← Chime

2026 Chime — April outage; DDoS claimed by Iran-linked actors; litigation alleges data breach

2026 Unknown records affected Share on X

Data compromised

Not uniformly established in public sources; plaintiffs allege PII exposure while company statements emphasized no member-data compromise

Technical writeup

On 1 April 2026 Chime suffered a widely reported service disruption. Bloomberg and other outlets summarized a pro-Iranian cybercrime group claiming credit and described a distributed denial-of-service attack affecting public-facing availability; some follow-on reporting relayed Chime’s statement that no funds or customer data were compromised. Parallel U.S. class-action filings (e.g. Castaneda v. Chime Financial, N.D. Cal.) alleged inadequate safeguards and exposure of personal information, naming extortion-oriented actors referenced in plaintiff narratives—creating an unresolved split between press/company framing and tort claims.

Root cause

Contested: DDoS and claimed intrusion narratives in open sources versus official no-data-loss statements

References