Nearly half a Million mobile customers of Lloyds Banking Group affected by security incident
2026-03-31T14:51:44Z•c122095894f851132dcca4db50fff395274707d1f90fdf19912b9fab70300611
APTCISA-KEVCVE-2026-21643CVE-2026-3055China-linkedCitrix-NetScalerDarkSwordDow-IncFortinetInfinity-StealerLloyds-Banking-GroupQilinTA446ZDI-CAN-30207active-exploitationdata-breachiOS-exploitmacOS-malwaremobile-bankingransomwaresupply-chain-update-failuretelegram-zero-dayvulnerability
What happened
Multiple high-impact security developments: Lloyds Banking Group disclosed a faulty app update that exposed transaction data of ~450,000 mobile users. Two critical NetScaler issues (notably CVE-2026-3055, CVSS 9.3) were added to CISA’s KEV and are being actively probed; a separate critical Fortinet FortiClient EMS flaw (CVE-2026-21643, CVSS 9.1) is under active exploitation. Other notable incidents include a Qilin ransomware claim against Dow Inc., a reported (but disputed) Telegram zero-click RCE disclosed as ZDI-CAN-30207, a macOS Infinity Stealer campaign, Russia-linked TA446 leveraging the
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- c122095894f851132dcca4db50fff395274707d1f90fdf19912b9fab70300611
- Enrichment time
- 2026-03-31T14:51:44Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.