01Summary
In late May 2024, the LockBit ransomware group gained unauthorized access to Evolve Bank & Trust's systems. LockBit exfiltrated over 7.6 million customer records before deploying ransomware. The breach was particularly significant because Evolve Bank provides back-end banking services to dozens of fintech companies, meaning the breach cascaded across the fintech ecosystem. Affected companies included Affirm, Mercury, Wise, Stripe, and many others. The stolen data included customer names, Social Security Numbers, bank account numbers, and loan information. The incident highlighted the systemic risk of centralized banking-as-a-service (BaaS) infrastructure.
02Background
Evolve Bank & Trust is a traditional bank that provides Banking-as-a-Service (BaaS) infrastructure to numerous fintech companies. Its platform handles everything from payment processing to loan origination for partners across the financial technology sector.
03Key revelations
- 01A single bank serving as BaaS infrastructure can be a systemic risk for the entire fintech industry.
- 02LockBit's continued operational capability despite law enforcement takedown efforts.
04Technical analysis
LockBit gained initial access through compromised credentials, likely obtained via phishing or purchased from initial access brokers. They then moved laterally through Evolve's network to access customer databases containing records from multiple fintech partners.
- Attack vector
- Compromised credentials / Phishing
- Attack method
- Ransomware with data exfiltration
- Initial access
- Compromised credentials / Phishing
- Lateral movement
- Network pivoting
- Exfiltration
- Bulk data extraction before encryption
- Tool / malware
- LockBit 3.0 Ransomware
- Malware family
- LockBit
- Malware type
- Ransomware
05Threat actor
LockBit is one of the most prolific ransomware operations, operating a Ransomware-as-a-Service (RaaS) model. Despite law enforcement takedown attempts in 2024, LockBit has continued operations.
Aliases
- LockBit 3.0
Attribution sources
- LockBit leak site
- Evolve Bank statements
- FBI
- Fintech partners
06Victims and impact
Additional victims
- Affirm
- Mercury
- Wise
- Stripe
- Multiple fintech companies
Countries affected
- United States
- Global
07Data exposed
Data types
- PII
- SSNs
- Bank account numbers
- Loan data
- Names
- Addresses
- Dates of birth
08Financial damage
Massive cascading impact across fintech ecosystem; regulatory fines from multiple agencies.
09Timeline
- 2024-05-29LockBit compromises Evolve Bank systems.
- 2024-06-26Evolve Bank publicly confirms breach.
10Reaction and fallout
Public reaction
Significant concern among fintech users about banking-as-a-service security and data aggregation risks.
Political impact
Increased regulatory scrutiny of Banking-as-a-Service (BaaS) partnerships and third-party risk management in financial services.
11Legal
Multiple regulatory investigations; potential class-action lawsuits from affected customers.
Civil lawsuits
- Anticipated class-action lawsuits
12Aftermath
Policy changes
- Calls for stronger oversight of fintech-banking partnerships.
Security improvements
- Enhanced third-party risk assessments for BaaS providers.
13Significance and legacy
Significance
One of the most impactful fintech ecosystem breaches, demonstrating systemic risk in centralized banking infrastructure.
Legacy
Led to major reassessment of Banking-as-a-Service risk models and fintech vendor concentration risk.
14Disclosure and media
- Authentication
- LockBit leak site and Evolve Bank SEC filing
Publishing organisations
- BleepingComputer
- TechCrunch
- Bloomberg
- KrebsOnSecurity
15Field notes
- 01Evolve Bank is one of the key Banking-as-a-Service providers powering much of the U.S. fintech industry.
16Resolution
Evolve Bank contained the breach and notified affected fintech partners and customers.
17Sources
Official documents
- Evolve Bank SEC filing
- Fintech partner breach notifications
References
- [1]BleepingComputer: Evolve Bank breach coverage
- [2]TechCrunch: Fintech ecosystem impact









