SoFi’s Hong Kong subsidiary confirmed unauthorized access on April 30, 2026 to a customer database operated by a third-party vendor, publicly disclosed June 8 per BleepingComputer.
Member checklist
- Watch for official SoFi mail—not SMS links with partial account details.
- Enable MFA on email accounts used for SoFi recovery.
- Monitor credit and banking alerts if Hong Kong onboarding included ID scans.
See also the separate December 2025 U.S. SoFi social-engineering incident.
Canonical record: SoFi Hong Kong 2026 on BreachHistory.