Wise, Affirm, Mercury, and other companies say they're investigating how a recent ransomware attack by LockBit on Evolve Bank and Trust impacted their customers
The money transfer and fintech company Wise announced on Friday that some of its customers' personal data may have been stolen …
TechCrunchLorenzo Franceschi-Bicchierai
Context & Ripple Effects
The incident puts Evolve Bank and Trust at the center of a shared exposure for fintech partners, with Wise, Affirm, Mercury, and others tracing whether customer information passed through the affected bank. A later filing on the Evolve breach indicates the inquiry concerns a large population of personal-data records.
It also fits LockBit's pattern of creating consequences beyond the initially compromised company: related coverage tied the group to an attack on a major financial institution and to a separate exposure involving an IT-services provider.
First-order effects
Wise and other Evolve-linked companies must determine which customer records and services were affected, while communicating the potential exposure to customers.
Evolve becomes the operational and information source for partners’ incident assessments, even where those partners were not the direct ransomware target.
Second-order effects
Fintech partners face additional support, notification, and security-review work as they reconcile their own customer data with Evolve’s breach findings.
The episode raises the practical cost of bank-partner dependence: prospective fintech customers and partners have a clearer reason to scrutinize how data is handled across embedded banking relationships.
Third-order effects
If breaches at shared banking providers repeatedly propagate to many fintech brands, third-party cyber resilience will become a more prominent differentiator in platform and bank-partner selection.
Ransomware risk increasingly behaves as ecosystem risk rather than a single-company event, because a compromise at a financial-services intermediary can trigger parallel responses across its customer base.
The trend: Ransomware incidents are exposing how concentrated financial infrastructure can turn one provider breach into a multi-brand customer-data and trust event.
We are aware of a cybersecurity attack that breached the security systems of one of our partner banks, Evolve Bank & Trust, which leaked their records, including some account numbers, deposit balances, business owner names, and emails associated with Mercury and other fintech
Evolve has known their systems were compromised since late May. But it appears they didn't notify impacted fintechs (or end users) until the breach became public last week: [image]
As an Affirm Card user, we wanted to alert you of a recent cybersecurity incident at Evolve Bank and Trust, an issuing partner on the Affirm Card (not an originating bank partner for Affirm loans). [image]
Confirming that we were alerted to Evolve Bank's cyber incident late last night. Evolve issues the Affirm Card, so if you don't have one of those, you can ignore this. If you do, we are still investigating, but in short: - your Affirm account is safe - your Affirm card is
@JosephJacks_ This only affects customers on Evolve which are <50%. From what we have verified so far - SSNs, passport/ID cards are not in the data breach for Mercury customers. Account numbers, founder names and emails are unfortunately. Here is our statement:
The fact that Evolve Bank & Trust is trying to silence a reporter rather than focus on the worst data and security breach in the history of American banking is incredibly damning.
I think one of the enduring legacies of the fintech boom of the last few years is that my SSN and license has now been exposed in so many breaches (more every day) that they are truly meaningless... thanks Evolve.
1/ The @Mercury team's #1 priority has been mitigating the impacts of the recent cybersecurity incident on one of our partner banks (we emailed potentially impacted customers on Wednesday). Some customers have asked whether leaked account numbers could be used to steal money from
Brown, @tammybaldwin, @JohnFetterman and @RonWyden write to Scott Stafford, president and CEO of Evolve Bank and Trust, the partner bank to fintechs that has been entangled with Synapse. Roughly 200,000 fintech depositors have had no access to funds for over a month.
Just received a cease & desist from Evolve. If people misunderstood my posts to mean that I would share sensitive PII in my reporting, please know that was never my intent. I would not risk exacerbating what's already a difficult time. Also know I plan on continuing my [image]
I have been part of countless data breaches over the years, but this @EvolveBank leak has be worried enough that I'm actually taking the step to freeze my credit today. #ProtectYaNeck
Mercury's partner bank — Evolve — got hacked bad. I'm guessing half of the SF tech startup scene and US ecom small businesses use them. This is a clusterF.