Financial technology company Affirm told regulators this week that a cyberattack on a banking partner exposed customer information.
Affirm - which runs one of the biggest buy now, pay later platforms - told the Securities and Exchange Commission on Monday that information about its own customers leaked during a cyberattack on Evolve Bank.
Last week, the bank confirmed that it suffered a cyberattack exposing the personal information of an undisclosed amount of customers.
Affirm partnered with Evolve Bank to issue its Affirm Card, which operates like a debit card but allows users to convert transactions into installment payments.
The company's SEC filing said it shares the personal information of Affirm Card users with Evolve to facilitate the issuance and servicing of cards.
An investigation into the breach is ongoing but Affirm has been told by Evolve Bank that the incident has been contained.
TechCrunch reported last week that Affirm was one of several Evolve customers, including money transfer company Wise, to confirm they were affected by the attack on the bank.
Affirm also shared a breach notification letter it sent to customers on X and created an FAQ page for customers.
On Monday, Evolve Bank confirmed that it had been attacked by the LockBit ransomware gang in late May. The gang falsely claimed it breached the U.S. Federal Reserve but eventually posted data that came from Evolve Bank.
Evolve Bank said it discovered that some of its systems were not working in May and eventually stopped the attack after several days.
The hackers stole names, Social Security numbers, bank account numbers, and contact information of customers as well as employees.
They plan to begin sending out breach notification letters on July 8 offering two years of free credit monitoring and identity theft protection.
LockBit claims cyberattack on Croatia's largest hospital.
Supreme Court to take up Texas law requiring adults verify age to watch porn.
This Cyber News was published on therecord.media. Publication date: Tue, 02 Jul 2024 17:20:22 +0000