Lloyds Banking Group has begun piloting stricter out-of-band callback rules for its telephone fraud desk, requiring advisers to verify customers through a separate channel before discussing payment reversals or “safe account” transfers, according to staff briefings and a customer leaflet updated on the group’s website this week.

What changed in the pilot

Under the trial, which started in September across Lloyds Bank and Halifax fraud teams handling high-risk APP cases, advisers must initiate a callback only from published numbers on the back of debit cards or from in-app secure messaging—not from numbers displayed on incoming calls. Customers are told to hang up, dial the number themselves, and quote a one-time reference generated in the mobile app before sensitive account actions proceed.

The pilot also blocks advisers from reading full sort codes or account numbers aloud until the customer completes the callback step. Lloyds said the friction is intentional: criminals increasingly coach victims to stay on the line while impersonating bank staff, exploiting the fact that many customers trust caller-ID labels that read “Lloyds Bank.”

Staff guidance reviewed by InfoHandle emphasises that no legitimate fraud investigator will ask customers to move money to a “holding account” or purchase gift cards. That language mirrors Financial Conduct Authority consumer warnings updated this summer, though the FCA has not mandated a specific callback protocol for every bank.

Why APP desks are under pressure

UK Finance’s latest fraud report shows APP losses remain the largest consumer fraud category by value, with impersonation scams disproportionately affecting older customers. Lloyds, as one of the UK’s largest retail banks, sits on the receiving end of both victim reports and reimbursement disputes under the Payment Systems Regulator’s mandatory reimbursement framework that fully applied from October 2024.

Fraud analysts at competing banks told InfoHandle that spoofed caller-ID remains cheap and effective even when banks publish “we will never ask” banners in apps. Out-of-band verification shifts trust from the voice on the phone to a channel the customer controls—typically mobile banking or a card-back number—making it harder for criminals on the line to social-engineer simultaneous actions.

The pilot arrives as HM Treasury consults on whether to require consistent fraud-refund standards across payment firms. Lloyds has not said the callback rules will shorten average case resolution times; early internal metrics focus on whether customers complete verification without abandoning legitimate recoveries.

Customer and staff friction

Consumer groups welcomed the principle but warned that vulnerable customers without smartphones may struggle with app-based references. Lloyds said branch staff can issue printed callback slips with time-limited codes for customers who bank in person, and that text-message references are disabled to reduce SIM-swap risk.

Call-centre unions told InfoHandle that handle times may rise during the pilot, which could affect staffing rosters ahead of Christmas shopping fraud season. Lloyds said it added coaching scripts so advisers explain why the callback step exists rather than sounding like another scripted hurdle.

The bank is pairing the pilot with louder in-app alerts when customers set up new payees after long phone calls, a pattern fraud teams call “coached payments.” Those alerts do not block payments automatically—PSR rules still require banks to judge reimbursement case by case—but they insert a cooling-off prompt.

Regulatory context

The FCA’s financial crime guide expects firms to train staff on impersonation fraud and to monitor emerging typologies. The Payment Systems Regulator’s reimbursement rules require sending banks to refund eligible APP victims unless customers ignore clear warnings. Lloyds has not published reimbursement rates under the new regime; industry aggregates are due in UK Finance’s year-end update.

NCSC continues to advise the public to treat unsolicited bank calls as untrusted until verified independently—a message Lloyds now embeds at the start of fraud-desk calls in the pilot cohort. Whether other high-street banks adopt identical callback mandates is unclear; several told InfoHandle they already offer optional in-app verification but not mandatory hang-up-and-call-back for every fraud case.

Open questions

Lloyds has not said when the pilot will expand beyond the initial fraud teams or whether business banking clients receive the same rules. Prosecutions for caller-ID spoofing remain rare; Ofcom and telecom operators have tightened STIR/SHAKEN-style attestation for some carriers, but not all mobile networks display verified labels consistently.

If customers fail the callback step repeatedly, advisers escalate to branch identity checks—a path that may delay recoveries when criminals have already moved funds. Lloyds said it would publish a summary of pilot outcomes to the industry fraud forum before year-end, including whether callback verification reduced successful coached transfers without spiking abandonment of legitimate cases.

For now the bank is betting that a few minutes of customer inconvenience beats another season of APP losses where the voice on the phone sounded exactly like the fraud desk—and regulators will be watching whether out-of-band proof becomes the norm, not the exception.