Evolve Bank’s Cyber Attack Exposes Risk Management Cracks in FinTech
Published on
7 min read

Evolve Bank’s Cyber Attack Exposes Risk Management Cracks in FinTech

Last week, Evolve Bank & Trust announced that it had suffered a data breach. The Evolve bank data breach was characterized by unauthorized leakage of customer data on the dark web. According to CIO News, the data breach was a result of a cybersecurity failure.

On Wednesday, Evolve Bank & Trust informed its retail customers and fintech partners that it had commenced investigations into the cyberattack.

In a notice published on its website, Evolve Bank said, “It appears these bad actors have released illegally obtained data, including Personal Identification Information (PII), on the dark web. The data varies by individual, but may include your name, Social Security Number, date of birth, account information, and/or other personal information.”

The company expressed confidence that the breach had been contained.

Evolve retail banking customers’ debit cards, online, and digital banking credentials do not appear to be impacted by the cybersecurity incident,” Evolve Bank added.

Regulator Warning

The cyberattack on Evolve Bank comes soon after the U.S. Federal Reserve Board issued enforcement action against the bank. Earlier last month, the regulator instructed the bank to reinforce its risk management initiatives concerning anti-money laundering regulations and fintech partnerships.

A representative from the bank said that the bank had sought the support of law enforcement agencies to facilitate its inquiry and remediation efforts.

We will offer all impacted customers (end users) complimentary credit monitoring with identity theft protection services. Those affected will be contacted directly with instructions on how to enroll in these protective measures,” the representative added.

Impact on Fintech Firms

The Evolve bank cyberattack has caused various fintech companies to initiate investigations into potential impact of the data breach. Mercury, a fintech startup, has already confirmed that its customer data was compromised. The company confirmed that Evolve’s intrusion disclosed emails, business owner names, and deposit balances for certain account numbers.

Mercury reported that impacted customers had been informed. The company also posted information on precautionary measures for its customers on X, formerly Twitter.

Another fintech startup, Affirm, reported possible unauthorized access of its customer database. However, the company says its Money Accounts and card may be safe to use as investigations continue. Other fintech startups that continue to investigate the impact of Evolve bank and Trust data breach include Melio, EarnIn, and Marqueta.

Kelly Kraft, Marqueta Spokesperson said, “Our customers affected by this incident have been notified, and we are working closely with Evolve to understand their remediation effort and how our mutual customers may be impacted.”

Publication of Stolen Data

Lockbut 3.0, a cybercrime group, reportedly published the stolen Evolve data on Tuesday. The hackers allegedly gave the Federal Reserve Board until Tuesday afternoon to comply with ransom demands to avoid disclosure of private information.

Julie Butler
X

Customize Consent Preferences

We use cookies to help you navigate efficiently and perform certain functions. You will find detailed information about all cookies under each consent category below.

The cookies that are categorized as Necessary are stored on your browser as they are essential for enabling the ... Show More

We use cookies to help you navigate efficiently and perform certain functions. You will find detailed information about all cookies under each consent category below.

The cookies that are categorized as Necessary are stored on your browser as they are essential for enabling the basic functionalities of the site.

We also use third-party cookies that help us analyze how you use this website, store your preferences, and provide the content and advertisements that are relevant to you. These cookies will only be stored in your browser with your prior consent.

You can choose to enable or disable some or all of these cookies but disabling some of them may affect your browsing experience.

Show Less

Necessary Always Active

Necessary cookies are required to enable the basic features of this site, such as providing secure log-in or adjusting your consent preferences. These cookies do not store any personally identifiable data.

Functional

Functional cookies help perform certain functionalities like sharing the content of the website on social media platforms, collecting feedback, and other third-party features.

No Cookie to display

Analytics

Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics such as the number of visitors, bounce rate, traffic source, etc.

Performance

Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.

No Cookie to display

Advertisement

Advertisement cookies are used to provide visitors with customized advertisements based on the pages you visited previously and to analyze the effectiveness of the ad campaigns.

No Cookie to display
Scroll to Top