Evolve Bank & Trust
ent_019de224a62665bc5a13a8dfcdfc0877
Disclosures
10
State AG · SEC 8-K · 9 jurisdictions
Incidents
2
filings grouped by incident
Max affected reported
7,640,112
nationwide · State AG IN
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Evolve Bank & Trust
- Normalized
- evolve bank— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300IRXW9RSZM2B951
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (10)newest first
- ⛰️New Hampshire State AGas victim2024-08-30
State AG breach notification filed by Evolve Bank & Trust in New Hampshire on August 30, 2024. The attached PDF content was empty, preventing extraction of incident details, dates, or data types.
- 🏎️Indiana State AGas victim2024-07-08
Evolve Bank & Trust reported a data breach to the Indiana Attorney General. The breach occurred on 2024-02-09 and was reported on 2024-07-08. 149,930 Indiana residents were affected. 7,640,112 individuals affected in total.
- 🦫Oregon State AGas victim2024-07-08
Evolve Bank & Trust reported a data breach to the Oregon Attorney General. The breach was reported on 2024-07-08. The breach occurred during 2/9/2024 - 5/31/2024. The breach was discovered on 5/29/2024. 64,904 individuals were affected. Notice was sent on 7/8/2024.
- 🥔Idaho State AGas victim2024-07-08
Evolve Bank & Trust notified Idaho AG on July 8, 2024, of a security event discovered May 29, 2024. Unauthorized actors accessed and downloaded customer data (names, SSNs, bank account numbers) in February and May 2024. Approximately 29,728 Idaho residents were affected. The bank stopped the attack, engaged forensic specialists, notified law enforcement, and offered 24 months of credit monitoring. No customer funds were accessed.
- ⛰️New Hampshire State AGas victim2024-07-08
Evolve Bank & Trust notified New Hampshire residents of a cybersecurity attack where threat actors accessed and downloaded customer information from databases and file shares in February and May 2024. The bank identified the unauthorized activity on May 29, 2024, stopped the attack, engaged a cybersecurity firm, and notified law enforcement. Affected individuals are offered TransUnion credit monitoring services.
- 🦞Maine State AGas victim2024-07-08
Evolve Bank & Trust, a Memphis-based financial services provider offering Banking-as-a-Service, experienced an external cybersecurity attack. Threat actors accessed and downloaded customer data from databases and a file share during periods in February and May 2024. The breach was discovered on May 29, 2024, and contained by May 31, 2024. Approximately 7,640,112 individuals were affected nationally; 20,970 Maine residents. Notifications sent July 8, 2024. No customer funds were impacted.
- 🦬Montana State AGas victim2024-07-08
Evolve Bank & Trust reported a data breach to the Montana Attorney General. The breach was reported on 2024-07-08. The breach occurred from 5/1/2024 to 5/31/2023. 38,740 Montana residents were affected.
- 🐻California State AGas victim2024-07-08
Evolve Bank & Trust experienced a cybersecurity attack where threat actors accessed and downloaded customer information from databases and file shares during periods in February and May 2024. The incident was identified on May 29, 2024, and contained by May 31, 2024. No customer funds were accessed. Evolve engaged a cybersecurity firm, notified law enforcement, and is offering 24 months of credit monitoring to affected individuals.
- 🌲Washington State AGas victim2024-07-08
Evolve Bank & Trust, a finance sector entity reported a ransomware incident to the Washington Attorney General. The organization became aware of the incident on 2024-05-29 and filed notice on 2024-07-08. 275,716 Washington residents were affected. 40 days elapsed between awareness and notification. 110 days to identify the breach. 2 days to contain the breach.
- FEDERALSEC 8-Kas victim2024-07-01
Affirm Holdings disclosed via Form 8-K that on June 25, 2024, Evolve Bank & Trust — the third-party issuer of the Affirm Card — notified Affirm of a cybersecurity incident in which an unauthorized third party accessed personal and financial information of Evolve's retail banking customers and fintech-partner customers, including Affirm Card users. Affirm's own systems were not compromised. Evolve indicated the incident was contained; Affirm launched an independent investigation, notified law enforcement and all Affirm Card users, and heightened fraud monitoring.