LockBit's claimed Federal Reserve hack was really Evolve Bank & Trust data
- Organization
- Evolve Bank & Trust
- Exploit
- Ransomware
- Industry
- Banking
On 23 June 2024 the LockBit ransomware group added a federalreserve.gov entry to its dark web leak site, claiming it held 33 terabytes of what it called American banking secrets and setting a 25 June deadline. The claim drew wide attention because a breach of the United States central bank would have been extraordinary.
LockBit published the files on 26 June. Researchers who examined them found the data had not come from the Federal Reserve at all. It belonged to Evolve Bank & Trust, an Arkansas lender best known for sponsoring fintech partners. Analysts at vx-underground suggested the attackers had seen a document referencing the Federal Reserve and drawn the wrong conclusion. The first download link on the LockBit page was a Federal Reserve Board press release announcing an enforcement action against Evolve over anti money laundering, risk management and consumer compliance failings.
Evolve confirmed the theft and told customers the exposed records could include names, Social Security numbers, dates of birth and account information. It said debit cards and online and digital banking credentials did not appear to be affected.
SecurityWeek reported that the Federal Reserve did not respond to a request for comment. Researchers were divided over whether LockBit had simply misread the material or had misattributed it deliberately to regain attention after law enforcement disrupted the group earlier in 2024.
Updates
-
Evolve Bank & Trust put the number of people affected at 7,640,112 in a filing with the Maine Attorney General, its first published count, and began mailing notification letters the same day.