Rescana
SoFi Hong Kong Data Breach Exposes Customer Information via Third-Party Vendor
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
On April 30, 2026, SoFi Hong Kong detected unauthorized access to a customer information database managed by a third-party vendor. The breach, publicly disclosed on June 8, 2026, exposed personally identifiable information (PII) of an undetermined number of customers. Attack vectors included social engineering and exploitation of third-party vendor access, with no malware detected. Compromised data included names, dates of birth, addresses, email addresses, phone numbers, and employment and education information. SoFi engaged external cybersecurity experts and notified affected individuals and regulators. The incident highlights the importance of third-party risk management in the financial sector. SoFi has implemented enhanced monitoring and verification procedures in response to the breach.
Key Points: • SoFi Hong Kong experienced a data breach due to unauthorized access via a third-party vendor. • Compromised data included PII such as names, addresses, and phone numbers, but not financial information. • The breach was detected on April 30, 2026, and publicly disclosed on June 8, 2026.