FEDERALItem 8.01 · voluntaryThird-Party / Supply ChainFinancial ServicesTechnologyFinanceSupply Chain (3P Vendor)Customer Data InvolvedDownstream VictimsPIIFINANCIALLowContained
Evolve Bank & Trust
bd_0306a4446fc3494b · schema v1 · pii pii-v1
Full breach record for Evolve Bank & Trust →Affirm Holdings disclosed via Form 8-K that on June 25, 2024, Evolve Bank & Trust — the third-party issuer of the Affirm Card — notified Affirm of a cybersecurity incident in which an unauthorized third party accessed personal and financial information of Evolve's retail banking customers and fintech-partner customers, including Affirm Card users. Affirm's own systems were not compromised. Evolve indicated the incident was contained; Affirm launched an independent investigation, notified law enforcement and all Affirm Card users, and heightened fraud monitoring.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_1ff6bf62e7850651Oregon State AGfiled 2024-07-08(7d gap)Verified
- bd_75a9fadea4599369Idaho State AGfiled 2024-07-08(7d gap)Verified
- bd_859e2a8aac37b2ffMaine State AGfiled 2024-07-08(7d gap)Verified
- bd_91935c803715a403Montana State AGfiled 2024-07-08(7d gap)Verified
Show 2 more filings ↓Show fewer ↑up to 7d gap
- bd_aa5d4b960051d1e4California State AGfiled 2024-07-08(7d gap)Candidate
- bd_fcb8a565ba7193c7Washington State AGfiled 2024-07-08(7d gap)Candidate
Source provenance
- Source URL
- https://www.sec.gov/Archives/edgar/data/1820953/000182095324000027/afrm-20240625.htm
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Jul 1, 2024
- Raw hash
- dd01d2a4e44d841b6d9dc9a6bb30974d171cc98992bd45d0744a8abbf5773508
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- Affirm Holdings, Inc.norm: affirm holdings
- SEC CIK
- 0001820953
- Domain
- affirm.com
Victim entity
- Name
- Evolve Bank & Trustnorm: evolve bank
- Industry
- Financial ServicesllmTechnologyllm
Incident
- Discovered
- Jun 25, 2024
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIFINANCIAL
- Attack vector
- Third-Party / Supply Chain
- Threat actor
- External
- Regulator citations
- Notified law enforcement
- Third party
- via Evolve Bank & Trust
Compliance
- Time to disclose
- 6 days(6 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.