DisclosureLens
FEDERALItem 8.01 · voluntaryHackingFinancial ServicesTechnologyFinanceStolen CredentialsSupply Chain (3P Vendor)Customer Data InvolvedMulti-Stage ChainPIIFinancial accountIdentity (basic)LowActive

Affirm Holdings, Inc.

bd_0306a4446fc3494b · schema v1 · pii pii-v1

Severity

Low

Discovered

Jun 25, 2024

Filed

Jul 1, 2024

To disclose

6 days

Affected

Not disclosed

Linked

9 filings

Confidence

66%
Full breach record for Affirm Holdings, Inc.

Affirm Holdings disclosed that Evolve Bank & Trust, its third-party card issuer, experienced a cybersecurity incident. Affirm believes Affirm Card user personal and financial information was compromised. Affirm's systems were not breached. Affirm notified law enforcement and users, and heightened fraud monitoring. Investigation is ongoing.

Incident timeline

discovery → filing · 6 days

Jun 25, 2024

Discovered

Jul 1, 2024

Filed

vs. sector median

8 wks faster

This filing is one of 9 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (8) · sorted by filing gap

Show 4 more filingsup to 7d gap

Filing propagation · 9 filings · 8 states

View merged incident ↗

Pattern: first filing Jul 1, last Jul 8 (WA) — a 7-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filing

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statementThis record

Unlocks: materiality, stated response, full audit trail. Ceiling removed.