Filing: Evolve Bank & Trust says LockBit accessed the personal data of at least 7.6M people during a February 2024 ransomware attack
On Monfay, Evolve confirmed that the personal data of at least 7.6 million people, was accessed during the incident. It's possible this number will keep going up as the investigation continues. … Forums: Hacker News : Evolve Bank and Trust confirms LockBit stole 7.6M people's data r/technology : Evolve Bank says ransomware gang stole personal data on millions of customers r/technews : Evolve Bank says ransomware gang stole personal data on millions of customers
Context & Ripple Effects
A week earlier, several companies that rely on Evolve said they were assessing whether their customers were affected by the bank’s breach; this disclosure gives that inquiry a far larger confirmed exposure base. Fintech partners’ earlier impact assessments now sit against a stated minimum of 7.6 million people, with the investigation still open.
The incident also adds to a recent sequence of LockBit disclosures involving large stores of sensitive information, including a separate breach affecting more than six million people at Infosys McCamish. It matters because a breach at a financial-services intermediary can create notification and accountability work beyond the breached institution itself.
First-order effects
- At least 7.6 million people now have a confirmed potential exposure of personal data, while Evolve must continue its investigation and any resulting customer-response process.
- Companies connected to Evolve, including those that had already begun reviewing customer impact, face a clearer need to determine which records and users overlap with the breach.
Second-order effects
- Evolve’s fintech and banking partners will face pressure to align customer communications, support, and remediation with Evolve’s findings, rather than treating the incident as an isolated vendor issue.
- The scale of the disclosure makes third-party security diligence and data-sharing boundaries more consequential for firms that depend on a common banking provider.
Third-order effects
- If comparable incidents continue, financial platforms may treat concentration at shared banking and service providers as a core operational risk, not merely a cybersecurity procurement concern.
- The pattern reinforces that ransomware’s lasting cost is often data exposure and downstream ecosystem disruption, even as law enforcement actions can disrupt a group’s operations.
The trend: Ransomware is increasingly producing ecosystem-wide exposure events when a single financial-services intermediary holds data used by multiple customer-facing companies.