The Evolve Bank & Trust data breach, widely but mistakenly referred to as the “Bolt Bloodbath,” was discovered in May 2024. The incident was caused by a third-party hack by the ShinyHunters group, which infiltrated Evolve's systems in February 2024. Evolve Bank & Trust disclosed the incident through an 8-K filing and notified clients and authorities. While the initial report referenced Bolt Solutions Inc., the evidence points to Evolve Bank & Trust as the breached entity, impacting its fintech partners like Bilt, Stripe, Wise, Affirm, Dave, and Mercury.
The breach exposed a wide range of sensitive data, including names, addresses, phone numbers, emails, Social Security numbers (SSNs)/employer identification numbers (EINs), account numbers, card numbers, account balances, and transaction histories. Additionally, KYC/KYB documentation, such as images of drivers’ licenses/passports and “selfie” images/videos, were compromised. While a Maine regulatory filing indicated at least 7,640,112 individuals were officially notified, the settlement administrator Kroll identified 17,880,046 unique records of impacted persons. There is no evidence of medical data exposure. The breach primarily affected customers across the U.S. whose data was stored with Evolve Bank & Trust or its fintech partners.
A class action settlement was reached in spring 2024, establishing an $11,858,259.98 common fund for benefits.