← Blog

SoFi Hong Kong Breach: Third-Party Vendor Database Hit

Share on X

SoFi’s Hong Kong subsidiary confirmed unauthorized access on April 30, 2026 to a customer database operated by a third-party vendor, publicly disclosed June 8 per BleepingComputer.

Member checklist

  1. Watch for official SoFi mail—not SMS links with partial account details.
  2. Enable MFA on email accounts used for SoFi recovery.
  3. Monitor credit and banking alerts if Hong Kong onboarding included ID scans.

See also the separate December 2025 U.S. SoFi social-engineering incident.

Canonical record: SoFi Hong Kong 2026 on BreachHistory.