Live data from Hacker News

Evolve Bank and Trust confirms LockBit stole 7.6M people's data

theregister.com

51–60 of 83 posts

Re: Evolve Bank and Trust confirms LockBit stole 7.6M people's data

#51

Earlier quoted context omitted.

The data breach did not cause the collapse of Synapse. Synapse has been a slow rolling collapse for the past 2ish years due to horrible management. Ultimately Synapse imploded when Mercury left Synapse as a BaaS provider to partner directly with Evolve BT. The Synapse collapse definitely put Evolve into the spotlight as someone with a ton of turmoil, lack of sufficient oversight and insufficient technological governa…

Wow, Mercury’s account and routing numbers were all leaked, along with all KYC info? Is there a way to confirm that? Their email made it sound much less serious. (Apropos nothing, sorry about your motorcycle accident — I hope you’ve recovered well. Thank you for this comment; the severity of this breach wasn’t apparent till now.)

Is now afraid to get on my motorcycle today. If you linked an external account, then most likely. However, it is my understanding that Mercury had a very relaxed KYC and I would suppose their user are not impacted by external accounts. The more likely victim of external accounts are B2B participants of partners of Evolve. This would most likely be true for Shopify. FWIW, routing numbers are public. Other data included in the hack is Evolve's emails in the form of outlook data files. Affirm is another definite impacted individual. VA loan data is probably also included in this hack.

Re: Evolve Bank and Trust confirms LockBit stole 7.6M people's data

#52
post #28

Evolve is the bank that actually holds the assets for Synapse, the money-transfer company that shut down recently. That was on HN a few days ago.[1] Are these incidents related? [1] https://news.ycombinator.com/item?id=40877346

Doubtful, if only because data breaches never(?) kill companies. Thanks for pointing that article out. It made me reconsider whether it’s wise to keep money in Mercury. EDIT: this rabbit hole goes deep. https://techcrunch.com/2024/05/16/a-us-trustee-wants-trouble... "San Francisco-based Synapse, which operated a platform enabling banks and fintech companies to develop financial services, was founded in 2014 by Bryan…

Mercury itself is not FDIC insured. If Mercury collapses, your money is not insured. If Evolve collapses, your money is insured. That's the official stance.

The majority of the banking industry is built on Cobol. Open Banking is the only real path forward. The issue of the US vs EU open-banking is the number of community banks.

The, unfortunate, most reliable banks from a technology/data perspective are ones that are large enough to be loathsome to deal with. Think JP Morgan, BoA.

Even banks of that size, Comerica, have had massive ledgering issues recently, so they are not immune.

Some reputable players in the BaaS industry are Unit, JP Morgan, Jack Henry, Moov(Massive plug for them), VGS (works with Visa and MC btw). If your neo-bank works with them, I would trust my money there. I do trust my money with one of those partners.

Re: Evolve Bank and Trust confirms LockBit stole 7.6M people's data

#53
post #28

Evolve is the bank that actually holds the assets for Synapse, the money-transfer company that shut down recently. That was on HN a few days ago.[1] Are these incidents related? [1] https://news.ycombinator.com/item?id=40877346

Doubtful, if only because data breaches never(?) kill companies. Thanks for pointing that article out. It made me reconsider whether it’s wise to keep money in Mercury. EDIT: this rabbit hole goes deep. https://techcrunch.com/2024/05/16/a-us-trustee-wants-trouble... "San Francisco-based Synapse, which operated a platform enabling banks and fintech companies to develop financial services, was founded in 2014 by Bryan…

The question is, if you have money stuck in Synapse, were records at Evolve that would help retrieve it compromised?

"The collapse of middleman Synapse has revealed fintech’s promise of safety as a mirage. More than 100,000 Americans with $265 million in deposits have been locked out of their accounts."[1]

Evolve has problems: Fed report on Evolve: "Examinations conducted in 2023 found that Evolve engaged in unsafe and unsound banking practices by failing to have in place an effective risk management framework for those partnerships. In addition, Evolve did not maintain an effective risk management program or controls sufficient to comply with anti-money laundering laws and laws protecting consumers."[2]

The combination of a collapse on the fintech side, bad risk management on the bank side, and a "hack" looks bad. It also raises the possibility that the "hack" might be an inside job to cover up theft. We've seen that happen in crypto land more than once.

[1] https://www.cnbc.com/2024/07/02/synapse-fintech-fdic-false-p...

[2] https://www.federalreserve.gov/newsevents/pressreleases/enfo...

Re: Evolve Bank and Trust confirms LockBit stole 7.6M people's data

#54

Earlier quoted context omitted.

Doubtful, if only because data breaches never(?) kill companies. Thanks for pointing that article out. It made me reconsider whether it’s wise to keep money in Mercury. EDIT: this rabbit hole goes deep. https://techcrunch.com/2024/05/16/a-us-trustee-wants-trouble... "San Francisco-based Synapse, which operated a platform enabling banks and fintech companies to develop financial services, was founded in 2014 by Bryan…

Mercury itself is not FDIC insured. If Mercury collapses, your money is not insured. If Evolve collapses, your money is insured. That's the official stance. The majority of the banking industry is built on Cobol. Open Banking is the only real path forward. The issue of the US vs EU open-banking is the number of community banks. The, unfortunate, most reliable banks from a technology/data perspective are ones that are…

> Mercury itself is not FDIC insured. If Mercury collapses, your money is not insured.

How is it not false advertising on the part of Mercury to describe their accounts as FDIC-insured if this is the case?

Re: Evolve Bank and Trust confirms LockBit stole 7.6M people's data

#55
post #20

Earlier quoted context omitted.

How did you get them to confirm for you? The best I got was “Right now, we know it is possible some of your personal information may have been breached. We do not have further details to share, but we encourage you to stay vigilant in monitoring your financial activity. Please be advised that Wise remains secure, as is your account. This breach did not impact our systems. However, keep an eye on any suspicious activi…

Here is the email I received on June 28: There’s been a data breach at Evolve Bank & Trust. Evolve Bank & Trust is a regulated bank that we worked with from 2020 until 2023 to provide your old USD account details. They’ve recently been affected by a data breach and some of your personal information may have been involved. This personal information does not include copies of any of the identification documents you’ve…

I've asked them: a) _what_ details may have been involved. Currently the criminals know more than we do. b) why EBT had any data if Wise stopped working with then in 2023.

I'd except there to be a fairly strong obligation (probably on both parties) under GDPR to ensure that EBT destroyed that data.

I'll be following up

Re: Evolve Bank and Trust confirms LockBit stole 7.6M people's data

#56
post #48

This thread seems as good a place as any to ask. I have a Mercury account for a now defunct/non-existent company, but Mercury refused to close my account. Unfortunately that means I was exposed in this breach. What is the best way to get them to actually close my account? I no longer even have access to the account because it's tied to a domain and email that no longer exist. The business entity was shut down correct…

If you can you re-register the domain and email address, that would be a convenient shortcut.

But more generally, they will need business closure docs, including asset disposal. The defunct account will become property of the asset receiver(s).

If there's enough money in the account to bother, hire a lawyer to remind them how things work.

If there isn't enough money in the account, then you were right to ignore it in the first place. The damage from this leak was not (especially) predictable, but regardless it's done now, and won't get any worse.

Re: Evolve Bank and Trust confirms LockBit stole 7.6M people's data

#57
post #45

Not saying that this breach is somehow connected, but all of my Wise cards(both physical and virtual) got charged($10, $100, $500) at random locations of the globe in May & June and method was manual entry. While some charges were declined initially because the expiry date was entered wrong on first try(all of my cards coincidentally have expiry date like 04/24 or similar) but cvv was always correct. To make matters…

Same, just last week on my Wise account. "Manual entry". First a 0USD "card check" was triggered, couple hours later transactions started going through.

I noticed a couple days later by accident, randomly checking my balance in the app. I got no notifications from Wise app at any time.

Thing is, although I have a physical Wise card, it was never used anywhere since the account was opened, so I suspected something was way off. Can't be stolen credit card info from some random store online, or ATM skimming etc.

While I don't know what all the possible ways to pull this off are, had a feeling I'd be reading about it on HN soon. This breach, or some other breach, looks to me like someone has enough info to charge random Wise accounts.

Re: Evolve Bank and Trust confirms LockBit stole 7.6M people's data

#58
post #45

Not saying that this breach is somehow connected, but all of my Wise cards(both physical and virtual) got charged($10, $100, $500) at random locations of the globe in May & June and method was manual entry. While some charges were declined initially because the expiry date was entered wrong on first try(all of my cards coincidentally have expiry date like 04/24 or similar) but cvv was always correct. To make matters…

> cvv was always correct

How do you know this, does Wise provide auth response data? (Merchants are not required to respect the CVV check, so it's possible for txns to go through with a non-matching CVV response code.)

I'm also curious about the lack of notifications. That would seem to indicate a level of account control beyond the cardholder data. Unless they were failed due to NSF before the notification step.

Re: Evolve Bank and Trust confirms LockBit stole 7.6M people's data

#59

Earlier quoted context omitted.

There are plenty of reasons to partner with a bank as a fintech other than to drive debit card revenue. 1. There are lots of regulations that say only banks can do certain actions, like lend in all 50 states under the rules of a single state. Or open a FDIC insured checking account. Or have a unique account+routing number for each user to send ACH funds to (various reasons this could be preferred to everyone ACH to o…

(1) is absolutely true. (2) - well, it isn’t that hard to become a bank, but it is hard to become a bank when your business plan is “we want to operate well outside of established regulation and norms”. (Starting a state chartered bank is particularly straightforward.) There are many small banks that would like to be acquired and they are generally profitable. A VC-funded fintech would not have a terribly difficult t…

Currently working at a state chartered credit union. Although it is "easy" to start one, most states regulations are very strict and lag significantly behind federal ones. Hell, where I work we aren't even allowed to serve businesses, loans, deposits, or otherwise.

Re: Evolve Bank and Trust confirms LockBit stole 7.6M people's data

#60
post #56
post #48

This thread seems as good a place as any to ask. I have a Mercury account for a now defunct/non-existent company, but Mercury refused to close my account. Unfortunately that means I was exposed in this breach. What is the best way to get them to actually close my account? I no longer even have access to the account because it's tied to a domain and email that no longer exist. The business entity was shut down correct…

If you can you re-register the domain and email address, that would be a convenient shortcut. But more generally, they will need business closure docs, including asset disposal. The defunct account will become property of the asset receiver(s). If there's enough money in the account to bother, hire a lawyer to remind them how things work. If there isn't enough money in the account, then you were right to ignore it in…

There was like $17 in the account when I tried to close it, so I am completely unconcerned with the money. My bigger concern is that their lax security will result in someone trying to fraudulently transact with the account and somehow that will come back to bite me.
Post reply on HN