On July 2, 2024, TechCrunch reported that Jason Mikula, publisher of Fintech Business Weekly, said Evolve Bank & Trust had sent him a cease-and-desist letter over files allegedly stolen in the bank’s cyberattack. According to Mikula’s account, the letter sought to stop him from sharing those files with fintech companies that might need to assess customer exposure. He said he had reviewed some leaked material and offered to help companies understand it, but was not distributing sensitive personal information. The actual letter has not been made public in the sources cited here, so its precise wording and legal basis remain unverified.
What Mikula said the letter was about
Mikula publishes Fintech Business Weekly and covers fintech businesses, banking-as-a-service providers and the fallout surrounding Synapse. That industry focus put him in a position to report on which fintech companies might be connected to Evolve’s breach. TechCrunch reported that he had been posting information about potentially affected companies on X and in his newsletter.
| # | Preview | Product | Price | |
|---|---|---|---|---|
| 1 |
|
MANAGEMENT NEWS - Novembre2025:: AI, Fintech e Leadership Strategica (Management for not manager... | $10.00 | Buy on Amazon |
According to TechCrunch’s July 2, 2024 account, the reported letter told Mikula not to share files from the dark web with fintech companies believed to be affected. Mikula said he had reviewed some of the material through contacts with access to it and had offered to help companies determine what information might be involved. He said he was not actually sharing the files. In a contemporaneous LinkedIn post, he described the letter as a misunderstanding of his reporting, said he intended to continue covering the breach responsibly and said he did not intend to publish sensitive personal information.
The available reporting does not establish that Mikula published customer records. Reviewing data to verify a breach, reporting on what it indicates, and redistributing the underlying personal information are distinct acts; the report describes the first two, not public release of the files.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstall#1 Best Overall
What happened in Evolve’s cyber incident
Evolve’s account of the incident provides context for why companies and customers wanted clarity. The bank said it identified systems that were not functioning properly in late May 2024 and initially suspected a hardware issue. It later determined that unauthorized activity had occurred. Evolve said it stopped the attack and that it saw no new unauthorized activity after May 31, 2024. In June, the bank acknowledged that stolen data had been posted on the dark web.
Evolve’s later disclosure said the information involved appeared to include names, Social Security numbers, Evolve account numbers, dates of birth and contact information. The bank said the incident involved personal, mortgage, trust and small-business customers as well as customers of Open Banking partners; a small portion of affected individuals also had debit-card numbers involved. These are categories Evolve identified in its notice, not evidence that every customer or partner’s customers were affected. See the bank’s cybersecurity incident update and incident FAQ.
Why fintech companies might need breach details
Evolve provided banking services to fintech companies, so a person could potentially be affected without having an account branded as an Evolve account. A fintech may need to know whether its customers’ records were involved, which data fields were exposed, and whether current or former customers were affected. Those details can inform customer notices, fraud precautions and other mitigation.
At the time of the July 2024 report, TechCrunch said not all potentially affected fintechs had received confirmation of the breach’s scope. That was reporting about the situation then, not a finding that every partner lacked information. A separate TechCrunch report said Wise had told customers that some personal data might have been affected. That example does not establish the status of other fintechs; see Wise’s customer disclosure.
Why inspecting leaked data can matter—and why sharing it is risky
Journalists and security researchers may examine limited samples of allegedly stolen data to check whether an incident is real, understand what kinds of records may be involved or identify organizations that need to investigate. Such review can serve the public interest when companies and customers lack clear information. It does not make the files safe to circulate or establish that a person has legal authority to distribute them.
Stolen records can cause additional harm when copied or passed around, even if the intent is to help. Responsible handling should minimize access and retention, verify claims independently, use secure channels to contact affected organizations, and involve legal counsel and newsroom security staff. Reporters should not publish or transmit Social Security numbers, account details, passwords, authentication tokens or other sensitive records. Readers should not search for, download, link to or share the leaked files, or use information in them to contact or identify potential victims.
What a cease-and-desist letter does—and does not mean
A cease-and-desist letter is a private demand to stop specified conduct. It is not a court order, and receiving one does not itself prove that the recipient broke the law. It can still exert pressure because it may threaten legal action. Without the letter, it is not possible to establish exactly what Evolve demanded, what legal theories it cited, or whether it sought anything beyond the reported restriction on sharing files.
The report described a demand concerning the sharing of stolen files, not a confirmed order to stop all coverage. It is therefore too broad to say, based on the available account, that Evolve tried to prohibit Mikula from reporting on the breach. The letter could have reflected concern about further exposure of customers’ information, but that explanation is an inference: the cited reporting does not provide a substantive public response from Evolve or the letter’s full text.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
What is confirmed and what remains unclear
- Reported in 2024: TechCrunch said Mikula told the publication Evolve sent him a cease-and-desist letter over sharing breach files. Mikula’s LinkedIn post confirms his contemporaneous account of receiving a letter.
- Confirmed by Evolve: The bank disclosed unauthorized activity, said it stopped the attack and later described categories of information that appeared to be involved.
- Not established by the available public record: The letter’s complete text, its exact legal demands and rationale, whether Evolve publicly confirmed sending it, or whether Mikula actually transferred the files to any fintech company.
The core account of the letter comes from Mikula’s statements as reported by TechCrunch; the existence and scope of the cyber incident are separately addressed in Evolve’s notices. Those are different kinds of evidence and should not be collapsed into a single confirmed narrative.
How the Synapse crisis fits—and how it differs
The letter story unfolded during the broader Synapse Financial Technologies crisis. Synapse filed for Chapter 7 bankruptcy in May 2024, and customers of fintech products connected to it faced difficulty accessing funds. Evolve was among the banking and fintech partners involved in disputes over customer money and responsibility. On July 1, 2024, senators urged the parties to address customers’ access to funds; their letter cited allegations that $65 million to $95 million might be missing, while the companies involved disputed responsibility.
That funds-access dispute is separate from Evolve’s data breach. The Synapse crisis concerned access to and reconciliation of customer funds; the breach concerned unauthorized access to information systems and possible exposure of personal data. One should not be presented as the cause of the other.
What happened after the letter report
Evolve published more detail about potentially affected data after the July 2024 coverage. The incident also led to multidistrict litigation in the U.S. District Court for the Western District of Tennessee, case No. 2:24-md-03127-SHL-cgc. The official settlement site says final approval was entered December 15, 2025, and approved-claim payments were issued March 30, 2026. It says checks are scheduled to become void after September 28, 2026. The site provides settlement status and case documents, including the documents page.
The later settlement process concerns the data-security litigation; it does not establish whether the reported letter to Mikula was justified or resolve the dispute over his proposed handling of files.
What affected customers can do
People who may have used Evolve directly or through a fintech partner should rely on official notices from the bank and their provider rather than trying to locate leaked records. Check the provider’s communications for whether your information was implicated and what steps it recommends. For settlement eligibility, deadlines and payment information, use the official settlement site rather than third-party claims or links to stolen data.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




