Affirm Holdings, Inc.

Jun 2024 · Graded Verified · Financial Services · Government record

Incident summary

Affirm Holdings, Inc.Jun 2024
Not yet quantified
VVerified
Affirm's systems were never touched; the breach was at Evolve Bank & Trust, the sponsor bank that issues the Affirm Card and holds the customer data a fintech front end never keeps. One malicious link inside Evolve exposed names, Social Security numbers, and account details across its fintech partners, and reporting credits LockBit, which leaked the file when the ransom went unpaid. When the ledger lives at the sponsor bank, a fintech's own security is beside the point: the bank is the single door everyone's data waits behind.
Financial Services
SEC 8-K, Item 8.01
Initial attack type third-party or supply chain confirmed · Impact data theft confirmed + data extortion · Actor LockBit

About this record

This incident is on the public government record: an SEC 8-K filing or a state-regulator notification, graded Verified. Every figure links to the source it was read from; if we have read one wrong, tell us at info@hackerinahoodie.com. This index never sums figures across incidents. See the methodology.

Cite this incident

← The complete On the Government Record ledger ← Back to the index