[go: up one dir, main page]

Security

Startups scramble to assess fallout from Evolve Bank data breach

Comment

illustration of money raining down
Image Credits: Bryce Durbin / TechCrunch

On Wednesday, Evolve Bank and Trust, a financial institution that’s popular with fintech startups, announced that it had been victim of a cyberattack and data breach that could have affected its partner companies as well.  

The incident, according to the company’s statement, involved “the data and personal information of some Evolve retail bank customers and financial technology partners’ customers.” 

When reached by TechCrunch, Evolve’s communications chief Thomas Holmes said that the incident involves “a known cybercriminal organization.”

“It appears these bad actors have released illegally obtained data, on the dark web,” said Holmes, declining to comment further.

The cybercriminals responsible for the breach appear to be the notorious ransomware gang LockBit, which posted data allegedly stolen from Evolve on its dark web leak site. 

Evolve lists a series of companies on its site as partners that rely on the banking giant to offer some of their financial and lending services. To understand the impact of the Evolve breach on these companies, TechCrunch reached out to Affirm, Airwallex, Alloy, Bond, Branch, Dave, EarnIn, Marqeta, Mastercard, Melio, Mercury, PrizePool, Step, Stripe, TabaPay and Visa. 

Only Affirm, EarnIn, Marqeta and Melio responded to the request for comment. 

Contact Us

Do you have more information about the Evolve breach and how it’s impacting partner companies? From a non-work device, you can contact Lorenzo Franceschi-Bicchierai securely on Signal at +1 917 257 1382, or via Telegram, Keybase and Wire @lorenzofb, or email. You also can contact TechCrunch via SecureDrop.

Affirm spokesperson Matt Gross told TechCrunch that the company is investigating the incident and “will communicate directly with any impacted consumers as we learn more.”

Affirm also alerted its customers in a post on X, writing that the Evolve breach “may have compromised some data and personal information” of Affirm customers. The company also said that it’s safe to use its card and Money Accounts, and that its investigation into the impact of the breach is still ongoing. 

EarnIn spokesperson Stephanie Borman said that the company is “aware of this incident and monitoring it closely.”

Marqeta spokesperson Kelly Kraft told TechCrunch that the company is aware of the breach, and that “Evolve supports a small part of our overall business.”

“Our customers affected by this incident have been notified, and we are working closely with Evolve to understand their remediation effort and how our mutual customers may be impacted,” Kraft said in an email.

Melio co-founder and CEO Matan Bar told TechCrunch that the company is aware of the breach and “diligently working with them to determine if Melio or any of our customers were impacted by it. We will keep our customers informed with any relevant information as we learn more. There have been no disruptions to Melio’s operations as a result of this incident.”

Another Evolve partner, the fintech startup Mercury, said on X that the Evolve breach impacted records associated with the company, “including some account numbers, deposit balances, business owner names, and emails.” 

As more affected companies come forward, the true impact of the Evolve breach on “some Evolve retail bank customers and financial technology partners’ customers” — as the company put it — will likely become clearer. 

Evolve has made headlines recently for other matters related to its fintech partnerships. On June 14, the Federal Reserve ordered Evolve Bank “to bolster its risk management programs around fintech partnerships as well as anti-money laundering laws.”

According to a statement by the Fed, examinations conducted in 2023 found that Evolve “engaged in unsafe and unsound banking practices by failing to have in place an effective risk management framework for those partnerships” with financial technology companies.

The bank has also been associated with the meltdown of banking-as-a-service startup Synapse, which provided a service that allowed others — mainly fintechs — to embed banking services into their offerings. When Synapse filed for bankruptcy this year and an attempted rescue acquisition of its assets by TabaPay fell through, the company pointed blame at its partner bank, Evolve — a saga that continues to play out.

This story was updated to include Marqeta and Melio’s comments.

More TechCrunch

The first defense startup to receive backing from Y Combinator, Ares Industries, launched earlier this week. In a post on the YC website, the startup outlined a vision to build…

Y Combinator backs its first defense startup, Ares Industries

Pavel Durov, founder and CEO of messaging app Telegram, was arrested on Saturday evening while leaving his private jet at France’s Le Bourget airport, as initially reported by French television…

Telegram founder Pavel Durov arrested in France

The Port of Seattle, which also operates the Seattle-Tacoma International Airport, said it was hit with a “possible cyberattack” that appeared to affect websites and phone systems. The port first…

The Port of Seattle and Sea-Tac Airport say they’ve been hit by ‘possible cyberattack’

Travly is a new social-first discovery and hotel booking platform designed to cater to the growing number of travelers who rely on short-form video content for trip ideas.  The platform…

Travly lets travelers submit videos for a chance to earn a 5% commission from hotel bookings

As AI developers and others start to think more deeply about how computers and people intersect, Stephan Wolfram says it is becoming a much more of a philosophical exercise

Stephen Wolfram thinks we need philosophers working on big questions around AI

Featured Article

The 12 biggest take-private PE acquisitions so far this year in tech

A roundup of the year’s billion-dollar take-private deals in the technology sector.

The 12 biggest take-private PE acquisitions so far this year in tech

Eruditus, an Indian edtech startup, is in advanced stages of talks to secure about $150 million in new funding, two sources familiar with the matter told TechCrunch, in what would…

TPG nears $150M funding in India’s Eruditus at $2.3B valuation

Apple will be unveiling new products on September 10, with the announced phones going on sale on September 20, according to a report from Bloomberg’s Mark Gurman. That lineup will…

Apple reportedly announcing iPhone 16 lineup and more on Sept. 10

Featured Article

The fallout after Bolt’s aggressive fundraising attempt has been wild

After fintech Bolt surprised the industry with a leaked term sheet that revealed it is trying to raise at a $14 billion valuation, things got weird.

The fallout after Bolt’s aggressive fundraising attempt has been wild

Boeing’s Starliner mission is coming back to Earth — empty. After months of data analysis and internal deliberation, NASA leadership announced today that Starliner will be coming back to Earth…

Starliner will return to Earth uncrewed, astronauts staying on ISS until February

A surprising number of “iPad kids” — aka Generation Alpha’s 7- to 9-year-old demographic — are using X, according to new data from parental control software maker Qustodio. The firm…

Do you know where your children are? Maybe on X

This week, Google joined a $250 million deal with the state of California to support California newsrooms. While the deal offers a much-needed cash infusion for an industry that’s seen…

Google just made a $250M deal with California to support journalism — here’s what it means

A court order recently forced Elon Musk’s X to reveal its full list of shareholders, as of June 2023, to the public. Many of the recognizable tech industry names had…

X shareholders as of June 2023 included funds tied to Bill Ackman, Binance, and Sean ‘Diddy’ Combs

Featured Article

VCs are so eager for AI startups, they’re buying into each others’ SPVs at high prices

VCs are increasingly buying shares of late-stage startups on the secondary market as they try to get pieces of the hottest ones — especially AI companies. But they are also increasingly doing so through financial instruments called special purpose vehicles (SVPs). Some of those SPVs are becoming such hot commodities…

VCs are so eager for AI startups, they’re buying into each others’ SPVs at high prices

Featured Article

The top AI deals in Europe this year

Cumulatively, there have been more than 1,700 funding rounds for AI startups in Europe so far in 2024.

The top AI deals in Europe this year

After two years of building the company, the company quietly launched its beta in June and is officially announcing it today, right here, in TechCrunch. 

The founder building a wealth-management product her grandmother would have loved

From the looks of things, companies in the category — including Agility Robotics and Formlogic — can’t hire quickly enough.

These 74 robotics companies are hiring

Automatically disappearing posts on social networks could be handy for users who have a habit of deleting their posts through third-party tools, or if the context of those posts is…

Threads confirms it is experimenting with ephemeral posts

Two former OpenAI researchers who resigned this year over safety concerns say they are disappointed but not surprised by OpenAI’s decision to oppose California’s bill to prevent AI disasters, SB…

‘Disappointed but not surprised’: Former employees speak on OpenAI’s opposition to SB 1047

Neil Mehta, the VC behind the acquisition of a string of properties on San Francisco’s tony Fillmore Street, made waves earlier this week for reportedly throwing long-established local restaurants to…

VC Neil Mehta, who’s quietly nabbing prized SF property, plans a “Y Combinator for restaurants”

RealPage, which makes property management software, was sued Friday by the U.S. Justice Department and eight attorneys general for allegedly helping apartment and building managers around the country collude to…

Justice Department sues RealPage over allegedly helping landlords collude to drive up rents

Colorful Capital’s co-founders, William Burckart and Megan Kashner, declined to comment. 

Colorful Capital will stop trying to raise for a fund

Andrew Ng is stepping down from his role as CEO at Landing AI, the computer vision platform he founded in 2017. Dan Maloney, formerly the COO, will take the reins…

Andrew Ng steps back at Landing AI after announcing new fund

AI models are being applied to every dataset under the sun, but are inconsistent in their outcomes. This is as true in the medical world as anywhere else, but a…

Piramidal’s foundation model for brainwaves could supercharge EEGs

No two businesses are the same, and that’s good news: As we saw again this week, it opens up space for companies to try opposite approaches, join forces or challenge…

M&A can open up the playing field for the competition

Featured Article

Marc Andreessen’s family plans to build a ‘visionary’ subdivision near the proposed California Forever utopia city

Marc Andreessen’s family is planning to build a large housing development near the proposed California Forever city.

Marc Andreessen’s family plans to build a ‘visionary’ subdivision near the proposed California Forever utopia city

EV startup Canoo’s chief technology officer Sohel Merchant has left the company, two people familiar with his departure have told TechCrunch. Merchant was one of the members of Canoo’s founding…

Canoo’s chief technology officer is out amid wider reorg

A company spokesperson for the oil drilling and fracking giant declined to name the executive overseeing cybersecurity, if any.

Halliburton shuts down systems after cyberattack

The move is an effort to squeeze additional revenue from second-hand products, over concerns that cheaper, slightly used bikes, treadmills and rowers could cannibalize used sales.

Peloton adds $95 activation fee for used equipment

Time is running out! These are the last hours to save up to $600 on TechCrunch Disrupt 2024 tickets — offer ends tonight at 11:59 p.m. PT. Join 10,000+ startup…

Last day for massive ticket savings to TechCrunch Disrupt 2024