Skip to content

Evolve Bank & Trust

Disclosed Jun 26, 20242 years ago7,640,112 affectedConfirmed

Official notice

LockBit ransomware attack on Evolve Bank exposes data of 7.6 million people

Evolve Bank & Trust said LockBit ransomware actors downloaded customer data in February and May 2024, affecting most of its personal banking customers and customers of fintech partners such as Wise, Affirm and Mercury. TechCrunch reported Evolve later confirmed about 7.6 million people were affected.

What is known

People affected7,640,112 (as reported by the organization)
DisclosedJun 26, 2024
DiscoveredMay 29, 2024
HappenedFeb 9, 2024
AttackRansomware
Data exposedNames, Credentials and tokens, Social Security numbers, Dates of birth, Financial, Phone numbers, Emails, Addresses, Employment
SectorFinance · US
StatusConfirmed

Sources

Source
California Attorney General breach notice: Evolve Bank & Trustoag.ca.gov · Official notice
Washington Attorney General breach notice: Evolve Bank & Trustatg.wa.gov · Official notice
Notice letter filed with the Delaware DOJ: Evolve Bank and Trustattorneygeneral.delaware.gov · Official notice
Oregon DOJ breach notice: Evolve Bank & Trustjustice.oregon.gov · Official notice
California AG breach notice: Evolve Bank & Trustoag.ca.gov · Regulator
A timeline of ransomware in 2024techcrunch.com · News
Cybersecurity Incident - Evolve Bank & Trustgetevolved.com · The organization
Indiana Attorney General 2024 data breach report: Evolve Bank & Trustin.gov · Official notice

Notices filed

WhereFiledPeople
ResearchtotalJun 26, 20247,600,000
California AGresidents of CAJul 8, 2024
Washington AGresidents of WAJul 8, 2024275,716
Delaware DOJresidents of DEJul 8, 202427,417
Oregon DOJresidents of ORJul 8, 202464,904
Indiana AGresidents of INJul 8, 2024149,930
History of this record
  • 2026-09-25 · records: 7600000 to 7640112 · backfill source
  • 2026-09-25 · data_types: ["names","credentials"] to ["names","credentials","ssn","dob","financial","phone","emails","addresses","employment"] · seed source
  • 2026-09-25 · records: 7640112 to 7600000 · seed source
  • 2026-09-25 · disclosed: 2024-07-08 to 2024-06-26 · seed source
  • 2026-09-25 · summary: empty to Evolve Bank & Trust said LockBit ransomware actors downloaded customer data in February and May 2024, affecting most of its personal banking customers and customers of fintech partners such as Wise, Affirm and Mercury. TechCrunch reported E · seed source
  • 2026-09-25 · title: empty to LockBit ransomware attack on Evolve Bank exposes data of 7.6 million people · seed source
  • 2026-09-25 · data_types: [] to ["names","credentials"] · backfill source
  • 2026-09-25 · records_basis: empty to organization · backfill source
  • 2026-09-25 · records: empty to 7640112 · backfill source
  • 2026-09-25 · attack: unknown to ransomware · backfill source
  • 2026-09-25 · discovered: empty to 2024-05-29 · backfill source
  • 2026-09-25 · occurred: empty to 2024-02-09 · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.

Everything about Evolve Bank & Trust

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.