures for mobile applications that can be executed within minutes\n- Deploy real-time monitoring for unusual cross-account data access patterns\n\n**Long-term improvements:**\n- Implement zero-trust architecture with granular permission controls at the application layer\n- Establish comprehensive security testing protocols including penetration testing for all customer-facing applications\n- Create isolated testing environments that mirror production data sensitivity without using real customer information\n\n**Detection measures:**\n- Deploy automated anomaly detection systems to identify unusual data access patterns across customer accounts\n- Implement comprehensive audit logging for all customer data access with real-time alerting capabilities",[12,13,14,15,16,17],"CIS Control 6","NIST AC-2","NIST AC-3","PCI DSS 7.1","GDPR Article 25","GDPR Article 32","published","2026-03-28T15:07:21.667522+00:00","2026-03-28T15:07:21.376+00:00",{"id":7,"url":22,"slug":23,"title":24},"https:\u002F\u002Fhackread.com\u002Flloyds-compensate-customers-app-glitch-exposed-data\u002F","lloyds-group-to-compensate-450-000-customers-after-app-glitch","Lloyds Group to Compensate 450,000 Customers After App Glitch",[26,32],{"id":27,"name":28,"slug":29,"description":30,"color":31},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":33,"name":34,"slug":35,"description":36,"color":37},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",[]]