LockBit

LockBit is a ransomware group operating a ransomware-as-a-service model, supplying its malware to affiliates who carry out attacks and share the ransom proceeds with LockBit's developers. In February 2024, an international law enforcement operation called Operation Cronos, led by the UK's National Crime Agency and the FBI with support from Europol, Eurojust, and national agencies across Europe, North America, and Asia, seized control of LockBit's infrastructure. The group rebuilt at reduced capacity in the weeks that followed, which is the environment in which the Evolve Bank attack, already underway, continued to unfold.

Evolve Bank & Trust

Evolve Bank & Trust, based in West Memphis, Arkansas, provides banking-as-a-service to numerous fintech companies, offering traditional banking services alongside partnerships with technology-driven financial firms. This dual role places Evolve at the center of a wide network of consumer financial products operated under the hood by other companies.

The Data Breach Incident

LockBit gained access to Evolve's systems after an employee clicked a malicious link, and the group accessed and downloaded data from Evolve's databases and file shares during periods in February and May 2024. Evolve first noticed something was wrong in late May, initially suspecting a hardware failure, before its investigation identified unauthorized activity and the intrusion was stopped. Evolve refused to pay the ransom LockBit demanded, and the group published the stolen data on its dark web forum in late June.

Before Evolve was named, LockBit had claimed to have breached the US Federal Reserve itself, threatening to leak 33 terabytes of Federal Reserve data unless paid. When the group actually released the files, they turned out to belong to Evolve Bank, not the Fed. A Maine attorney general filing later confirmed the breach affected 7,640,112 individuals, with exposed data including names, Social Security numbers, Evolve account numbers, dates of birth, and contact information.

Separately, on June 14, 2024, the Federal Reserve Board issued a cease-and-desist order against Evolve over longstanding deficiencies in its anti-money laundering, risk management, and consumer compliance programs tied to its fintech partnerships. That order addressed issues identified in examinations dating back to 2023 and was unconnected to the ransomware attack, though the two became public within weeks of each other.

Details of the LockBit Post and Data Leak

LockBit's post on its forum claimed responsibility for the breach and mocked the security measures of the institutions it had infiltrated. The leaked data raised significant concerns about identity theft and fraud among affected customers and partners of Evolve Bank. Evolve later offered affected individuals 24 months of complimentary credit monitoring and identity theft protection through TransUnion and Cyberscout.

Impact of the Breach

The breach affected not only Evolve's direct customers but also customers of its fintech partners, including Affirm, Mercury, and Wise, several of which confirmed in SEC filings that they were materially affected. These companies had to notify their own customers and take additional security measures, extending the breach's reach well beyond Evolve's direct customer base.

In April 2025, Evolve agreed to pay $11,858,259.98 to resolve consolidated litigation over the breach, without admitting wrongdoing. An estimated 18 million individuals were made eligible to claim up to $3,000 each in compensation under the settlement.

Conclusion

The Evolve breach illustrates how exposure in banking-as-a-service arrangements extends well past the Bank itself, reaching every fintech company built on top of its infrastructure and, ultimately, their customers too. A single compromised employee credential at one Bank rippled out to affect partner companies and their own users months later, and the eventual settlement cost, alongside the separate and unrelated regulatory order the Bank was already facing, shows how quickly compounding failures across security and compliance can catch up with an institution operating at this scale.

Sources

Federal Reserve Board, "Federal Reserve Board issues an enforcement action against Evolve Bancorp, Inc. and Evolve Bank & Trust." federalreserve.gov/newsevents/pressreleases/enforcement20240614a.htm

Evolve Bank & Trust, "Cybersecurity Incident" notice. getevolved.com/cybersecurity-incident

Evolve Bank & Trust, "Substitute Notice of Data Breach." getevolved.com/substitute-notice-of-data-breach

The Register, "Evolve Bank & Trust confirms LockBit stole 7.6 million people's data." theregister.com/2024/07/09/evolve_lockbit_attack

Dark Reading, "Evolve Bank and Trust Reveals 7M Impacted in LockBit Breach." darkreading.com/cyberattacks-data-breaches/evolve-bank-and-trust-reveals-7m-impacted-in-lockbit-breach

FinTech Futures, "Evolve Bank to pay $11.85m settlement over 2024 data breach." fintechfutures.com/data-privacy-security/evolve-bank-to-pay-11.85m-settlement-over-2024-data-breach