HackingCapture Stored DataData ExfiltratedCustomer Data InvolvedDelayed DiscoveryPIIIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
Evolve Bank & Trust
bd_aa5d4b960051d1e4 · schema v1 · pii pii-v1
Full breach record for Evolve Bank & Trust →Evolve Bank & Trust experienced a cybersecurity attack where threat actors accessed and downloaded customer information from databases and file shares during periods in February and May 2024. The incident was identified on May 29, 2024, and contained by May 31, 2024. No customer funds were accessed. Evolve engaged a cybersecurity firm, notified law enforcement, and is offering 24 months of credit monitoring to affected individuals.
California clockDiscovered May 29, 2024 → Notified Jul 8, 202440d ✓ CA 60-day OK6 weeks discovery → filing
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_1ff6bf62e7850651Oregon State AGfiled 2024-07-08Verified
- bd_75a9fadea4599369Idaho State AGfiled 2024-07-08Verified
- bd_859e2a8aac37b2ffMaine State AGfiled 2024-07-08Verified
- bd_91935c803715a403Montana State AGfiled 2024-07-08Verified
Show 2 more filings ↓Show fewer ↑up to 7d gap
- bd_fcb8a565ba7193c7Washington State AGfiled 2024-07-08Candidate
- bd_0306a4446fc3494bSEC 8-Kfiled 2024-07-01(7d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-588210
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 8, 2024
- Raw hash
- 08b118ead72b36b3026a6957a99df41a5c3593b444a936587242c9f6ed3c94f2
Reporting entity
- Name
- Evolve Bank & Trustnorm: evolve bank
Victim entity
- Name
- Evolve Bank & Trustnorm: evolve bank
Incident
- Discovered
- May 29, 2024
- Materiality determined
- —
- Notification sent
- Jul 8, 2024
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 ChannelT1119 Automated Collection
- Threat actor
- External
- Regulator citations
- Notified law enforcement
Compliance
- Time to disclose
- 6 weeks(40 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 40d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: May 29, 2024→ Notified: Jul 8, 202440d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.