Event Briefing / Event

Evolve Bank confirms cyber attack and data breach

OUR TAKE The incident not only poses a challenge to Evolve Bank’s reputation, but also highlights the growing cybersecurity threats facing financial institutions in the digital age. The government and regulators will closely monitor the progress of this incident and may further strengthen the securi…

Evolve Bank confirms cyber attack and data breach
Caption: Evolve Bank visual context for BTW intelligence coverage. · Source context: Existing article media was retained or restored as the subject-specific visual basis. · Relevance reason: Evolve Bank is the primary subject or event subject; the image supports the article's market reading. · Image provenance: Existing curated article image retained because it is subject- or event-specific and not a generic pool placeholder.

Sources

Public references used for this article.

External references will appear here after editorial citation review.

CategoryEvent

Evolve Bank is covered for market relevance.

RegionAsia Pacific

Evolve Bank matters because public evidence connects it to internet infrastructure, governance, market, or operational-dependency signals.

Signal FocusMarket

Evolve Bank matters because public evidence connects it to internet infrastructure, governance, market, or operational-dependency signals.

Content TypeEvent

The public signal carries medium impact across infrastructure visibility, relationship movement, and operational dependency.

Primary DomainSecurity

The public signal carries medium impact across infrastructure visibility, relationship movement, and operational dependency.

TopicMarket

OUR TAKE The incident not only poses a challenge to Evolve Bank’s reputation, but also highlights the growing cybersecurity threats facing financial institutions in the digital age. The government and regulators will closely monitor the progress of this incident and may further strengthen the securi…

ImpactMedium

The public signal carries medium impact across infrastructure visibility, relationship movement, and operational dependency.

Confidence?Confidence Grade
0.90–1.00AHigh — direct sources
0.75–0.89A/BStrong
0.55–0.74B/CMedium
0.35–0.54C/DWeak–medium
0.10–0.34DWeak signal
0.00–0.09DInternal monitoring
Good confidence (82%)

Published reporting

Evolve Bank is a BTW intelligence profile anchored in public article evidence, object context, event links, and relationship watchpoints.

Evolve Bank and Trust confirmed on Wednesday it was the victim of a cybersecurity incident that involved customers’ data being illegally released on the dark web. Lockbit 3.0, the hacking group behind the Evolve leak, functions as a ransomware-as-a-service group. OUR TAKE The incident not only poses a challenge to Evolve Bank’s reputation, but also highlights the growing cybersecurity threats facing financial institutions in the digital age.

The government and regulators will closely monitor the progress of this incident and may further strengthen the security standards and compliance requirements of the financial industry to deal with potential threats in the future. –Revel Cheng, BTW reporter Evolve Bank and Trust confirmed on Wednesday it was the victim of a cybersecurity incident that involved customers’ data being illegally released on the dark web.

What happened Evolve Bank & Trust confirmed it was the victim of a cyber attack and that customer data had been posted on the dark web, less than two weeks after the Arkansas-based lender was ordered by regulators to improve its risk management and get approval before entering into any new partnerships. The Russian-linked hacker group LockBit 3.0 on Tuesday posted data taken from Evolve’s systems after claiming earlier in the week that it had hacked the US Federal Reserve, giving US officials until Tuesday afternoon to pay an undisclosed amount in exchange for the information purportedly stolen from the central bank’s systems.

So far, it does not appear that any sensitive data from the Fed has been released by the group. A spokesperson for Evolve said in an email that the incident has been contained and the company is currently investigating the situation with “appropriate law enforcement authorities.” The bank also said it will offer all affected customers complimentary credit monitoring with identity theft protection services. It’s still unclear exactly what information was included in the data, which Evolve said was stolen by a “known cybercriminal organisation” without naming LockBit.

Also read: Digital banking’s essential shift Also read: Bank of America puts banking, investing, retirement into one app Why it’s important Lockbit 3.0, the hacking group behind the Evolve leak, functions as a ransomware-as-a-service gang, where members lease their technical tools to affiliates and take a percentage of any extortion payments. The group posted the Evolve information on a darkweb forum tied to Lockbit, a prolific ransomware gang that has received millions of dollars in payments following attacks on thousands of victims, including the Industrial & Commercial Bank of China Ltd., Boeing Co and the UK’s Royal Mail.

By 2022, the group had rebranded itself as LockBit 3.0. In February, law enforcement agencies from 11 countries led by the UK’s National Crime Agency and aided by the US Federal Bureau of Investigations–seized LockBit’s technical tools in an operation that targeted its malware deployment system. But the group’s hacking tools have remained widely used since they were leaked to the public in 2022, and members of the group are believed to remain active. The compromised information included tax identification numbers, as well as wires and settlements, linked to people who have directly and indirectly worked with Evolve, according to Dirce E.

Hernandez, a cybersecurity expert with experience in insurance and financial services who has spoken to analysts familiar with the data.

Event Brief

  • Event: Evolve Bank confirms cyber attack and data breach
  • Signal Type: Market
  • Region: Asia Pacific
  • Classification: Company

Affected Area

  • Published sources should identify the affected parties, operating surface, and market exposure before this event map is treated as complete.

Legal and Market Context

  • The article supports medium-impact monitoring of infrastructure visibility, relationship movement, and operational dependency.
  • Operational relevance: Medium
  • Time horizon: Next quarter

What To Watch

  • Watch for official statements, regulatory updates, customer or partner exposure, and follow-up disclosures.

Member Briefing

Deeper Event Context

Login is required to unlock the full event briefing and source notes.

Only for Strategy Circle

Strategic Circle Access

Open to all readers. Unlock event briefings after joining and logging in.

Join Strategic Circle

Only for Leadership Alliance

Leadership Alliance Access

For operators, investors, and policy teams that need relationship evidence, failure paths, and source notes. Login required to unlock.

Join Leadership Alliance
← BackAll Events