Nearly half a Million mobile customers of Lloyds Banking Group affected by security incident

2026-03-31T14:51:44Zc122095894f851132dcca4db50fff395274707d1f90fdf19912b9fab70300611
APTCISA-KEVCVE-2026-21643CVE-2026-3055China-linkedCitrix-NetScalerDarkSwordDow-IncFortinetInfinity-StealerLloyds-Banking-GroupQilinTA446ZDI-CAN-30207active-exploitationdata-breachiOS-exploitmacOS-malwaremobile-bankingransomwaresupply-chain-update-failuretelegram-zero-dayvulnerability

What happened

Multiple high-impact security developments: Lloyds Banking Group disclosed a faulty app update that exposed transaction data of ~450,000 mobile users. Two critical NetScaler issues (notably CVE-2026-3055, CVSS 9.3) were added to CISA’s KEV and are being actively probed; a separate critical Fortinet FortiClient EMS flaw (CVE-2026-21643, CVSS 9.1) is under active exploitation. Other notable incidents include a Qilin ransomware claim against Dow Inc., a reported (but disputed) Telegram zero-click RCE disclosed as ZDI-CAN-30207, a macOS Infinity Stealer campaign, Russia-linked TA446 leveraging the

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
c122095894f851132dcca4db50fff395274707d1f90fdf19912b9fab70300611
Enrichment time
2026-03-31T14:51:44Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.