Evolve Bank & Trust Ransomware Incident: 7.6 Million Records Exposed
Evolve Bank & Trust officially reported a ransomware attack that impacted approximately 7.6 million individuals. The breach, which occurred in May 2024, exposed sensitive personal information including names, Social Security numbers, bank account numbers, and contact information.
- State
- TN
- Affected
- 7,600,000
- Breach date
- May 29, 2024
- Reported
- March 5, 2026
What may have been exposed
- names
- Social Security numbers
- bank account numbers
- contact information
Evolve Bank & Trust, based in Tennessee, has formally disclosed a significant data security incident stemming from a ransomware attack. Public filings indicate the breach event occurred on May 29, 2024, with the official report submitted to regulators on March 5, 2026.
The incident resulted in the unauthorized access to and potential exposure of personal data belonging to approximately 7.6 million individuals. The categories of information confirmed to be affected include names, Social Security numbers, bank account numbers, and contact information.
The ransomware group identified as LockBit claimed responsibility for the attack, subsequently publishing data that they asserted was taken from Evolve Bank & Trust. This compromised data reportedly pertained to both direct customers of the bank and individuals associated with its fintech partners. The matter is currently under active investigation.
Individuals who have been notified or believe they may be affected by this breach should monitor their financial accounts and credit reports closely for any suspicious activity. Reviewing statements for unauthorized transactions can help in early detection of potential misuse.
As a precautionary measure, consider placing a fraud alert or security freeze on your credit files with the major credit bureaus. This can help prevent new accounts from being opened in your name without your authorization. Additionally, be wary of unsolicited communications, as exposed contact information could be used in phishing attempts.