FinWise Bank has revealed that it suffered a major data breach that compromised the personal information of hundreds of thousands of customers. According to disclosures filed by American First Finance (AFF), a partner of the bank, a former FinWise employee was able to gain access to sensitive records, despite having left the company.

The revelation has raised concerns in the financial sector, as it highlights the loopholes that can be left behind by inadequate exit controls. The incident occurred on May 31, 2024, but was not made public until several months later, through documents filed with the Maine Attorney General's office.
What is American First Finance and how is it connected to FinWise?
American First Finance offers financial products such as installment loans and lease-to-own programs, which are used by thousands of consumers to purchase everyday goods and services. FinWise Bank serves as the bank that originates and funds these loans, while AFF handles applications, repayments and customer service.
See also: Burger King removes post revealing security flaws in Drive-Thru systems
The two companies’ collaboration means that a potential security weakness on FinWise’s side has direct consequences for AFF customers. That’s exactly what happened with the recent breach, which is estimated to have affected 600,000–689,000 people, according to different filings and reports.
What was exposed and what wasn't
FinWise confirmed that names and personal data customer by the former employee, but did not specify what data was exposed. It is unclear whether this included financial data such as account numbers or social security numbers.

The lack of transparency has caused discomfort among customers and investors, especially as the bank limited itself to offering free credit monitoring and identity protection for one year, a measure often considered insufficient in such large-scale incidents.
How did the breach occur?
The biggest question that remains unanswered is how a former employee still had active access credentials. In financial institutions, deactivating accounts after employees leave is considered a basic security rule. The fact that it was not implemented properly leaves FinWise open to serious charges of negligence.
See also: New SEO Poisoning Attack Targets Windows Users
Although the bank hired outside cybersecurity consultants to investigate the case, no clear explanation has been given so far. Instead, management simply told the Securities and Exchange Commission (SEC) that about 600,000 customers were affected.
The legal consequences
FinWise is now facing multiple class action lawsuits in the United States. The plaintiffs accuse the bank of inadequate security measures and a failure to protect critical personal data. The litigation is expected to last years and could cost tens of millions of dollars in damages and settlements.
The bank, however, refuses to comment on details due to pending litigation.

The broader message for the banking industry
This incident highlights an often-neglected aspect of security: managing insider threats, that is, threats that come from within an organization. While most companies invest in systems to detect external attacks, it is not uncommon for the greatest damage to be caused by people who have—or had—legal access.
See also: Fairmont Federal Credit Union: Data breach affects 187,000 people
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Experts point out that banks and financial institutions should implement stricter staff offboarding mechanisms, such as automatic account deactivation, regular access checks , and logging of all user actions.
Customers in focus
For consumers, the case is a reminder of the vulnerability of their personal data, even when dealing with institutions. While FinWise offers limited support measures, experts recommend that those affected closely monitor their financial activities, activate alerts for suspicious transactions , and consider freezing credit reports.
Source: www.bleepingcomputer.com
