Desk live·
ForensicPost
Breaches/Finance/File 26-0112

Team 313 Outage Left 20,000 Chime Users Unable to Access Accounts

A group operating as Team 313 caused an outage at Chime on 1 April 2026 that at its peak left an estimated 20,000 or more users unable to check balances, transfer funds or pay bills.

Constructed geometry · not a chart of case data
TargetChime
ActorTeam 313
S. Rosler11 min readConfidence: medium1 source reviewed

On 1 April 2026 a group operating as Team 313, also described as The Islamic Cyber Resistance, caused a widespread outage at the digital banking provider Chime. At its peak an estimated 20,000 or more users were unable to access balances, transfer funds or pay bills. Separate breach litigation has been reported against the company.

Availability Failure Is The Whole Harm Here

This desk has argued repeatedly — at BridgePay in 26-0209, at Foster City in 26-0310 — that availability is the half of the security triad nobody files. This is a clean example.

No data need have been taken for the harm to be real. A person who cannot pay rent on the day it is due experiences a concrete loss, and it does not appear in any breach statistic.

The Affected Population Is The Point

App-only banking is used disproportionately by people underserved by traditional banks — those without a nearby branch, without the balances that attract relationship banking, or living paycheque to paycheque.

That population has the least financial slack to absorb an outage. There is no branch to visit, no overdraft to lean on, and frequently no second account. The customers most affected by a digital-only service failing are the ones least able to route around it.

On The Branding

This desk treats a politically-framed group name as a claim about identity, not a finding. Ideological branding is cheap to adopt, it attracts coverage, and it can equally serve to obscure a straightforwardly criminal or opportunistic operation.

We record the name the group used and attribute nothing further. Graded medium: the outage and its scale are consistently reported; the mechanism and the group’s actual composition are not established.

How we reported this

Compiled from public reporting, listed below. The group name is self-declared and we treat any political framing as unverified. Reported litigation contains untested allegations. Corrections: corrections@forensicpost.com.

Sources
  1. Chime layoffs: 150 jobs cut while breach lawsuit targets app-only banking customersTech Times
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary