Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
Evolve Bank & Trust said a LockBit ransomware attack exposed and downloaded customer and partner information in 2024. The incident was not a breach of the Federal Reserve, despite LockBit’s initial claim. Evolve said there was no evidence attackers accessed customer funds, but names, Social Security numbers, bank-account numbers and other personal information may have been exposed.
The breach also created downstream risk for fintech customers. Wise said its own systems were not compromised but that information shared with Evolve for U.S.-dollar account services could have been affected. Affirm said information belonging to some Affirm Card users was believed to have been compromised through Evolve, while Affirm’s systems and card functionality remained available. Dave later disclosed improper disclosure of some members’ information.
What happened at Evolve Bank?
Evolve attributed the incident to LockBit ransomware. According to the bank, an employee clicked a malicious link, allowing attackers to enter its systems. The attackers accessed and downloaded data, then deployed file-encrypting ransomware.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Evolve said it had backups, refused to pay the ransom and later saw the stolen information leaked online. LockBit initially claimed the material came from the Federal Reserve, but the leaked files were subsequently identified as originating from Evolve Bank & Trust—not the Federal Reserve. The contemporary incident report did not establish that the Federal Reserve had been breached.
#1 Best Overall
Evolve said the relevant access or download activity occurred during periods in February and May 2024. Affirm said Evolve notified it on June 25, 2024, and LockBit leaked the material on June 26. The incident details were reported on July 2, 2024. Those dates describe a historical breach, not a new 2026 event.
What information may have been exposed?
The exact records and affected population were still under investigation when Evolve and the fintech companies first disclosed the incident. The following are reported data categories, not proof that every affected person had every listed field exposed.
Evolve customers and employees
Evolve said potentially obtained information included:
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
- Names
- Social Security numbers
- Bank-account numbers
- Contact information
- Information belonging to personal-banking customers
- Information belonging to Open Banking partners’ customers
- Likely personal information belonging to employees
Wise customers
Wise said data it had supplied to Evolve for U.S.-dollar account details could have included a customer’s name, address, date of birth, contact details and, for U.S. customers, a Social Security number or employer identification number. Non-U.S. customers may have provided another identity-document number.
That list describes information Wise shared with Evolve—not necessarily information that attackers downloaded. Wise said Evolve had not confirmed which specific Wise records were affected, and Wise said its own systems were not compromised.
Affirm Card users
In a Form 8-K filed with the SEC, Affirm said personal information belonging to some Affirm Card users was believed to have been compromised because Evolve provided card-issuing and servicing functions.
Affirm did not establish that all Affirm Card users were affected or identify every compromised field. The disclosure concerned the Evolve-linked Affirm Card relationship, not necessarily all Affirm customers or products.
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Dave members
Dave later disclosed in its 2024 Form 10-K that the incident involved improper disclosure of some members’ information. The reported categories included names, Social Security numbers, partner-bank account numbers, dates of birth and contact information.
Dave’s disclosure supports treating the incident as broader than an isolated Affirm-related exposure, but it does not mean every Dave member—or every customer of every Evolve-linked fintech—was affected.
Which fintech companies were affected?
| Company or program | What was reported | Were its own systems compromised? | Confidence |
|---|---|---|---|
| Wise | Information supplied to Evolve for U.S.-dollar account services may have been affected. | Wise said no. | Wise’s statement was reported in contemporary coverage. |
| Affirm Card | Affirm believed personal information belonging to some card users may have been compromised through Evolve. | Affirm said no. | Affirm’s SEC filing. |
| Dave | Later SEC disclosures acknowledged improper disclosure of some members’ information. | Not established by the cited filing. | Dave’s SEC filing. |
| Other reported Evolve-linked firms | Mercury, Branch, EarnIn, Yotta, Bitfinex, Copper and Nomad were mentioned in reporting or industry discussions. | Unknown from the available evidence. | Do not treat these names as confirmed victims without a company-specific notice. |
A relationship with Evolve does not automatically prove that a company’s customers were exposed. The most accurate classifications are:
- Confirmed company impact: the company disclosed affected or potentially affected customers.
- Potential data presence: the company shared information with Evolve, but the bank had not confirmed which records were accessed.
- Unverified reporting: a company appeared in leaked-data analysis or industry commentary without a clear company confirmation.
Were customer funds stolen?
Evolve said there was no evidence that attackers accessed customer funds. That is narrower than saying no one suffered financial harm. Exposed bank-account numbers and identity information can support phishing, impersonation, account takeover or payment fraud later.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Clear out junk files and repair common Windows errors3Scan for outdated or missing drivers - takes under a minuteThe incident should therefore be separated into distinct risks:
- Data exposure: personal or financial information may have been accessed or downloaded.
- Account compromise: an attacker gains control of a customer account.
- Unauthorized transfer: money is moved without the customer’s authorization.
- Identity theft: exposed identity data is used for fraud.
The available evidence supports the first risk and did not show that Evolve customers’ funds had been accessed at the time of its statement. It does not prove that every account was hacked or guarantee that no later fraud occurred.
Were Wise or Affirm’s systems breached?
For the companies covered by the strongest disclosures, the exposure occurred at Evolve rather than through an intrusion into their own networks. Wise said its systems were not impacted. Affirm said its information systems were not compromised and that Affirm Card users could continue transacting.
This is a third-party exposure event: a fintech can protect its own network while customers’ information is exposed at a bank partner that stores or processes that information.
Why could one bank affect so many fintech customers?
Many fintech applications rely on regulated partner banks for services such as deposit accounts, card issuance, payment processing and other banking functions. Those banks may hold or process personally identifiable and financial information for multiple programs.
Best Value
Evolve was therefore more than a software vendor. It was a banking and card-issuing partner for different fintech programs. That arrangement helps fintech companies launch products without becoming banks themselves, but it creates concentration risk: one partner-bank incident can affect customers who know the fintech brand but may not know which bank handles their account or data.
Dave’s SEC disclosures illustrate this dependency, describing Evolve as a provider of banking, deposit-account and debit-card services. Dave also discussed the potential operational impact of disruption or regulatory restrictions affecting a bank partner.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What affected customers should do
- Check for a direct notice. Review messages from Evolve or the relevant fintech, but access the company through its known website or app rather than links in unsolicited messages.
- Be alert for convincing phishing. Do not provide passwords, one-time codes, account numbers or identity documents in response to unexpected calls, emails or texts.
- Change reused passwords. Update passwords used on affected services and anywhere else they were reused. Enable multifactor authentication, especially on email, banking and fintech accounts.
- Monitor accounts. Review bank, card and fintech activity for unfamiliar transactions, new payees, login alerts or profile changes.
- Consider a credit freeze or fraud alert. If a Social Security number or comparable identity number may have been exposed, U.S. consumers can contact the three nationwide credit bureaus. A freeze or alert can make new-account fraud harder, but it does not erase exposed information or prevent every type of fraud.
- Review recovery settings. Confirm that email addresses and phone numbers are correct and use account-recovery protections where available. Exposed contact information can make SIM-swap and account-takeover attempts more persuasive.
- Keep documentation. Save breach notices, support correspondence and records of suspicious activity in case an identity-theft report or transaction dispute becomes necessary.
What remains unknown?
The initial disclosures did not establish:
- the exact number of affected individuals;
- the exact records downloaded;
- which data fields were exposed for each fintech program;
- whether every company named in third-party reporting had data in the leaked files; or
- whether later fraud resulted from the exposure.
That uncertainty matters. A customer may have information stored with Evolve without being in the accessed dataset, while another customer may have had several sensitive fields exposed. Only a direct notice from the relevant company or a later regulatory disclosure can establish an individual program’s confirmed scope.
The broader lesson for fintech customers
The Evolve incident demonstrates the difference between a fintech brand and the regulated institutions supporting its products. Consumers should identify the bank behind a deposit account or card, understand which company handles support and security notifications, and avoid assuming that protection of one company’s systems protects every organization in the service chain.
It also shows why a ransomware incident has multiple consequences. System encryption may disrupt operations, unauthorized access may expose data, and a public leak may create long-term identity and phishing risks—even when backups limit downtime and there is no evidence of stolen funds.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

