2025 SoFi — social engineering breach exposed PII for 38,049 Washington residents
Data compromised
Names, DOB, addresses, emails, phones, employment and education info; no passwords or payment card numbers per SoFi
Technical writeup
SoFi Technologies confirmed a social engineering incident allowing unauthorized access to internal systems from December 29, 2025 through January 3, 2026, discovered January 2, 2026. A Washington Attorney General filing disclosed 38,049 state residents affected with names, dates of birth, addresses, contact details, and employment/education information; SoFi stated account passwords and payment card numbers were not accessed. The company engaged CrowdStrike and notified affected individuals by mail.
Root cause
Social engineering attack granting unauthorized access to internal SoFi systems (Dec 29, 2025–Jan 3, 2026)