SoFi Hong Kong subsidiary confirms third-party vendor data breach
SoFi Securities (Hong Kong) Limited has confirmed a third-party vendor data breach discovered on April 30, 2026, in which unauthorised actors accessed a vendor database containing subsidiary customer information. The scope of personal data exposed, number of affected customers, vendor identity, and any extortion or ransomware component remain undisclosed. External incident response has been engaged and a Hong Kong support line established. No insured loss estimate, regulator action, or systemic market impact has been disclosed.
AI-generated from linked source reports. See our correction policy.
Impact verdict
Low impact. Loss pathway centres on a supply-chain data breach at a Hong Kong fintech securities subsidiary. Potential exposures include third-party liability (vendor and customer-facing), regulatory exposure under Hong Kong personal data rules, and contingent business interruption considerations. Vendor identity, scope of personal data, any extortion/ransomware component, and any subsequent Privacy Commissioner or other regulator action remain the key watch items. No insured loss estimate or systemic market impact is evident from current reporting.
View assessment methodologyPremium discovery tier
Unlock analyst briefs, intelligence depth, and the revision timeline
Public pages show event facts and a short lead-in. Premium accounts unlock analyst briefs, deeper intelligence, loss context, and the full revision history for this event.
Start two-week trialGeographic Zone Matches
3 active matches
- TRIA Certified AreasRule-basedConfidence 100%
- Pacific Ring of FireRule-basedConfidence 100%
- Caribbean Hurricane ZoneRule-basedConfidence 100%
Geographic zone matches are RiskEvents spatial/analytical indicators, not coverage determinations or Lloyd's official classifications.
Affected countries
Lloyd's classifications
Tracking this kind of risk? Get an email when Cyber events escalate.
Get alerts