HackingFinancial ServicesFinanceCapture Stored DataData ExfiltratedCustomer Data InvolvedDelayed DiscoveryPIIFINANCIALMediumContained
Evolve Bank & Trust
bd_859e2a8aac37b2ff · schema v1 · pii pii-v1
Full breach record for Evolve Bank & Trust →Evolve Bank & Trust, a Memphis-based financial services provider offering Banking-as-a-Service, experienced an external cybersecurity attack. Threat actors accessed and downloaded customer data from databases and a file share during periods in February and May 2024. The breach was discovered on May 29, 2024, and contained by May 31, 2024. Approximately 7,640,112 individuals were affected nationally; 20,970 Maine residents. Notifications sent July 8, 2024. No customer funds were impacted.
Maine clockDiscovered May 29, 2024 → Filed with AG Jul 8, 202440d ⏱ ME AG >30d6 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_1ff6bf62e7850651Oregon State AGfiled 2024-07-08Verified
- bd_75a9fadea4599369Idaho State AGfiled 2024-07-08Verified
- bd_91935c803715a403Montana State AGfiled 2024-07-08Verified
- bd_aa5d4b960051d1e4California State AGfiled 2024-07-08Candidate
Show 2 more filings ↓Show fewer ↑up to 7d gap
- bd_fcb8a565ba7193c7Washington State AGfiled 2024-07-08Candidate
- bd_0306a4446fc3494bSEC 8-Kfiled 2024-07-01(7d gap)Candidate
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/a2e61e38-f78d-403d-9abb-3810771bb5d2.html
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 8, 2024
- Raw hash
- 6813d7117b9fd2b2fe87643572fe6f272f142cb85a43e6d2c6d7935f2daa48c3
Reporting entity
- Name
- Evolve Bank & Trustnorm: evolve bank
- Domain
- evolvebank.com
- Industry
- Financial Services
Victim entity
- Name
- Evolve Bank & Trustnorm: evolve bank
- Domain
- evolvebank.com
- Industry
- Financial Services
- Industry
- Financial Servicesllm
Incident
- Discovered
- May 29, 2024
- Materiality determined
- —
- Notification sent
- Jul 8, 2024
- Affected individuals
- 20,970
- Data types
- PIIFINANCIAL
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- law enforcement notified
Compliance
- Time to disclose
- 6 weeks(40 days from discovery to filing)
- Compliance flags
- ME AG >30d · 40d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: May 29, 2024→ Filed with AG: Jul 8, 202440d 30 days (soft) ME AG >30d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.