Data Breach Watch logoDBW
    Banking
    High
    closed
    Updated about 1 month ago

    Evolve Bank & Trust Data Breach

    Key takeaways

    • Reports suggest a potential breach involving Evolve Bank & Trust.
    • Discovered on November 11, 2024.
    • Possible data exposed: Name, Address, Phone, Email, SSN, EIN, Account Number, Credit Card Number, Account Balance, Transaction History, Driver's License, Passport, Selfie Images/Videos.
    • Affects individuals in: Maine, Tennessee.
    • Confirmation level: Confirmed by regulators.

    Breach confirmed

    The Evolve Bank & Trust breach is confirmed. If you may be affected, add your details below and we will take it from there.

    Detailed summary

    The Evolve Bank & Trust data breach, widely but mistakenly referred to as the “Bolt Bloodbath,” was discovered in May 2024. The incident was caused by a third-party hack by the ShinyHunters group, which infiltrated Evolve's systems in February 2024. Evolve Bank & Trust disclosed the incident through an 8-K filing and notified clients and authorities. While the initial report referenced Bolt Solutions Inc., the evidence points to Evolve Bank & Trust as the breached entity, impacting its fintech partners like Bilt, Stripe, Wise, Affirm, Dave, and Mercury.

    The breach exposed a wide range of sensitive data, including names, addresses, phone numbers, emails, Social Security numbers (SSNs)/employer identification numbers (EINs), account numbers, card numbers, account balances, and transaction histories. Additionally, KYC/KYB documentation, such as images of drivers’ licenses/passports and “selfie” images/videos, were compromised. While a Maine regulatory filing indicated at least 7,640,112 individuals were officially notified, the settlement administrator Kroll identified 17,880,046 unique records of impacted persons. There is no evidence of medical data exposure. The breach primarily affected customers across the U.S. whose data was stored with Evolve Bank & Trust or its fintech partners.

    A class action settlement was reached in spring 2024, establishing an $11,858,259.98 common fund for benefits.

    Data possibly involved

    • Name
    • Address
      Could be combined with other data for identity theft
    • Phone
    • Email
      Increases risk of phishing attacks and account takeovers
    • SSN
      Can be used to open fraudulent accounts and file false tax returns
    • EIN
    • Account Number
    • Credit Card Number
      May result in unauthorized charges on your accounts
    • Account Balance
    • Transaction History
    • Driver's License
      Can be used for identity fraud
    • Passport
    • Selfie Images/Videos

    Company Response Timeline

    Response Grade
    A

    Notified consumers within 30 days of discovery

    Breach Occurred

    Feb 1, 2024

    Company Discovered

    May 1, 2024

    Regulator Notified

    Unknown

    Consumers Notified

    May 1, 2024

    90 days to discover
    0 days to notify consumers

    Breach Verification Status

    Reports Only

    Complete

    Initial dark web reports of potential breach

    Company Confirmed

    Complete

    Company has acknowledged the breach

    Regulator Confirmed

    Current

    Confirmed by regulatory authorities

    Note: Breach verification can take time. Information may evolve as more details become available from companies and regulators.

    Case Status:
    Case Closed

    This case has been concluded.

    Were You Affected By This Breach?

    If you are a customer or have received a data breach notification, you may submit your information as part of our ongoing investigation. Submitting your information is free and does not obligate you.

    Were you in the Evolve Bank & Trust breach? Check your email

    Free scan against known breach datasets. Then remove your info from data-broker sites with Data Shield.

    No signup required. 30-second scan. Your email is only stored if you opt into alerts.

    Get your info off data-broker sites

    Data Shield files removal requests with every broker that accepts an authorized agent, and gives you the exact link or letter for the brokers that only accept requests from you.

    See how Data Shield works

    Check Your Risk Level

    Answer a few questions to understand how this breach might affect you

    What should I do?

    Change your passwords

    Update passwords for the affected service and any accounts using the same password

    Enable two-factor authentication

    Add an extra layer of security to your accounts

    Monitor your accounts

    Watch for suspicious activity on your financial and online accounts

    Watch for phishing attempts

    Be cautious of emails or messages claiming to be from the affected company

    Consider a credit freeze

    Prevent unauthorized access to your credit report

    Scan your email for other exposures

    Check whether this address shows up in other known breaches. Free, no account.

    Get your info off data-broker sites

    Data Shield files removal requests with every broker that accepts an authorized agent, and gives you the exact link or letter for the brokers that only accept requests from you.

    See how Data Shield works

    Got a notice about this breach?

    Paste it into BreachBrief to see exactly what data was exposed, how serious it is, and what to do next.

    Protect yourself

    Share This Breach Alert

    Help friends and family who might be affected by sharing this breach information

    Are you a law firm investigating this breach?

    Get qualified claimant leads delivered directly to your CRM.

    Related breaches

    Stay informed about breaches like this one

    We'll notify you when new data breaches are reported. Free, no spam. Unsubscribe anytime.

    Free, no spam. Unsubscribe anytime.