Fall ResetAmazon USFall reset deals: check better picks before checkoutAmazon US: today's deals, useful picks and quick comparisons.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run ScanFall ResetAmazon USWork and home upgrades are worth comparing todayAmazon US: today's deals, useful picks and quick comparisons.See Picks×
Skip to content
Blog

Evolve Bank Data Breach Affected at Least 7.6 Million People: What Happened and What to Do Now

By TheFinanceBase Team8 min read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

The Evolve Bank & Trust data breach was a 2024 ransomware incident—not a newly discovered 2026 breach. Evolve said attackers accessed and downloaded information during periods in February and May 2024, and that the affected population included at least 7.6 million people. That group may include direct Evolve customers, employees, business customers, and people who used fintech services backed by Evolve.

As of August 18, 2026, the important remaining issues are identity-theft precautions and settlement-payment status. The settlement claim deadline has passed, approved payments were issued March 30, 2026, and uncashed settlement checks become void after September 28, 2026.

At a glance

  • Affected: At least 7.6 million people, according to Evolve’s state breach filing reported in July 2024.
  • When: Data access or downloading occurred in February and May 2024; Evolve discovered unauthorized activity on May 29.
  • Data involved: Names, Social Security numbers, dates of birth, contact information, account information and ACH records. Debit-card numbers affected a smaller portion of people.
  • Customer funds: Evolve said it found no evidence that attackers accessed customer funds.
  • Settlement: The October 30, 2025 claim deadline has passed. Approved payments were issued March 30, 2026.
  • Current date to watch: Cash a valid settlement check by September 28, 2026.

What happened at Evolve Bank?

Evolve described the incident as a LockBit ransomware attack. According to the bank’s cybersecurity notice, attackers used a malicious link to obtain access, downloaded information from databases and a file share, and later leaked the data after Evolve refused to pay the ransom. The malicious-link explanation is Evolve’s account of the incident.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The timeline is more detailed than the shorthand description “the May Evolve breach” suggests:

  • February 2024: Evolve says files were accessed or downloaded during this period.
  • May 2024: A second period of access or downloading occurred.
  • May 29, 2024: Evolve noticed that systems were not working properly and initially suspected a hardware problem.
  • May 31, 2024: Evolve says it identified no further unauthorized activity after this date.
  • June 2024: The bank publicly disclosed the cybersecurity incident and attributed it to LockBit.
  • July 8, 2024: Individual breach notifications began.
  • July 9, 2024: Reporting based on a Maine filing identified at least 7.6 million affected people.
  • August 27, 2024: Evolve updated its substitute notice with additional detail about the information involved.

The incident was separate from the Synapse bankruptcy and from a Federal Reserve enforcement action announced around the same time.

Is the 7.6 million figure accurate?

Yes, but the most accurate wording is “at least 7.6 million people” or “approximately 7.6 million people.” The figure came from a state breach-notification filing and was reported on July 9, 2024. It refers to people whose information was included in data Evolve determined had been accessed—not to people who were proven to have suffered identity theft or financial loss.

Nor does the figure mean that every person had every listed data field exposed. Evolve’s later notices indicate that the information varied by individual. The number should therefore not be presented as an exact count of people whose Social Security numbers, bank-account numbers and debit-card numbers were all stolen.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Who could have been affected?

Evolve was not only a conventional consumer-facing bank. It also provided banking infrastructure and services to financial-technology companies. As a result, someone could have been affected without ever opening an account branded “Evolve.”

The potentially affected population included:

  • Direct Evolve banking customers.
  • Customers of fintech companies that used Evolve for deposit accounts, payments or other banking services.
  • Some customers connected through Synapse Financial Technologies.
  • Evolve employees.
  • Mortgage, trust and small-business customers.
  • ACH payors and payees whose information appeared in transaction records.

News coverage identified or discussed Evolve relationships involving companies such as Affirm, Mercury and Wise. That does not mean every customer of those companies was affected. Inclusion depended on whether the person’s information appeared in files involved in the incident. The settlement FAQ also says the administrator may not be able to identify which specific fintech relationship supplied an individual’s information.

What information was exposed?

Evolve’s updated substitute notice described several categories of potentially affected information:

Category What it may have included
Identity information Names, Social Security numbers and dates of birth
Contact information Addresses and other contact details
Account information Evolve account numbers and financial account numbers
Payment information Routing numbers and ACH transaction records, including payor and payee names
Card information Debit-card numbers for a smaller portion of affected people
Litigation-notice categories Driver’s-license numbers were also listed among information alleged to have been accessed; this should not be read as universal exposure

The presence of financial records increases the risk of targeted phishing, fraudulent ACH activity, account takeover and identity-theft attempts. It does not establish that each person experienced any of those events.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Were customer bank balances stolen?

Evolve said there was no evidence that the attackers accessed customer funds. That statement addresses access to money; it does not guarantee that no individual later experienced fraud, unauthorized transactions or other harm connected to exposed information.

These are separate questions:

  1. Was Evolve’s system or data accessed? Yes, according to the bank’s incident notices.
  2. Did the attackers access customer funds? Evolve said it found no evidence of that.
  3. Could exposed information be used later for fraud? Yes. Sensitive identity and payment data can create continuing risk even when account balances were not directly accessed.

What monitoring did Evolve offer?

Evolve offered U.S. residents two years of credit monitoring and identity-theft protection through TransUnion and Cyberscout. The state notice listed October 31, 2024, as the enrollment deadline for recipients of that notice. International residents were offered dark-web monitoring where available.

That breach-specific enrollment opportunity is no longer a current option in August 2026. Credit monitoring can alert you to suspicious activity; it cannot make exposed information private again or guarantee that identity theft will be prevented.

What happened with the class-action settlement?

The settlement process continued into 2025 and 2026. According to the official settlement FAQ:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • The claim deadline was October 30, 2025.
  • The opt-out and objection deadline was October 15, 2025.
  • Final approval was scheduled for November 14, 2025.
  • Approved settlement payments were issued March 30, 2026.
  • Uncashed checks become void after September 28, 2026.

No ordinary new claim appears to be available now because the claim deadline has passed. People who submitted claims should use the official settlement website or its published administrator contact information to check payment status.

The settlement described several potential benefits:

  • Reimbursement of documented losses up to $3,000 per eligible class member, subject to documentation and other conditions.
  • An estimated flat cash payment of $20, subject to pro-rata adjustment. It was not a guaranteed universal amount.
  • One year of credit monitoring, real-time alerts and up to $1 million in identity-theft insurance for eligible claimants who selected that benefit.

People who remained in the settlement class and did not opt out released claims relating to the incident. The settlement resolved litigation without a judicial finding that Evolve committed wrongdoing; Evolve denied wrongdoing. The legal effect of participation can depend on the applicable settlement terms, so this is not individualized legal advice.

What affected people should do now

  1. Check your records. Look for an official Evolve or fintech breach notification, including messages sent to an old email address or a spam folder.
  2. Review bank and payment accounts. Look for unfamiliar ACH transactions, transfers, new payees, changed account details or unexpected password-reset notices.
  3. Pull all three credit reports. Check Equifax, Experian and TransUnion for unfamiliar accounts, inquiries and address changes.
  4. Freeze your credit if appropriate. A security freeze is free through the three nationwide credit bureaus and generally does not lower your credit score. You can temporarily lift it when applying for credit.
  5. Consider a fraud alert. A fraud alert can signal lenders to take additional steps before opening credit in your name.
  6. Secure your accounts. Change reused passwords, use unique credentials and enable multifactor authentication on email, bank and fintech accounts.
  7. Expect phishing. Do not provide passwords, Social Security numbers or one-time codes in response to an unsolicited message. Type official website addresses yourself rather than clicking unexpected links.
  8. Report suspected identity theft. Use IdentityTheft.gov, contact the relevant financial institution immediately and preserve messages, transaction records and other evidence.
  9. Check settlement status safely. Use only EvolveSettlement.com and its published contact details.
  10. Cash a valid settlement check promptly. If you received an approved payment, do not wait past September 28, 2026.

How this relates to Evolve’s fintech partnerships

The incident illustrates why a banking-as-a-service breach can reach beyond a bank’s own retail customers. A fintech may provide the app or brand a consumer recognizes, while a partner bank provides deposit, payment or account infrastructure. Records held in that infrastructure can therefore involve the fintech’s customers, business counterparties and transaction recipients.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The Federal Reserve separately announced a June 14, 2024, enforcement action citing deficiencies in Evolve’s anti-money-laundering, risk-management and consumer-compliance programs, including oversight of fintech partnerships. The Federal Reserve described that action as independent of Synapse’s bankruptcy proceedings. It is relevant regulatory context, but it is not a finding that the order caused the cyberattack or proof of what caused the breach.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How to avoid Evolve-breach scams

Scammers may use the incident, a supposed monitoring offer or a settlement payment as a pretext. Treat unexpected requests for payment, passwords, verification codes or sensitive identity information as suspicious. A legitimate settlement communication should not require you to surrender control of your bank account or pay a fee to receive an approved payment.

If you are unsure, close the message and navigate independently to the official Evolve breach page or settlement site. Do not rely on a phone number or link supplied in an unsolicited email or text.

Frequently Asked Questions

Was Evolve Bank hacked?

Yes. Evolve described a 2024 ransomware-related cybersecurity incident and attributed it to the LockBit criminal organization. The bank said data was accessed and downloaded during periods in February and May 2024.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Did the breach affect 7.6 million people?

Evolve’s state filing, reported in July 2024, identified at least 7.6 million affected people. The figure refers to people whose information was accessed, not people proven to have suffered identity theft or financial loss.

Could my fintech account have been included?

Possibly. Evolve served as a banking partner for fintech companies, so some people could be affected without holding an Evolve-branded account. Not every customer of an identified fintech was necessarily included.

What information was exposed?

Potential categories included names, Social Security numbers, dates of birth, contact information, account numbers, routing numbers and ACH records. Debit-card numbers affected a smaller group, and driver’s-license numbers appeared in litigation-related descriptions. The data varied by person.

Were customer funds stolen?

Evolve said it found no evidence that attackers accessed customer funds. That does not rule out later fraud or identity theft involving exposed information.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Can I still file an Evolve settlement claim?

The official settlement FAQ lists October 30, 2025, as the claim deadline, so an ordinary new claim does not appear to be available as of August 18, 2026.

When were settlement payments sent?

The settlement administrator says approved payments were issued on March 30, 2026. Check your status only through the official settlement website.

What if my settlement check is uncashed?

Cash it before September 28, 2026. The settlement FAQ says uncashed checks become void after that date.

Should I buy identity-theft protection?

Not necessarily. Start with free credit freezes, fraud alerts, credit-report reviews, bank alerts, multifactor authentication and FTC recovery resources. Check your original notice before paying for a service that may duplicate an existing benefit.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Written by TheFinanceBase Team

The Team behind TheFinanceBase.

Add your note

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Recommended PC Tool
Recommended PC Tool
Windows Errors? Fix Them Before They SpreadFree repair scan
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.