2026 SoFi Hong Kong — third-party vendor database unauthorized access
Data compromised
Customer PII categories under investigation; SoFi stated no account passwords or financial account numbers in accessed set per June disclosures
Technical writeup
SoFi confirmed in June 2026 that its Hong Kong subsidiary detected unauthorized access on April 30, 2026 to a customer information database managed by a third-party vendor. BleepingComputer reported the public disclosure June 8, 2026 alongside ongoing investigation into data categories and scope; SoFi emphasized no account passwords or financial account numbers were in the compromised database per initial statements.
Root cause
Unauthorized access to customer database managed by a third-party vendor (supply-chain compromise)