Rescana SoFi Hong Kong Data Breach Exposes Customer Information via Third-Party Vendor
Article Content
- •SoFi Hong Kong experienced a data breach due to unauthorized access via a third-party vendor.
- •Compromised data included PII such as names, addresses, and phone numbers, but not financial information.
- •The breach was detected on April 30, 2026, and publicly disclosed on June 8, 2026.
On April 30, 2026, SoFi Hong Kong detected unauthorized access to a customer information database managed by a third-party vendor. The breach, publicly disclosed on June 8, 2026, exposed personally identifiable information (PII) of an undetermined number of customers. Attack vectors included social engineering and exploitation of third-party vendor access, with no malware detected. Compromised data included names, dates of birth, addresses, email addresses, phone numbers, and employment and education information. SoFi engaged external cybersecurity experts and notified affected individuals and regulators. The incident highlights the importance of third-party risk management in the financial sector. SoFi has implemented enhanced monitoring and verification procedures in response to the breach.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track SoFi in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…