In the days after Evolve’s confirmation, financial technology companies began telling their own customers they were affected. Wise and Affirm both did so.
Wise had worked with Evolve between 2020 and 2023 to provide US account details. The partnership had ended the year before the intrusion; the records had not.
Ending A Supplier Relationship Does Not End The Exposure
That is the finding this desk would keep from the whole episode. A company can change partner, migrate its customers, and complete the transition — and the historical records remain wherever they were held, under the retention policy of a company it no longer has a commercial relationship with.
A customer who left the product entirely is in the same position, with even less reason to be watching.
The Notification Chain Is Long And Nobody Controls All Of It
Evolve determines that records were taken. The fintechs determine which of their customers appear in those records. The customer hears from the brand they recognise about a company they do not.
Each hop adds delay, and each party knows only its own segment. The corpus recorded at 24-0620 and 24-1219 how long a single organisation takes to establish scope; a chain multiplies that, and no participant can state the total.
What The Affected Person Is Asked To Do About It
The standard remedy is credit monitoring, offered by one of the parties. The corpus notes throughout that this is a control designed for financial fraud, that no mechanism connects a breach to a subsequent fraud — filed at 25-1219 — and that it transfers the remaining work to the person who had the least influence over any of it.
In a banking-as-a-service arrangement that person also cannot act structurally. There is no supplier to switch away from, because they did not choose the supplier.
Compiled from the fintechs’ own statements as reported and contemporaneous coverage, listed below. Graded high: the disclosures originate with the companies. The dates of the Wise partnership are as reported. No figure is given here for how many customers of any individual fintech were affected, because this desk has not seen reliable per-company counts. Corrections: corrections@forensicpost.com.