Evolve Bank & Trust, a financial institution widely recognized for its deep integration with fintech and cryptocurrency companies, has confirmed a major cybersecurity incident. According to security researchers, the notorious ransomware group Lockbit 3.0 has published customers' personally identifiable information (PII) on the dark web, including names, addresses, Social Security numbers, and partial account transaction records. The news sent shockwaves through the cryptocurrency community, prompting investors and everyday users to reassess the safety of their digital assets.
Background: A Crypto-Friendly Bank Under Siege
Evolve Bank & Trust, a century-old U.S. commercial bank, gained prominence in recent years by aggressively embracing fintech and crypto. Through its Banking-as-a-Service (BaaS) platform, the bank provides accounts and payment processing for numerous cryptocurrency exchanges, wallet providers, and decentralized finance (DeFi) projects. This makes its database a treasure trove of sensitive information belonging to digital asset investors. The breach highlights the inherent security vulnerabilities when traditional banking systems intersect with the fast-evolving crypto landscape.
Lockbit 3.0: A Prolific Cybercriminal Operator
Lockbit 3.0 is one of the most active ransomware-as-a-service (RaaS) groups globally, infamous for its double-extortion tactics — encrypting victims' systems and threatening to leak stolen data. The group has previously hit healthcare, government, and tech corporations. Its targeting of Evolve Bank signals a shift toward financial infrastructure that supports crypto assets. The dark web leak site shows that Lockbit 3.0 claimed to have infiltrated Evolve's internal systems prior to June 27, 2024, exfiltrating terabytes of sensitive data.
Direct Impact on the Crypto Community
The breach poses multiple threats to crypto users: identity theft, phishing campaigns, and potential asset theft. Several cryptocurrency platforms that partner with Evolve Bank have already issued warnings, urging customers to reset passwords, enable multi-factor authentication (preferably hardware-based), and be vigilant against suspicious emails claiming to be from the bank. Some users have reported seeing their KYC document scans — including passports, driver's licenses, and selfies — in the leaked dark web data.
Bank's Response and Mitigation
Evolve Bank promptly released a statement confirming the unauthorized access and stated that it has retained third-party cybersecurity experts to conduct a forensic investigation. The bank is offering free credit monitoring and identity theft protection services for at least 24 months to all affected customers. It also emphasized that its core banking systems were not fully compromised and that customer funds remain secure. However, security analysts caution that the leaked PII could be exploited for years, so long-term vigilance is essential.
Industry Reassessment and Recommendations
This incident is a stark reminder that even within regulated traditional banking, crypto user data is not immune to sophisticated attacks. Experts recommend crypto users take the following steps: 1) Use strong, unique passwords for all financial accounts and change them regularly; 2) Enable hardware-based two-factor authentication instead of SMS-based codes; 3) Withdraw digital assets from exchanges to self-custodial wallets where possible; 4) Follow only official communications from the bank and partner platforms. Additionally, Evolve Bank's partners are urged to strengthen their own security audits to prevent supply-chain attacks.
As of press time, the U.S. Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) have joined the investigation. Evolve Bank pledged full cooperation with law enforcement to identify the attackers and will continue updating customers on developments. The crypto community is holding its breath, watching to see if this breach cascades into broader systemic risks.

