Developing event. Generated by AI and subject to further corroboration and review.
SoFi Hong Kong subsidiary confirms third-party vendor data breach
SoFi Securities (Hong Kong) Limited has confirmed a third-party vendor data breach discovered on April 30, 2026, in which unauthorized actors accessed customer data via the vendor's database. The subsidiary has engaged a third-party cybersecurity firm and opened a Hong Kong support line. Scope of exposed personal data, number of affected customers, vendor identity, and any extortion or ransomware component remain unconfirmed.
AI-generated from linked source reports. See our correction policy.
Impact verdict
Low impact. Loss pathway centres on a supply-chain data breach at a Hong Kong fintech subsidiary, with potential third-party liability and cyber insurance exposure. The subsidiary is a relatively small entity within a US fintech parent. No insured loss estimate, confirmed customer count, ransom demand, vendor identity, or regulator action has been disclosed, and there is no evidence of systemic market impact. Watch items: vendor identity, scope of personal data exposed, any extortion or ransomware demand, and any subsequent Hong Kong Privacy Commissioner or other regulator action.
View assessment methodologyHow we grade what we know -- Known · Reported · Uncertain. Methodology →
Intelligence ledger
Each line expands in place to its underlying sourced claim.
Known26 lines
SoFi Securities (Hong Kong) Limited confirmed a data breach discovered on April 30, 2026▾
Unauthorized access occurred via a third-party vendor's database▾
SoFi has engaged a third-party cybersecurity firm for incident response▾
A Hong Kong support line (+852 26938888) has been established for affected customers▾
No insured loss estimate has been disclosed or identified at this stage.▾
Unauthorized access was achieved via a third-party vendor's database.▾
SoFi Securities (Hong Kong) Limited confirmed a data breach at the subsidiary discovered on April 30, 2026.▾
Unauthorized access occurred through a third-party vendor's database, indicating a supply-chain attack vector.▾
SoFi Securities (Hong Kong) Limited disclosed a data breach detected on April 30, 2026.▾
Unauthorised access to customer data occurred through a third-party vendor's database rather than directly through SoFi's own systems.▾
Unauthorized actors accessed customer data through a third-party vendor's database, indicating a supply-chain attack vector.▾
SoFi Securities (Hong Kong) Limited confirmed a data breach discovered on April 30, 2026.▾
No insured loss estimate has been disclosed.▾
A Hong Kong support line (+852 26938888) has been opened for affected customers.▾
Event lifecycle is 'developing' following corroboration across at least two independent sources.▾
SoFi has engaged a third-party cybersecurity firm for incident response and investigation.▾
A Hong Kong support line (+852 26938888) has been established for affected customers.▾
SoFi has engaged a third-party cybersecurity firm for incident response.▾
The event remains at signal-stage maturity: confirmed breach, no quantified impact metrics, no identified London market loss mechanism.▾
SoFi has engaged a third-party cybersecurity firm to assist with incident response and investigation.▾
No Hong Kong Privacy Commissioner or other regulatory action has been publicly announced in connection with the breach.▾
No regulatory action by the Hong Kong Privacy Commissioner or other authorities has been confirmed.▾
A Hong Kong support line has been established for affected customers.▾
SoFi has engaged a third-party cybersecurity firm to support incident response.▾
SoFi has engaged a third-party cybersecurity firm to assist with incident response.▾
SoFi Securities (Hong Kong) Limited disclosed a data breach discovered on April 30, 2026, originating from a third-party vendor's database.▾
Reported8 lines
Customer data was potentially exposed through the vendor breach▾
No public statement or enforcement action from the Hong Kong Privacy Commissioner or other regulators has been disclosed as of the latest update.▾
SoFi Securities (Hong Kong) Limited is a subsidiary of a US-listed fintech parent.▾
The event is characterized as a supply-chain cyber incident affecting a financial services entity in Hong Kong, with potential third-party liability and cyber insurance implications.▾
Customer data was potentially exposed through the third-party vendor breach; categories and volume not yet confirmed.▾
Customer data was potentially exposed through the vendor breach; categories and scope remain unconfirmed.▾
Customer data was potentially exposed through the vendor breach; specific data categories are not yet confirmed.▾
Customer data was potentially exposed through the vendor breach; scope and categories remain undisclosed.▾
Uncertain30 lines
Scope and categories of personal data affected▾
Total number of customers impacted▾
Identity of the third-party vendor▾
Whether the incident involved extortion or ransomware demands▾
Threat actor attribution▾
Total number of customers impacted by the breach has not been disclosed.▾
Total number of customers impacted has not been disclosed.▾
The total number of customers impacted has not been disclosed.▾
It is unconfirmed whether the incident involved extortion or ransomware demands; threat actor attribution is also unknown.▾
No Hong Kong Privacy Commissioner or other regulator action has been disclosed at this stage.▾
The identity of the third-party vendor involved has not been disclosed.▾
Scope and categories of personal data affected, and the total number of customers impacted, remain unconfirmed.▾
Whether the incident involved extortion or ransomware demands has not been confirmed.▾
Identity of the third-party vendor involved has not been disclosed.▾
Scope and categories of personal data affected remain unconfirmed.▾
Threat actor attribution has not been disclosed.▾
No threat actor attribution has been reported.▾
The identity of the third-party vendor whose database was accessed has not been publicly disclosed.▾
It has not been confirmed whether the incident involved any extortion or ransomware demands.▾
The scope and categories of personal data exposed, total number of customers impacted, and identity of the third-party vendor remain unconfirmed.▾
No insured loss estimate has been disclosed.▾
The identity of the third-party vendor whose database was compromised has not been disclosed.▾
Whether the incident involved extortion demands, ransomware, or other coercive tactics has not been confirmed.▾
The categories of personal data potentially exposed have not been confirmed.▾
The categories and scope of personal data exposed in the breach have not been confirmed by SoFi.▾
The total number of customers impacted by the breach has not been disclosed.▾
It has not been confirmed whether the incident involved ransomware, extortion or any ransom demand.▾
No threat actor group has been attributed to the breach in public reporting.▾
The categories of personal data potentially involved (e.g., identifiers, financial, KYC) have not been confirmed.▾
The identity of the third-party vendor whose database was accessed has not been publicly disclosed.▾
Geographic Zone Matches
3 active matches
- TRIA Certified AreasRule-basedConfidence 100%
- Pacific Ring of FireRule-basedConfidence 100%
- Caribbean Hurricane ZoneRule-basedConfidence 100%
Geographic zone matches are RiskEvents spatial/analytical indicators, not coverage determinations or Lloyd's official classifications.
Affected countries
Latest developments
- Summary refreshed from cited evidence.
- PQER A6 event_resynthesis lines_of_business full replacement
- SoFi Hong Kong subsidiary has confirmed a data breach discovered on April 30, 2026. — BleepingComputer
- The breach occurred through a third-party vendor's database, not SoFi's own systems. — BleepingComputer
- The vendor involved has not been publicly identified. — BleepingComputer
- Number of affected customers remains undisclosed. — BleepingComputer
- The categories of personal data potentially involved have not been confirmed. — BleepingComputer
- No extortion or ransomware component has been publicly confirmed. — BleepingComputer
Timeline
SoFi Hong Kong disclosed a data breach at a third-party vendor containing customer information from its securities business. The scope, number of affected customers, and specific data exposed remain unknown. The incident represents a supply chain cyber attack on a fintech subsidiary with potential cyber liability and regulatory exposure.
Source: r/cybersecurity (Social / Community) · View source
Status changed to developing
evidence_trigger: corroboration >= 2
signal -> developing
SoFi has disclosed a data breach affecting its Hong Kong securities subsidiary, where hackers gained unauthorized access to a third-party vendor's database containing customer information. The incident was discovered on April 30, 2026, and the scope of exposed data remains under investigation, with potential implications for cyber liability coverage and regulatory exposure across multiple jurisdictions.
Source: r/privacy (Social / Community) · View source
Initial Detection
SoFi Securities (Hong Kong) Limited disclosed a data breach discovered on April 30, 2026, in which unauthorized actors accessed customer data via a third-party vendor's database. The scope of exposed personal data remains unknown, and the company has not confirmed customer count impact, extortion demands, or vendor identity. This is a supply-chain cyber incident affecting a financial services entity in Hong Kong, with potential third-party liability and cyber insurance implications.
We do not yet have complete information about the scope and impact of the incident, or whether (and, if so, which categories of) your personal data was involved.
Source: BleepingComputer (Trade Media) · View source
Lloyd's classifications
Tracking this kind of risk? Get an email when Cyber events escalate.
Get alerts