Supply chain
β Supply Chain
Bilt Third-Party Breach (July 2024)
Primary Source βIncident Details
Affirm says cardholders impacted by Evolve Bank data breach. Buy now, pay later loan company Affirm is warning that holders of its payment cards had their personal information exposed due to a data breach at its third-party issuer, Evolve Bank & Trust (Evolve). Affirm is a fintech firm that provides consumer-friendly alternatives to traditional credit options. It also offers point-of-sale financing, virtual cards on a mobile app , and a fully integrated physical card called the ‘Affirm Card.’. Evolve is a large financial services provider specializing in retail and commercial banking, payment processing, and banking-as-a-service (BaaS). Third-party company: Evolve Bank & Trust.
Technical Details
- Initial Attack Vector
- Compromise of third-party service provider / vendor relationship
- Vendor / Product
- Evolve Bank & Trust
- Supply Chain Attack
- β Confirmed third-party / vendor compromise
Timeline
- 2024-07-01 Breach occurred
- 2024-07-02 Publicly disclosed