2024 Bilt Rewards — customer notices after Evolve Bank & Trust LockBit ransomware / partner breach
Data compromised
Types described in Evolve notifications—financial and identity fields for partner-bank customer datasets; Bilt users potentially overlapping that population
Technical writeup
Evolve Bank & Trust, Bilt’s banking partner for the Bilt Mastercard program, disclosed a major cybersecurity incident tied to LockBit ransomware activity with unauthorized access beginning February 9, 2024, discovery in late May 2024, and containment May 31, 2024 per Evolve’s public incident summary and mainstream security press. Evolve stated affected data could include names, Social Security numbers, account and payment-card numbers, DOB, contact information, government IDs, and ACH transaction metadata for millions of Americans (~7.6M figure widely reported for Evolve overall). Bilt Rewards separately notified members that information shared with Evolve as part of the card program could have been affected; reporting often treated impact as partner-supply-chain exposure rather than a compromise of Bilt’s own core systems. Precise Bilt-only headcount was not uniformly broken out in first-wave disclosures.
Root cause
Ransomware / unauthorized access at partner bank (Evolve) handling Bilt program data; phishing link enabling network access per Evolve narrative