Evolve Bank & Trust (Evolve) is sending out alerts about a breach data affecting 7.6 million U.S. citizens. The data theft resulted from a recent ransomware attack (LockBit).

In June, the LockBit falsely claimed to have breached the Federal Reserve. It was later determined that the data belonged to Evolve Bank & Trust. Evolve confirmed that the data belonged to them and launched an investigation into the incident.
The investigation revealed that an employee clicked on a malicious link, which gave hackers access to Evolve's database and shared files. The attackers then downloaded some files.
See also: Fujitsu: Customer data breach
Evolve Bank & Trust said customer funds remained safe, but the attack led to a data breach that has affected several fintech. Affirm, Wise and Bilt confirmed that the Lockbit attack on Evolve affected customers .
Now, the company is sending notifications to individuals whose personal information was stolen. In a filing with the Office of the Attorney General of Maine, Evolve Bank & Trust says that 7,640,112 individuals were affected by the data breach.
The breach was detected on May 29, 2024, as some systems were not functioning properly.
However, the investigation showed that the initial breach occurred on February 9, 2024, which means the hackers were in the company's network for about four months.
See also: Neiman Marcus: Data breach exposes 31 million email addresses
Evolve offers credit monitoring and identity for U.S. residents and dark web monitoring services for international residents. Recipients of breach notifications must register by October 31, 2024.

Those affected should be very careful in the coming period, as their information can be used for malicious activities.
Following this incident, the company should experts cybersecurity to identify the weak points in its system and take appropriate protective measures. This collaboration is essential to prevent future attacks and strengthen data security.
See also: Shopify denies data breach
Additionally, the company needs to strengthen its security policies and procedures , including training staff on cybersecurity. As it turned out, the attack was initiated by opening a malicious link. Employees should be trained so they can recognize a potential threat.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: www.bleepingcomputer.com
