← SoFi

2025 SoFi — social engineering breach exposed PII for 38,049 Washington residents

2025 38.0K records affected Share on X

Data compromised

Names, DOB, addresses, emails, phones, employment and education info; no passwords or payment card numbers per SoFi

Technical writeup

SoFi Technologies confirmed a social engineering incident allowing unauthorized access to internal systems from December 29, 2025 through January 3, 2026, discovered January 2, 2026. A Washington Attorney General filing disclosed 38,049 state residents affected with names, dates of birth, addresses, contact details, and employment/education information; SoFi stated account passwords and payment card numbers were not accessed. The company engaged CrowdStrike and notified affected individuals by mail.

Root cause

Social engineering attack granting unauthorized access to internal SoFi systems (Dec 29, 2025–Jan 3, 2026)

References