Driver FixRecommendedSound, Wi-Fi or graphics acting up? Check drivers firstFind missing or outdated drivers fast.Check DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsSlow PC?RecommendedPC slow today? Run a repair scan before it gets worseResolve common Windows issues and optimize system performance.Scan Now×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

Wise customers and the 2024 Evolve Bank data breach: what was exposed and what to do

Wise customers may have had personal information exposed in Evolve Bank’s 2024 breach. Wise says its systems, passwords, cards, PINs and account access were not compromised.
From TheFinanceBase Team5 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Wise disclosed on July 1, 2024 that personal information belonging to some customers may have been involved in a breach at Evolve Bank & Trust, a former provider of Wise USD account details. Wise says its own systems, passwords, cards, PINs and account access were not compromised. Its help page says the incident was resolved in July 2024.

What happened to Wise customers?

Wise previously worked with Evolve Bank & Trust to provide USD account details. According to Wise, that relationship ran from 2020 through 2023; USD account details are now provided by another bank. During the 2024 Evolve cybersecurity incident, information that Evolve held for some Wise customers may have been exposed.

This was a third-party data exposure, not a compromise of Wise’s infrastructure. Wise’s official guidance, last updated December 20, 2024, says the incident was resolved in July 2024 and that customers it believed were affected would be contacted directly. The original disclosure was reported on July 1, 2024 by TechCrunch.

What information may have been involved?

Wise said it had shared certain identifying information with Evolve, but Evolve had not confirmed which specific records were actually affected. Information shared with a bank is therefore not the same as information confirmed to have been accessed or downloaded.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Customer group Information Wise said could have been shared with Evolve What is confirmed
U.S. customers Name, address, date of birth, contact details, and Social Security number or employer identification number (SSN or EIN) Evolve had not confirmed to Wise which fields were affected
Non-U.S. customers Name, address, date of birth, contact details, and another identity-document number Evolve had not confirmed to Wise which fields were affected

Wise did not publicly specify how many of its customers were affected. Nothing in the public notices establishes that every Wise customer, every former customer, or every person with USD account details was included.

Were Wise accounts, cards or money compromised?

Wise says its systems were not affected. Customers could continue using their Wise accounts, USD account details and Wise cards. Wise also says account credentials, card numbers and PINs were not affected.

The notice does not report that Wise customer funds were stolen. Evolve’s statement, as reported by TechCrunch, said there was no evidence that criminals accessed customer funds. Those statements reduce the indication of an immediate account-takeover or balance-loss event, but they do not eliminate the identity-theft and phishing risks that can follow exposure of personal information.

What Evolve said about the 2024 incident

TechCrunch reported Evolve’s description of the event as a ransomware attack associated with the LockBit group. Evolve said attackers accessed and downloaded customer information from databases and a file share during periods in February and May 2024, while encrypting some data. These details are Evolve’s account as reported by TechCrunch, not an independent finding that every Wise-related record was downloaded.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Who may be affected?

The relevant population is likely to center on people whose Wise USD account details were connected to Evolve during the 2020–2023 relationship. A former Wise customer can still be relevant because records from that period may have remained with the former banking partner. Conversely, being a current Wise customer does not by itself show that a person’s information was stored at Evolve.

Wise has not published a Wise-specific number of affected customers in the sources cited here. It also has not publicly identified the exact records accessed, whether every potentially affected person was ultimately notified, or any confirmed cases of identity theft resulting from the incident.

How Wise says it will contact affected customers

Wise said it would email customers it believed might have been affected. Treat an unexpected message cautiously even if it uses accurate details about Wise or Evolve. A breach notification should never require you to disclose a password, one-time verification code or card PIN.

Wise warns that it will not:

  • Ask for your two-step verification code.
  • Tell you to change your password to a specific phrase.
  • Instruct you to move money to a specified account.
  • Ask you to ignore an unfamiliar transaction notification.
  • Claim to coordinate in real time with another bank while requesting sensitive action.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What potentially affected customers should do

  1. Sign in independently. Open the Wise app or type the Wise website address yourself rather than using a link in an email or text.
  2. Check for an in-account notice. Look for a direct Wise message indicating whether Wise identified your information as potentially affected.
  3. Expect phishing attempts. Be especially wary of messages mentioning Evolve, USD account details, tax information, identity verification, refunds or urgent account action.
  4. Protect authentication data. Do not disclose your password, one-time code, PIN, recovery details or full identity-document information in response to an unsolicited contact.
  5. Review accounts and credit files. Watch bank, card and other financial accounts for unfamiliar activity, and review your credit reports for accounts or inquiries you do not recognize.
  6. Consider a U.S. fraud alert. U.S. customers can place a free initial fraud alert with any one of the three major credit bureaus; that bureau must notify the other two.
  7. Report suspected identity theft. Use the Federal Trade Commission’s identity-theft reporting service and, when appropriate, contact your state attorney general or local police department.

Wise’s notice does not call for closing an account or replacing a card solely because of this incident. Since Wise says cards and account access were not impacted, take those steps only if you identify separate suspicious activity or Wise specifically instructs you to do so.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How this fits the wider Evolve fallout

Evolve was a banking-as-a-service provider for multiple fintech companies. The July 1, 2024 report said partners including Affirm, EarnIn, Marqeta, Melio and Mercury were investigating possible customer impact. Those companies did not necessarily hold the same records or involve the same customers as Wise, so another partner’s disclosure cannot be used to infer what happened to Wise users.

What remains unknown

  • The exact number of Wise customers affected.
  • Which individual records, if any, were accessed for a particular customer.
  • Whether every person whose information may have been involved received a direct notification.
  • Whether any Wise customer suffered identity theft or fraud because of the exposure.

Bottom line

According to Wise, the 2024 Evolve event was a possible exposure of personal information held by a former banking partner, not a breach of Wise’s own systems. Wise says account credentials, card numbers, PINs and account functionality were unaffected, and its help page records the incident as resolved in July 2024. Continue monitoring for phishing and identity fraud, but do not assume that your Wise balance, password or card was breached.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase07 MAR 2625 minWhat Is a 457 Plan?
  2. The Money DeskBlogTheFinanceBase07 MAR 2621 minTime Value of Money: What It Is and How It Works
  3. The Money DeskBlogTheFinanceBase07 MAR 2627 minAre You Living in One of These Top 10 Most Expensive Cities to Retire?
Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.