On June 27, 2024, Evolve Bank & Trust, a Tennessee-based financial institution known for its extensive partnerships with fintech and cryptocurrency companies, confirmed a major cybersecurity incident. The notorious ransomware group Lockbit 3.0 claimed responsibility, releasing customers' personally identifiable information (PII)—including names, Social Security numbers, account details, and transaction records—on its dark web leak site. The breach has sent shockwaves through the cryptocurrency community, as Evolve Bank provides Banking-as-a-Service (BaaS) to several prominent crypto exchanges, wallets, and lending platforms, potentially exposing the identities and financial data of millions of digital asset holders.
Why This Breach Matters for Crypto
Evolve Bank's BaaS model allows crypto companies to offer FDIC-insured accounts, debit cards, and payment processing to their users. This means that even users who do not have a direct relationship with Evolve Bank may have their data compromised through a partner platform. The scale of exposure is unprecedented in the context of crypto-related financial infrastructure. Previous breaches typically affected a single exchange or wallet service, but this incident targets the banking layer that connects multiple crypto entities, amplifying the risk of identity theft, account takeovers, and targeted phishing campaigns.
Lockbit 3.0's Evolving Tactics
Lockbit 3.0, the latest iteration of one of the world's most prolific ransomware-as-a-service operations, has shifted its strategy in this attack. Instead of encrypting files and demanding a ransom for decryption, the group appears to have exfiltrated data and published it without encryption—a move that suggests Evolve Bank either refused to pay or had robust backups. This 'pure data theft' approach is increasingly common among cybercriminals who seek to maximize pressure on victims who cannot afford the reputational damage of a data leak. Security analysts note that Lockbit 3.0's infrastructure is highly sophisticated, employing polymorphic malware and decentralized command-and-control servers, making attribution and disruption difficult.
Evolve Bank's Response and Customer Protections
In an official statement, Evolve Bank confirmed the incident and assured customers that it had engaged leading cybersecurity firms to investigate and contain the breach. The bank has notified federal law enforcement agencies and banking regulators. As a remedial measure, all affected customers will receive free 24-month credit monitoring and identity theft protection services, including dark web surveillance, fraud alerts, and identity restoration assistance. However, critics argue that standard credit monitoring is insufficient for cryptocurrency users, who may face risks beyond traditional credit fraud, such as SIM swapping or unauthorized access to crypto wallets linked to their bank accounts. The bank has advised customers to monitor all accounts—including those at partner crypto platforms—for suspicious activity.
Immediate Steps for Crypto Users
Given the broad reach of Evolve Bank's partnerships, anyone who has used a US-based crypto service that offers bank account integration should assume their data may be compromised. Security experts recommend the following urgent actions:
- Freeze your credit reports at all three major bureaus (Equifax, Experian, TransUnion) to prevent new account openings in your name;
- Enable multi-factor authentication on all financial and crypto accounts, preferably using hardware security keys or authenticator apps rather than SMS;
- Change passwords for any accounts that may use the same email or credentials as those associated with Evolve Bank partners;
- Review recent transaction histories for small, unauthorized charges that might indicate test fraud;
- Be extremely cautious of phishing emails purporting to be from Evolve Bank or its partners—attackers will likely use the leaked names and email addresses to craft convincing messages.
Broader Implications for the Crypto Banking Sector
This breach adds to the growing list of challenges facing crypto-friendly banks. Following the collapses of Silvergate Bank and Signature Bank in 2023, the industry has struggled to maintain stable fiat on-ramps. The Evolve Bank incident may accelerate a shift toward decentralized finance (DeFi) native solutions and encourage crypto firms to build their own custody and compliance frameworks, reducing reliance on traditional banking partners. From a regulatory perspective, the U.S. Federal Reserve and the Office of the Comptroller of the Currency (OCC) are likely to impose stricter oversight on third-party risk management for banks serving fintech and crypto clients. Stronger penetration testing requirements and mandatory incident reporting timelines could become the new norm.
As of press time, Lockbit 3.0 has not demanded a specific ransom or disclosed the full extent of the stolen data. However, the cybersecurity community considers this one of the most consequential financial data breaches of 2024. Cryptocurrency users are urged to stay vigilant, implement the recommended security measures, and follow Evolve Bank's official communications for further updates.

