Evolve Bank & Trust confirmed that data had been stolen, reporting the intrusion as beginning when an employee followed a malicious link, and identified in late May 2024. The affected population was subsequently reported at around 7.6 million people.
The material included names, Social Security numbers, dates of birth and account information.
Banking-As-A-Service Is The Structure That Matters Here
Evolve provides the regulated banking layer behind financial technology products. A consumer opens an account in an app, and the deposits sit at a partner bank the app has chosen.
So the customer relationship, the brand and the interface belong to one company, and the regulated institution actually holding the record is another. The corpus files this under concentration — but the usual version is a supplier the affected person has never heard of, and here it is a bank they were arguably banking with without knowing.
The Initial Access Is The Ordinary Kind Again
An employee followed a link. The corpus recorded the same account at Ascension in 24-0509 and refused the conclusion it invites, on the grounds that an attack needing only an ordinary mistake is worse than one needing an exceptional failure, because ordinary mistakes are guaranteed.
What is not established here — as there — is what allowed one click to reach the records of 7.6 million people. That is the question a defender would want answered and it is not in anything this desk has seen.
The Disclosure Came Out Under Pressure
The confirmation followed the group’s public claim rather than preceding it. That ordering is common in this database and it shapes what a reader should take from a first statement: the organisation is describing an event that is already public.
Compiled from the company’s statements and contemporaneous reporting, listed below. Graded high: the intrusion and the initial-access account originate with the organisation, and the affected-person figure comes from its notification. What allowed the access to reach the records it reached is not established and is not inferred here. Corrections: corrections@forensicpost.com.