SoFi Hong Kong Data Breach Exposes Customer Information via Third-Party Vendor

SoFi Hong Kong Data Breach Exposes Customer Information via Third-Party Vendor

First seen 9 Jun 2026, 14:29 UTC BleepingcomputerRescanawww.claimdepot.com 77% similarity 51.9

Article Content

Browse articles
ThreatCluster

On April 30, 2026, SoFi Hong Kong detected unauthorized access to a customer information database managed by a third-party vendor. The breach, publicly disclosed on June 8, 2026, exposed personally identifiable information (PII) of an undetermined number of customers. Attack vectors included social engineering and exploitation of third-party vendor access, with no malware detected. Compromised data included names, dates of birth, addresses, email addresses, phone numbers, and employment and education information. SoFi engaged external cybersecurity experts and notified affected individuals and regulators. The incident highlights the importance of third-party risk management in the financial sector. SoFi has implemented enhanced monitoring and verification procedures in response to the breach.

Key Points: • SoFi Hong Kong experienced a data breach due to unauthorized access via a third-party vendor. • Compromised data included PII such as names, addresses, and phone numbers, but not financial information. • The breach was detected on April 30, 2026, and publicly disclosed on June 8, 2026.

ThreatCluster AI

Timeline

2026-04-30
Unauthorized access detected
SoFi Hong Kong discovered unauthorized access to a customer database managed by a third-party vendor.
BleepingComputer
2026-06-08
Breach publicly disclosed
SoFi publicly announced the data breach, confirming exposure of customer PII.
Rescana
Date unknown
Ongoing investigation
SoFi is conducting an ongoing investigation to assess the scope and impact of the incident.
BleepingComputer

Community

Browse all →