Desk live·
ForensicPost
Ransomware/Finance/File 24-0626

Seven Point Six Million, From a Bank Most of Them Had Not Heard Of

Evolve confirmed the intrusion, traced to an employee following a malicious link. The affected population included customers of financial apps that were not banks.

Constructed geometry · not a chart of case data
JurisdictionUSAMemphis, Tennesseethe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetEvolve Bank & Trust
ActorLockBit
D. Kennedy13 min readConfidence: high3 sources reviewed

Evolve Bank & Trust confirmed that data had been stolen, reporting the intrusion as beginning when an employee followed a malicious link, and identified in late May 2024. The affected population was subsequently reported at around 7.6 million people.

The material included names, Social Security numbers, dates of birth and account information.

Banking-As-A-Service Is The Structure That Matters Here

Evolve provides the regulated banking layer behind financial technology products. A consumer opens an account in an app, and the deposits sit at a partner bank the app has chosen.

So the customer relationship, the brand and the interface belong to one company, and the regulated institution actually holding the record is another. The corpus files this under concentration — but the usual version is a supplier the affected person has never heard of, and here it is a bank they were arguably banking with without knowing.

The Initial Access Is The Ordinary Kind Again

An employee followed a link. The corpus recorded the same account at Ascension in 24-0509 and refused the conclusion it invites, on the grounds that an attack needing only an ordinary mistake is worse than one needing an exceptional failure, because ordinary mistakes are guaranteed.

What is not established here — as there — is what allowed one click to reach the records of 7.6 million people. That is the question a defender would want answered and it is not in anything this desk has seen.

The Disclosure Came Out Under Pressure

The confirmation followed the group’s public claim rather than preceding it. That ordering is common in this database and it shapes what a reader should take from a first statement: the organisation is describing an event that is already public.

How we reported this

Compiled from the company’s statements and contemporaneous reporting, listed below. Graded high: the intrusion and the initial-access account originate with the organisation, and the affected-person figure comes from its notification. What allowed the access to reach the records it reached is not established and is not inferred here. Corrections: corrections@forensicpost.com.

Sources
  1. Substitute notice of data breachEvolve Bank & Trust
  2. Evolve hack impacts 7.6M people, including Wise customersCybernews
  3. Evolve Bank shares data breach details as fintech firms report being hitSecurityWeek
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary