EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/ransomware-attack/2024-evolve-bank-data-breach
091/430

File EL-0340CriticalResolvedRansomware Attack / Ransomware with Data Exfiltration

Evolve Bank & Trust Data Breach

Also filed as Evolve Bank Ransomware · LockBit Evolve Hack · Fintech Partner Breach

The LockBit ransomware gang breached Evolve Bank & Trust, a key banking partner for numerous fintech companies. The breach exposed customer data from multiple fintech platforms including Affirm, Mercury, and Wise, affecting millions of users across the financial technology ecosystem.

  • #banking
  • #fintech
  • #ransomware
  • #lockbit
  • #supply-chain
  • #pii
Notoriety8/10
Event
29 May 2024
Disclosed
26 Jun 2024
Target
Evolve Bank & Trust
Actor
LockBit
Scale
7.6M people
Status
Resolved

01Summary

In late May 2024, the LockBit ransomware group gained unauthorized access to Evolve Bank & Trust's systems. LockBit exfiltrated over 7.6 million customer records before deploying ransomware. The breach was particularly significant because Evolve Bank provides back-end banking services to dozens of fintech companies, meaning the breach cascaded across the fintech ecosystem. Affected companies included Affirm, Mercury, Wise, Stripe, and many others. The stolen data included customer names, Social Security Numbers, bank account numbers, and loan information. The incident highlighted the systemic risk of centralized banking-as-a-service (BaaS) infrastructure.

02Background

Evolve Bank & Trust is a traditional bank that provides Banking-as-a-Service (BaaS) infrastructure to numerous fintech companies. Its platform handles everything from payment processing to loan origination for partners across the financial technology sector.

03Key revelations

  1. 01A single bank serving as BaaS infrastructure can be a systemic risk for the entire fintech industry.
  2. 02LockBit's continued operational capability despite law enforcement takedown efforts.

04Technical analysis

LockBit gained initial access through compromised credentials, likely obtained via phishing or purchased from initial access brokers. They then moved laterally through Evolve's network to access customer databases containing records from multiple fintech partners.

Attack vector
Compromised credentials / Phishing
Attack method
Ransomware with data exfiltration
Initial access
Compromised credentials / Phishing
Lateral movement
Network pivoting
Exfiltration
Bulk data extraction before encryption
Tool / malware
LockBit 3.0 Ransomware
Malware family
LockBit
Malware type
Ransomware

05Threat actor

LockBit is one of the most prolific ransomware operations, operating a Ransomware-as-a-Service (RaaS) model. Despite law enforcement takedown attempts in 2024, LockBit has continued operations.

Aliases

  • LockBit 3.0

Attribution sources

  • LockBit leak site
  • Evolve Bank statements
  • FBI
  • Fintech partners

06Victims and impact

Additional victims

  • Affirm
  • Mercury
  • Wise
  • Stripe
  • Multiple fintech companies

Countries affected

  • United States
  • Global

07Data exposed

Data types

  • PII
  • SSNs
  • Bank account numbers
  • Loan data
  • Names
  • Addresses
  • Dates of birth

08Financial damage

Massive cascading impact across fintech ecosystem; regulatory fines from multiple agencies.

09Timeline

  1. 2024-05-29LockBit compromises Evolve Bank systems.
  2. 2024-06-26Evolve Bank publicly confirms breach.

10Reaction and fallout

Public reaction

Significant concern among fintech users about banking-as-a-service security and data aggregation risks.

Political impact

Increased regulatory scrutiny of Banking-as-a-Service (BaaS) partnerships and third-party risk management in financial services.

11Legal

Multiple regulatory investigations; potential class-action lawsuits from affected customers.

Civil lawsuits

  • Anticipated class-action lawsuits

12Aftermath

Policy changes

  • Calls for stronger oversight of fintech-banking partnerships.

Security improvements

  • Enhanced third-party risk assessments for BaaS providers.

13Significance and legacy

Significance

One of the most impactful fintech ecosystem breaches, demonstrating systemic risk in centralized banking infrastructure.

Legacy

Led to major reassessment of Banking-as-a-Service risk models and fintech vendor concentration risk.

14Disclosure and media

Authentication
LockBit leak site and Evolve Bank SEC filing

Publishing organisations

  • BleepingComputer
  • TechCrunch
  • Bloomberg
  • KrebsOnSecurity

15Field notes

  1. 01Evolve Bank is one of the key Banking-as-a-Service providers powering much of the U.S. fintech industry.

16Resolution

Evolve Bank contained the breach and notified affected fintech partners and customers.

17Sources

Official documents

  • Evolve Bank SEC filing
  • Fintech partner breach notifications

References

  1. [1]BleepingComputer: Evolve Bank breach coverage
  2. [2]TechCrunch: Fintech ecosystem impact
Fact sheetEL-0340

Dates

Event
29 May 2024
Started
29 May 2024
Discovered
29 May 2024
Disclosed
26 Jun 2024
Ongoing
No

Target

Organisation
Evolve Bank & Trust
Type
Financial Institution
Sector
Banking / Financial Services
Country
United States

Actor

Name
LockBit
Type
Ransomware Gang
Motivation
Financial gain through ransomware extortion and data theft.
Attribution
High
Status
Active
Arrested
No
Convicted
No

Data

People
7,640,000
Records
7,640,000
Sensitivity
Critical
Published
Yes
Sold (dark web)
Yes

Money

Crypto
Bitcoin

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.