FinWise reported a data-security incident involving a former employee and information connected to American First Finance (AFF). Regulatory notification materials identified about 689,000 individuals, but public reporting does not establish that everyone’s information was viewed, copied, or misused. The full list of affected data types has not been disclosed.
What happened at FinWise?
FinWise’s reported timeline separates the incident from its discovery by more than a year:
| Event | Date and detail |
|---|---|
| Incident | May 31, 2024, according to reporting on a filing with the Maine attorney general. |
| Discovery | June 18, 2025, according to the same reporting. |
| Public reporting | The incident was reported in September 2025. |
FinWise said a former employee accessed company data after leaving the organization. The company investigated with outside cybersecurity specialists and notified people whose information was associated with AFF. The reports do not explain how the access occurred or why detection took until June 2025. (The Register’s timeline report; ITPro’s report on the notification)
How were FinWise and American First Finance connected?
FinWise Bank provided lending and financial services; AFF was the technology provider involved in offering installment loans and related financing. A consumer may have dealt mainly with AFF even if FinWise was involved in the financing.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstall#1 Best Overall
FinWise’s reported notice said potentially affected people may have had a FinWise installment loan, lease-to-own account, or retail installment sales agreement through AFF. The notification figure was 689,000 individuals, often rounded in headlines to “nearly 700,000.” The reporting does not clarify how many were active customers, former customers, applicants, or people represented in related records. (CPO Magazine’s explanation of the product relationship; ITPro’s report on the affected population)
What information was involved?
Full names were reported among the affected information, but the other data elements were not publicly specified in the coverage. The relevant list was redacted or otherwise undisclosed. That means public information does not confirm whether Social Security numbers, dates of birth, account numbers, driver’s-license details, passwords, or payment-card information were involved. Do not assume any of those specific data types were exposed based on the available reports. (ITPro; The Register)
Was customer data stolen or misused?
Public reporting does not establish that the information was exfiltrated, sold, published, or used for fraud. The reports describe access by a former employee and an investigation into whether sensitive information had been accessed. A person being counted in the potentially affected population does not by itself prove that their record was viewed or copied.
For that reason, “potential exposure” or “possible unauthorized access” is more precise than saying that 689,000 identities were stolen. The length of time between the reported incident date and discovery date is known; the duration of any actual unauthorized access is not.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Who should look for a notice?
Pay attention if you applied for or received an AFF-related installment loan, used a lease-to-own financing product, or had a retail installment sales agreement connected with the businesses. Former customers may also have records retained by a company. However, the public figure does not mean every AFF customer was affected. A notification from FinWise is the clearest indication that you are included.
What should you do if FinWise contacts you?
- Check that the notice is genuine. Use contact details already present on FinWise’s official website or on account paperwork you trust rather than relying only on a link or phone number in an unexpected message. Do not share passwords, one-time codes, or payment details with someone who contacts you claiming to be from FinWise or AFF.
- Read the notice for your specific eligibility and enrollment instructions. FinWise reportedly offered affected individuals credit monitoring and identity-theft protection. The public coverage does not identify the provider, duration, deadline, or full terms, so rely on the official notice for those details.
- Use the offered protection if eligible. Consider it before buying a separate plan that may duplicate the notice’s service. Monitoring can alert you to some activity, but it cannot prevent every kind of identity theft or misuse of an existing account.
- Review your credit reports. Get them through the official U.S. credit-report source, AnnualCreditReport.com, and dispute unfamiliar accounts or inquiries with the relevant credit bureau and lender.
- Consider a fraud alert or credit freeze. A fraud alert asks creditors to take extra steps to verify your identity; a freeze restricts access to your credit report for many new-account applications. A freeze is free to place through the credit bureaus and can help limit new-account fraud, but it does not stop misuse of existing accounts.
- Watch financial accounts and messages. Check bank and loan accounts for unfamiliar activity. Treat unexpected messages about compensation, refunds, or urgent account verification cautiously; a breach notice can be used as a pretext for phishing.
- Keep the notice and records of your response. Save the notification and any enrollment confirmation in case you need to follow up about the service or dispute later activity.
What remains unknown?
Public reports do not specify the full data categories, the access method, the former employee’s motive, how many records were actually viewed, or whether any information was misused. They also do not establish a final regulatory finding, criminal charge, settlement, or court outcome. FinWise’s general reference to additional precautions does not describe specific changes to access controls or employee offboarding.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




