Supply chain β›“ Supply Chain

Bilt Third-Party Breach (July 2024)

πŸ“… 2024-07-01 🏒 Evolve Bank & Trust
Primary Source β†—

Incident Details

Affirm says cardholders impacted by Evolve Bank data breach. Buy now, pay later loan company Affirm is warning that holders of its payment cards had their personal information exposed due to a data breach at its third-party issuer, Evolve Bank & Trust (Evolve). Affirm is a fintech firm that provides consumer-friendly alternatives to traditional credit options. It also offers point-of-sale financing, virtual cards on a mobile app , and a fully integrated physical card called the ‘Affirm Card.’. Evolve is a large financial services provider specializing in retail and commercial banking, payment processing, and banking-as-a-service (BaaS). Third-party company: Evolve Bank & Trust.

Technical Details

Initial Attack Vector
Compromise of third-party service provider / vendor relationship
Vendor / Product
Evolve Bank & Trust
Supply Chain Attack
βœ… Confirmed third-party / vendor compromise

Timeline

  1. 2024-07-01 Breach occurred
  2. 2024-07-02 Publicly disclosed