Desk live·
ForensicPost
Ransomware/Concentration/File 24-0702

Wise and Affirm Customers Exposed by a Breach at a Firm They Never Chose

Wise and Affirm told customers their data had been exposed in a breach at a company they had never chosen. One of them had ended the partnership the previous year.

Constructed geometry · not a chart of case data
JurisdictionUSAthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetFintech customers
ActorLockBit
S. Rosler13 min readConfidence: high3 sources reviewed

In the days after Evolve’s confirmation, financial technology companies began telling their own customers they were affected. Wise and Affirm both did so.

Wise had worked with Evolve between 2020 and 2023 to provide US account details. The partnership had ended the year before the intrusion; the records had not.

Ending A Supplier Relationship Does Not End The Exposure

That is the finding this desk would keep from the whole episode. A company can change partner, migrate its customers, and complete the transition — and the historical records remain wherever they were held, under the retention policy of a company it no longer has a commercial relationship with.

A customer who left the product entirely is in the same position, with even less reason to be watching.

The Notification Chain Is Long And Nobody Controls All Of It

Evolve determines that records were taken. The fintechs determine which of their customers appear in those records. The customer hears from the brand they recognise about a company they do not.

Each hop adds delay, and each party knows only its own segment. The corpus recorded at 24-0620 and 24-1219 how long a single organisation takes to establish scope; a chain multiplies that, and no participant can state the total.

What The Affected Person Is Asked To Do About It

The standard remedy is credit monitoring, offered by one of the parties. The corpus notes throughout that this is a control designed for financial fraud, that no mechanism connects a breach to a subsequent fraud — filed at 25-1219 — and that it transfers the remaining work to the person who had the least influence over any of it.

In a banking-as-a-service arrangement that person also cannot act structurally. There is no supplier to switch away from, because they did not choose the supplier.

How we reported this

Compiled from the fintechs’ own statements as reported and contemporaneous coverage, listed below. Graded high: the disclosures originate with the companies. The dates of the Wise partnership are as reported. No figure is given here for how many customers of any individual fintech were affected, because this desk has not seen reliable per-company counts. Corrections: corrections@forensicpost.com.

Sources
  1. Fintech company Affirm says Evolve Bank attack exposed customer infoThe Record
  2. Evolve Bank data breach impacted fintech firms Wise and AffirmSecurity Affairs
  3. A data breach at Evolve is hurting its many fintech partnersAmerican Banker
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary