Live data from Hacker News

Evolve Bank and Trust confirms LockBit stole 7.6M people's data

theregister.com

11–20 of 83 posts

Re: Evolve Bank and Trust confirms LockBit stole 7.6M people's data

#11
post #6

Can someone explain why in the world Evolve has my data? (I use Mercury and Wise for my company). I tried going to their website and I'm still completely clueless. Edit: Apparently Mercury was using Evolve as their banking partner. I know this is super common w/ online neobanks, but I'm really confused as to why they always choose the most random obscure bank. Why not partner with a major bank, or Column?

After Wise moved away from Evolve to Community Federal Savings Bank, they gave me new account details that included an address in New York.

Looking that up on Google Maps and Street View, it appeared to be a small branch in Brooklyn, on a street that looked immediately familiar to me as the starting area in Grand Theft Auto IV.

Re: Evolve Bank and Trust confirms LockBit stole 7.6M people's data

#12
post #6

Can someone explain why in the world Evolve has my data? (I use Mercury and Wise for my company). I tried going to their website and I'm still completely clueless. Edit: Apparently Mercury was using Evolve as their banking partner. I know this is super common w/ online neobanks, but I'm really confused as to why they always choose the most random obscure bank. Why not partner with a major bank, or Column?

An act of Congress (I believe it was Dodd-Frank) capped debit card fees at a very low amount (fractions of a precent). An exception was left in for small banks to continue to charge credit-card-like rates for debit cards, around 2%.

Since then, every fintech has had essentially the same business model:

- Come up with some kind of "innovative" thing to sell consumers on that results in them generating debit card transactions. (Online bank account, instant international money transfer, loan, etc.) - the trick is that to get the money, you swipe that debit card.

- Partner with some small bank so that they are one the one providing the debit card. The law essentially has a loophole on it allowing this.

- The fintech company sets up essentially everything, with all the small bank does is have automated accounts created for cardholders when the fintech's software says so. No money is kept in the customer account until the moment of that debit card swipe - then it is instantly transferred in and instantly transferred back out for the payment.

- This requires reserves, but the fintechs and small banks collaborate on how to get good interest on the reserves involved.

There are now fintechs which offer "fintech as a service" which will set all of this up for a tiny bank who can then offer this to any other fintech with almost no involvement from the tiny bank. All they have to do is sign a few papers.

The definition of a big or small bank is based on the amount on deposit, so they are careful to not actually have any money on deposit.

Congress needs to correct this abuse, immediately, and only allow the larger debit card fees for traditional checking accounts held by consumers where the money involved is held on deposit at that bank.

Edit: one of the major problems here is that small banks are often not staffed for adequate cybersecurity for global operations like these; they do just fine doing hometown community banking, but are very vulnerable to being cracked like this. Yet another reason small banks that are providing big-bank services should be regulated like big banks.

Re: Evolve Bank and Trust confirms LockBit stole 7.6M people's data

#14
post #6

Can someone explain why in the world Evolve has my data? (I use Mercury and Wise for my company). I tried going to their website and I'm still completely clueless. Edit: Apparently Mercury was using Evolve as their banking partner. I know this is super common w/ online neobanks, but I'm really confused as to why they always choose the most random obscure bank. Why not partner with a major bank, or Column?

> but I'm really confused as to why they always choose the most random obscure bank. Why not partner with a major bank.

Because major banks won't support startups looking to compete with them. Why would JPM, BoA, etc. service Mercury who is going after their SMB business banking vertical? Banking is a cartel in the US. The bank lobby makes it as hard as possible to compete with them.

Re: Evolve Bank and Trust confirms LockBit stole 7.6M people's data

#15
post #6

Can someone explain why in the world Evolve has my data? (I use Mercury and Wise for my company). I tried going to their website and I'm still completely clueless. Edit: Apparently Mercury was using Evolve as their banking partner. I know this is super common w/ online neobanks, but I'm really confused as to why they always choose the most random obscure bank. Why not partner with a major bank, or Column?

An act of Congress (I believe it was Dodd-Frank) capped debit card fees at a very low amount (fractions of a precent). An exception was left in for small banks to continue to charge credit-card-like rates for debit cards, around 2%. Since then, every fintech has had essentially the same business model: - Come up with some kind of "innovative" thing to sell consumers on that results in them generating debit card trans…

The key to keeping debit card fees down isn't to legislate a fee cap, it's to make payment rails more open and competitive.

Why are regulators still attacking stablecoins, for example, when they represent one type of innovation that could actually lower transaction costs? Creating a legislative framework that encourages innovation rather than stifles it would make a lot more sense than trying to micromanage fees.

Re: Evolve Bank and Trust confirms LockBit stole 7.6M people's data

#16
post #6

Can someone explain why in the world Evolve has my data? (I use Mercury and Wise for my company). I tried going to their website and I'm still completely clueless. Edit: Apparently Mercury was using Evolve as their banking partner. I know this is super common w/ online neobanks, but I'm really confused as to why they always choose the most random obscure bank. Why not partner with a major bank, or Column?

> Why not partner with a major bank, or Column?

Yeah, why didn't Mercury partner with a well-established, vetted, and recognized bank like SVB?

Re: Evolve Bank and Trust confirms LockBit stole 7.6M people's data

#17
post #15

Earlier quoted context omitted.

An act of Congress (I believe it was Dodd-Frank) capped debit card fees at a very low amount (fractions of a precent). An exception was left in for small banks to continue to charge credit-card-like rates for debit cards, around 2%. Since then, every fintech has had essentially the same business model: - Come up with some kind of "innovative" thing to sell consumers on that results in them generating debit card trans…

The key to keeping debit card fees down isn't to legislate a fee cap, it's to make payment rails more open and competitive. Why are regulators still attacking stablecoins, for example, when they represent one type of innovation that could actually lower transaction costs? Creating a legislative framework that encourages innovation rather than stifles it would make a lot more sense than trying to micromanage fees.

https://news.ycombinator.com/item?id=36801491 ("HN: FedNow Is Live")

https://www.frbservices.org/financial-services/fednow/organi...

https://explore.fednow.org/explore-the-city?id=3&building=ne...

$25/month to plug into FedNow instant payment rails, 5 cents to move up to $100k in value (initial limit, max is $500k), 20 second settlement SLA.

Re: Evolve Bank and Trust confirms LockBit stole 7.6M people's data

#18
post #6

Can someone explain why in the world Evolve has my data? (I use Mercury and Wise for my company). I tried going to their website and I'm still completely clueless. Edit: Apparently Mercury was using Evolve as their banking partner. I know this is super common w/ online neobanks, but I'm really confused as to why they always choose the most random obscure bank. Why not partner with a major bank, or Column?

[deleted]

Re: Evolve Bank and Trust confirms LockBit stole 7.6M people's data

#19
post #15

Earlier quoted context omitted.

The key to keeping debit card fees down isn't to legislate a fee cap, it's to make payment rails more open and competitive. Why are regulators still attacking stablecoins, for example, when they represent one type of innovation that could actually lower transaction costs? Creating a legislative framework that encourages innovation rather than stifles it would make a lot more sense than trying to micromanage fees.

https://news.ycombinator.com/item?id=36801491 ("HN: FedNow Is Live") https://www.frbservices.org/financial-services/fednow/organi... https://explore.fednow.org/explore-the-city?id=3&building=ne... $25/month to plug into FedNow instant payment rails, 5 cents to move up to $100k in value (initial limit, max is $500k), 20 second settlement SLA.

This technically exists but can you actually use it? It seems like there are no articles about it in the 2024 calendar year.

I remember reading a really nice screed from walmart last year pushing the fed to turn the screws on rent seekers, but without RFP and ubiquitous participation that isnt going to come about.

bit of a conspiracy here but IMO banks have been observing the fraud rates with zelle, venmo, etc and only tolerating it because an external party gets to be the bogeyman.

Re: Evolve Bank and Trust confirms LockBit stole 7.6M people's data

#20

As the article explains any Wise (a fintech popular for travel debit cards and cheap intl money transfers) that had USD balance was exposed with the breach.

That doesn’t seem right to me. Wise moved away from EBT a year or so ago. They may not be done moving away from them but my Wise USD balance is not with EBT anymore and they confirmed by email I was not affected by the breach.

How did you get them to confirm for you? The best I got was

“Right now, we know it is possible some of your personal information may have been breached. We do not have further details to share, but we encourage you to stay vigilant in monitoring your financial activity.

Please be advised that Wise remains secure, as is your account. This breach did not impact our systems. However, keep an eye on any suspicious activity and make sure to report it.”

Post reply on HN