news.bgov.com Chime Faces Lawsuits After Alleged Iran-Linked Cyberattack
Article Content
- •Chime Financial's app outage on April 1, 2026, was linked to a cyberattack by Team 313.
- •Three lawsuits allege that sensitive customer data was compromised, despite Chime's denials.
- •Chime has not filed a cybersecurity incident notice with the SEC as of May 4, 2026.
On April 1, 2026, Chime Financial's mobile app experienced a significant outage attributed to a cyberattack by the pro-Iranian hacker group Team 313. Customers reported being unable to access their accounts, leading to concerns over potential data theft. Three proposed class action lawsuits have been filed in the U.S. District Court for the Northern District of California, alleging that Team 313 breached Chime's systems and stole sensitive personal information, including Social Security numbers and government-issued IDs. Chime has publicly stated that no data was stolen during the incident. Despite the claims, no evidence of a breach has been presented beyond existing public knowledge. The outage resulted in over 6,600 user reports on DownDetector, indicating widespread impact. As of May 4, 2026, Chime has not filed a material cybersecurity incident notice with the SEC, raising questions about the company's assessment of the incident's severity. Customers have expressed frustration and anxiety over the lack of access and potential data compromise.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track 313 Team Hacking Team and 313 Team Corporation in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
BlueMoon Exploit Kit Targeting Chrome and Windows by Multiple State Actors A new exploit kit named BlueMoon has been rapidly adopted by at least four espionage groups, primarily linked to China, exploiting vulnerabilities in Google Chrome and Microsoft Windows. The first observed use of BlueMoon was on August 28, 2026, by the China-aligned threat actor TA412, with subsequent adoption by…