Evolve Bank & Trust has officially confirmed a serious cybersecurity incident, with the notorious ransomware group Lockbit 3.0 allegedly releasing customers' personally identifiable information (PII) on the dark web. First reported by Bitcoin.com, the breach has sent shockwaves through the crypto community, given the bank's extensive partnerships with fintech companies that manage accounts for a large number of cryptocurrency users.
Incident Overview: Lockbit 3.0 Strikes Again
Lockbit 3.0, one of the most active ransomware-as-a-service (RaaS) groups, employs a double-extortion tactic: encrypting victims' data while threatening to leak stolen information. In this attack, the group claims to have exfiltrated millions of customer records and posted samples on their dark web leak site to pressure Evolve Bank into paying a ransom.
Evolve Bank's Role: A Hidden Pipeline for Crypto
Evolve Bank serves as a critical banking-as-a-service (BaaS) provider for numerous fintech startups and crypto platforms. Many well-known cryptocurrency exchanges, wallet services, and DeFi projects rely on Evolve to hold customer deposits or facilitate payment flows. Consequently, the bank's databases contain extensive KYC data tied to crypto users. The exposure of such information puts individuals at risk of financial fraud and identity theft far beyond the crypto realm.
Bank Response and Remediation
In an official statement, Evolve Bank said it immediately activated its incident response plan, engaged third-party cybersecurity experts, notified law enforcement, and began offering affected customers 24 months of complimentary credit monitoring and identity theft protection services. The bank strongly recommends that all customers monitor their accounts for unauthorized activity, watch for phishing attempts and scam calls, and follow the security steps outlined on its official channels.
Industry Impact and User Guidance
Cybersecurity analysts warn that this breach will likely intensify regulatory scrutiny on data protection practices within the crypto-financial nexus. Crypto users with accounts tied to Evolve Bank should promptly change passwords for linked services, enable two-factor authentication, and stay updated via the bank's official communications. Platforms that rely on Evolve for custody or settlement should also issue their own security advisories.
As of now, Lockbit 3.0 has not disclosed a ransom demand, and some stolen data has already circulated on underground forums. Evolve Bank has pledged to provide further updates as the investigation unfolds and emphasized that its core banking operations remain unaffected. Nonetheless, the incident underscores a stark reality: despite the promise of decentralization, centralized financial rails remain the most vulnerable targets in the digital asset ecosystem.

