FinWise Bank has disclosed a significant data security incident that compromised the personal information of approximately 689,000 customers, stemming from unauthorized access by a former employee after their employment ended.
## The Incident Details
On May 31, 2024, FinWise Bank experienced a data breach when a former employee gained access to sensitive customer files despite no longer being employed by the institution. The breach primarily affected customers of American First Finance (AFF), a consumer financing company that partners with FinWise for loan origination and funding services.
American First Finance provides various financial products including installment loans and lease-to-own programs, with FinWise serving as the backing bank for these services.
## Scope of the Breach
According to filings with the Maine Attorney General’s office, the incident impacted 689,000 customers. The compromised data included:
– Full customer names
– Additional personal data elements (specific details were redacted from public notifications)
FinWise’s SEC filing indicates approximately 600,000 people were affected, closely aligning with the initial disclosure numbers.
## Key Concerns and Unknowns
The bank has not disclosed critical details about the incident, including:
– How the former employee maintained access to systems after termination
– The complete list of compromised data types
– The total duration of unauthorized access
## Response and Remediation
Upon discovering the breach, FinWise took several immediate actions:
– Launched a comprehensive investigation with external cybersecurity professionals
– Implemented strengthened internal security controls
– Offered 12 months of free credit monitoring and identity theft protection to affected customers
## Legal Implications
The data breach has resulted in multiple class-action lawsuits against FinWise Bank. The company has declined to provide additional comments, citing ongoing litigation.
## Industry Impact
This incident highlights critical cybersecurity challenges in the financial sector, particularly around access management and employee offboarding procedures. The breach underscores the importance of immediately revoking system access when employees leave organizations, especially in industries handling sensitive financial data.
The case serves as a reminder for financial institutions to regularly audit access controls and implement robust monitoring systems to detect unauthorized access attempts by former employees.
