← SoFi

2026 SoFi Hong Kong — third-party vendor database unauthorized access

2026 Unknown records affected Share on X

Data compromised

Customer PII categories under investigation; SoFi stated no account passwords or financial account numbers in accessed set per June disclosures

Technical writeup

SoFi confirmed in June 2026 that its Hong Kong subsidiary detected unauthorized access on April 30, 2026 to a customer information database managed by a third-party vendor. BleepingComputer reported the public disclosure June 8, 2026 alongside ongoing investigation into data categories and scope; SoFi emphasized no account passwords or financial account numbers were in the compromised database per initial statements.

Root cause

Unauthorized access to customer database managed by a third-party vendor (supply-chain compromise)

References