2026 Chime — April outage; DDoS claimed by Iran-linked actors; litigation alleges data breach
Data compromised
Not uniformly established in public sources; plaintiffs allege PII exposure while company statements emphasized no member-data compromise
Technical writeup
On 1 April 2026 Chime suffered a widely reported service disruption. Bloomberg and other outlets summarized a pro-Iranian cybercrime group claiming credit and described a distributed denial-of-service attack affecting public-facing availability; some follow-on reporting relayed Chime’s statement that no funds or customer data were compromised. Parallel U.S. class-action filings (e.g. Castaneda v. Chime Financial, N.D. Cal.) alleged inadequate safeguards and exposure of personal information, naming extortion-oriented actors referenced in plaintiff narratives—creating an unresolved split between press/company framing and tort claims.
Root cause
Contested: DDoS and claimed intrusion narratives in open sources versus official no-data-loss statements
References
- https://www.bloomberg.com/news/articles/2026-04-07/pro-iran-group-takes-credit-for-cyberattacks-on-chime-pinterest
- https://www.thestar.com.my/tech/tech-news/2026/04/08/pro-iran-group-takes-credit-for-cyberattacks-on-chime-pinterest
- https://www.classaction.org/news/chime-data-breach-lawsuit-says-april-2026-incident-could-have-been-prevented