The 2024 breach happened at Evolve Bank & Trust, not in Wise’s systems. Wise said some current or former customers who used its USD account-details service may have had identifying information stored at Evolve involved. Wise said its accounts, passwords, cards, card numbers, PINs and customer funds were not affected. The exposure is a reason to watch for phishing and identity fraud—not evidence that a Wise balance or login was stolen.
What happened in the Evolve Bank breach?
Evolve said it identified system problems in late May 2024 and later determined that attackers had accessed its systems. The bank attributed the incident to LockBit ransomware and said an employee had inadvertently clicked a malicious link. Evolve reported that files were accessed and downloaded during periods in February and May 2024, and that it found no new unauthorized activity after May 31, 2024. Evolve refused to pay the ransom and said downloaded data was later leaked. Evolve’s incident statement describes its account of the attack and response.
Wise’s public notice, last updated December 20, 2024, says the incident was resolved in July 2024. Wise said it would continue monitoring the situation and update its notice if needed. That status reflects Wise’s published account, rather than an independent forensic finding. Wise’s notice about the Evolve incident is the source for its customer-specific statements.
Why did Evolve have information about Wise customers?
Wise said it worked with Evolve, a regulated U.S. bank, from 2020 through 2023 to provide USD account details. Evolve needed identifying information to provide that service. Wise said it no longer worked with Evolve and that another bank provided USD account details by the time Wise published its notice. The former relationship means someone who used the relevant Wise USD details during 2020–2023 may be relevant even if they no longer use Wise.
#1 Best Overall
Wise said customers could continue using their Wise accounts and USD details normally because those details were no longer connected to Evolve. It did not advise customers to close accounts. Wise’s explanation of the former relationship gives the service context.
What information may have been exposed?
Information Wise said it had shared
Wise said identifying information it shared with Evolve could include a customer’s name, address, date of birth and contact details. For U.S. customers, it could include a Social Security number or EIN; for non-U.S. customers, it could include another identity-document number. Wise said Evolve had not confirmed which data was actually affected when Wise published its notice. These are possible categories in records shared for the service, not confirmation that every Wise customer’s record—or every listed field—was exposed.
Information in Evolve’s broader incident
Evolve’s later substitute notice described a broader set of data involved across its incident: names, Social Security numbers, Evolve account numbers, dates of birth, contact information, debit-card numbers for a small portion of individuals, and ACH records with account numbers, routing numbers, and payor and payee names. That description applies to the overall Evolve incident; it does not establish that all those fields belonged to Wise-linked records. Evolve’s substitute notice lists those categories.
Were Wise accounts, passwords, cards or money compromised?
Wise said its own systems were not affected, and that Wise account credentials and passwords, cards, card numbers and PINs were safe. Wise also said customers could continue using their accounts. Evolve separately said it found no evidence that criminals accessed customer funds. These statements distinguish potential exposure of identity records from theft of login credentials, unauthorized transactions or direct loss of money; they do not establish that every type of identity fraud is impossible. Wise’s account of what was not affected and Evolve’s incident FAQ provide the respective statements.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Scan for outdated or missing drivers - takes under a minute3Clear out junk files and repair common Windows errorsWho was notified, and what if you did not receive a message?
Wise said it would email customers it believed might have been affected. Evolve said it began individual notifications on July 8, 2024 and expected further, smaller notification rounds as its investigation progressed. Not receiving a message does not prove that a person’s data was or was not involved: Wise did not publicly quantify the Wise-customer subset or specify every record it believed affected. Evolve’s overall notification process is separate from Wise’s customer outreach.
A message about the incident can itself be a phishing attempt. Evolve warned that legitimate incident notifications came from email addresses it identified in its statement, and that messages from other addresses were not legitimate. Check the current guidance on Evolve’s incident page rather than relying on a sender name, caller ID or a link in an unexpected email.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What should a current or former Wise customer do?
Verify the message without using its links
- Do not click links or open attachments in an unexpected breach message. Open the Wise app yourself or type Wise’s website address into your browser.
- Use the official Wise Help Centre or Evolve’s incident page to check guidance. Do not call a number supplied in an unsolicited message.
- Never disclose a password, PIN, one-time passcode or full login credentials in response to a call or email. Be suspicious of urgent demands to “secure” an account, move money, or pay for monitoring.
Check account activity and preserve evidence
Review Wise activity for unfamiliar transfers, recipients, login alerts or changes to account details, and check other financial accounts if you see a suspicious transaction. Contact the institution through its official app or website if something is wrong. Keep suspicious emails, message details, transaction records and, where available, email headers before deleting anything; they may help the institution investigate or support a fraud report.
Protect U.S. identity information where appropriate
If you are a U.S. customer and are concerned that an SSN or other identity information may have been involved, a credit freeze can make it harder for someone to open new credit using your identity. It does not secure a Wise login, protect existing payment accounts, or prevent every kind of identity fraud. A fraud alert asks creditors to take additional steps to verify identity, while credit monitoring reports certain activity after it occurs; neither is a substitute for a freeze if preventing new-credit applications is the priority.
Best Value
| Measure | What it does | Official resource |
|---|---|---|
| Credit freeze | Restricts access to a credit file for new-credit applications; does not prevent all fraud or protect account credentials. | Equifax, Experian and TransUnion |
| Fraud alert | Asks creditors to take extra steps to verify identity; it is less restrictive than a freeze. | Evolve advised consumers to establish free alerts with Equifax, Experian and TransUnion in its incident guidance. |
| Credit reports | Lets you review report information; checking a report is not continuous monitoring or prevention. | AnnualCreditReport.com, the federally authorized source for free U.S. credit reports |
Evolve said U.S. residents who received its notice would receive two years of credit monitoring and identity protection; it said international residents would receive dark-web monitoring where available. Check the terms in any direct Evolve notice rather than assuming eligibility or coverage. For suspected identity theft, the free FTC IdentityTheft.gov service offers reporting and recovery guidance. Evolve also recommended monitoring account activity and credit reports in its incident statement.
Change a password only when there is a reason
This breach alone does not establish a need to reset a Wise password: Wise said its credentials were not affected. Change it if you reused that password elsewhere, entered it after following a suspicious link, disclosed it to someone, or see an unfamiliar login or account change. Use a unique password, and follow any security prompt shown inside your own Wise account rather than a link in a message.
For customers outside the United States, the relevant identifier and options for credit or identity protection vary by country. The U.S. bureau links above apply to U.S. credit files, not every national identity system.
What remains unconfirmed for Wise customers?
- Wise did not publicly state how many of its customers were affected.
- Its notice did not identify the exact Wise-customer records involved or confirm which fields were actually exposed for each person.
- Evolve’s broader data-category list does not prove that all those data types appeared in records associated with Wise.
For an individual customer, Wise’s statement is that it would contact people it believed might have been affected; the public notice does not provide a way to infer exposure from account status alone. Use official Wise or Evolve channels for incident-specific questions.
Free tools Windows power users keep installed
One-click scans. No signup required.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




