Developing event. Generated by AI and subject to further corroboration and review.
SoFi Hong Kong subsidiary confirms third-party vendor data breach
SoFi Securities (Hong Kong) Limited has confirmed a third-party vendor data breach discovered on April 30, 2026, in which unauthorized actors accessed a vendor database containing subsidiary customer information. The scope of personal data exposed, customer count, vendor identity, and any extortion or ransomware component remain undisclosed. External incident response has been engaged and a Hong Kong support line established. No insured loss estimate, confirmed customer count, ransom demand, vendor identity, or regulator action has been disclosed, and there is no evidence of systemic market impact.
AI-generated from linked source reports. See our correction policy.
Impact verdict
Low impact. Loss pathway centres on a supply-chain data breach at a Hong Kong fintech securities subsidiary, with potential third-party liability exposure, regulatory exposure under Hong Kong privacy rules, and cyber insurance implications. No insured loss estimate, confirmed customer count, ransom demand, vendor identity, or regulator action has been disclosed, and there is no evidence of systemic market impact. Watch items remain vendor identity, scope of personal data exposed, any extortion or ransomware demand, and any subsequent Hong Kong Privacy Commissioner or other regulator action.
View assessment methodologyHow we grade what we know -- Known · Reported · Uncertain. Methodology →
Intelligence ledger
Each line expands in place to its underlying sourced claim.
Known37 lines
SoFi Securities (Hong Kong) Limited confirmed a data breach discovered on April 30, 2026▾
Unauthorized access occurred via a third-party vendor's database▾
SoFi has engaged a third-party cybersecurity firm for incident response▾
A Hong Kong support line (+852 26938888) has been established for affected customers▾
The unauthorized access occurred via a third-party vendor's database, establishing the incident as a supply-chain cyber event rather than a direct compromise of SoFi HK systems.▾
The affected entity is SoFi Securities (Hong Kong) Limited, a relatively small subsidiary within a US fintech parent.▾
No insured loss estimate has been disclosed or identified at this stage.▾
The affected entity is SoFi Securities (Hong Kong) Limited, a Hong Kong securities subsidiary of US-based SoFi.▾
Unauthorized access occurred via a third-party vendor's database holding SoFi Hong Kong subsidiary customer information.▾
The data breach was discovered on April 30, 2026.▾
SoFi Securities (Hong Kong) Limited confirmed a data breach discovered on April 30, 2026 affecting customer information held by a third-party vendor.▾
Unauthorized access occurred via a third-party vendor's database holding subsidiary customer information, establishing a supply-chain attack vector.▾
SoFi Securities (Hong Kong) Limited confirmed a data breach discovered on April 30, 2026, involving unauthorized access to a third-party vendor database holding subsidiary customer information.▾
Unauthorized actors accessed customer data via a third-party vendor's database, indicating a supply-chain attack vector.▾
Unauthorized access to SoFi Hong Kong customer data occurred through a third-party vendor's database (supply-chain vector).▾
SoFi Securities (Hong Kong) Limited disclosed a data breach detected on April 30, 2026.▾
Unauthorized access occurred through a third-party vendor's database, indicating a supply-chain attack vector.▾
Unauthorised access to customer data occurred through a third-party vendor's database rather than directly through SoFi's own systems.▾
SoFi Securities (Hong Kong) Limited confirmed a data breach discovered on April 30, 2026.▾
SoFi has engaged a third-party cybersecurity firm for incident response.▾
A Hong Kong support line (+852 26938888) has been established for affected customers.▾
The event is in the developing lifecycle stage, with evidence_trigger: corroboration >= 2.▾
Event is in the developing stage with no resolution or full scope currently established.▾
A Hong Kong support line (+852 26938888) has been established for affected customers.▾
SoFi has engaged a third-party cybersecurity firm to conduct incident response.▾
A Hong Kong support line (+852 26938888) has been established for affected customers.▾
SoFi Hong Kong has engaged a third-party cybersecurity firm to investigate the incident.▾
Event lifecycle is 'developing' following corroboration across at least two independent sources.▾
A Hong Kong support line (+852 26938888) has been established for affected customers.▾
SoFi has engaged a third-party cybersecurity firm for incident response.▾
SoFi has engaged a third-party cybersecurity firm to assist with incident response and investigation.▾
No Hong Kong Privacy Commissioner or other regulatory action has been publicly announced in connection with the breach.▾
The event remains at signal-stage maturity: confirmed breach, no quantified impact metrics, no identified London market loss mechanism.▾
No regulatory action by the Hong Kong Privacy Commissioner or other authorities has been confirmed.▾
SoFi has engaged a third-party cybersecurity firm to support incident response.▾
SoFi has engaged a third-party cybersecurity firm to assist with incident response.▾
SoFi Securities (Hong Kong) Limited disclosed a data breach discovered on April 30, 2026, originating from a third-party vendor's database.▾
Reported19 lines
Customer data was potentially exposed through the vendor breach▾
No Hong Kong Privacy Commissioner or other regulator action has been disclosed as of the latest reporting.▾
The incident creates potential regulatory exposure under Hong Kong privacy rules.▾
Incident corroborated by two social/community posts on Reddit (r/cybersecurity and r/privacy), consistent with trade media reporting.▾
As a Hong Kong-regulated securities entity handling personal data, the subsidiary faces potential regulatory exposure under Hong Kong privacy rules.▾
The incident creates potential regulatory exposure under Hong Kong privacy rules; no regulator action has been confirmed to date.▾
Customer data was potentially exposed through the vendor breach, per SoFi Hong Kong's disclosure.▾
No public statement or enforcement action from the Hong Kong Privacy Commissioner or other regulators has been disclosed as of the latest update.▾
SoFi Securities (Hong Kong) Limited is a subsidiary of a US-listed fintech parent.▾
The event is characterized as a supply-chain cyber incident affecting a financial services entity in Hong Kong, with potential third-party liability and cyber insurance implications.▾
Customer data was potentially exposed through the third-party vendor breach; specific categories and scope remain undisclosed.▾
Customer data was potentially exposed through the vendor breach; categories and scope remain unconfirmed.▾
Customer data was potentially exposed through the vendor breach; specific data categories are not yet confirmed.▾
Customer data was potentially exposed through the vendor breach; scope and categories remain undisclosed.▾
No insured loss estimate has been disclosed.▾
No insured loss estimate has been disclosed.▾
The supply-chain breach at a third-party vendor creates potential third-party liability exposure for SoFi Hong Kong.▾
There is no evidence of systemic market impact from this incident.▾
No evidence of systemic market impact has been observed.▾
Uncertain45 lines
Scope and categories of personal data affected▾
Total number of customers impacted▾
Identity of the third-party vendor▾
Whether the incident involved extortion or ransomware demands▾
Threat actor attribution▾
Total number of customers impacted has not been disclosed.▾
Total number of customers impacted has not been disclosed.▾
Total number of customers impacted has not been disclosed.▾
The total number of customers impacted has not been disclosed.▾
Whether the incident involved extortion or ransomware demands has not been confirmed.▾
Scope and categories of personal data affected have not been disclosed by SoFi.▾
Threat actor attribution has not been disclosed.▾
No public confirmation of any extortion demand or ransomware component.▾
The identity of the third-party vendor whose database was accessed has not been publicly disclosed.▾
Scope and categories of personal data affected remain unconfirmed by SoFi Hong Kong.▾
No Hong Kong Privacy Commissioner or other regulator action has been disclosed at this stage.▾
Scope and categories of personal data affected, and the total number of customers impacted, remain unconfirmed.▾
The identity of the third-party vendor involved has not been disclosed.▾
It is unconfirmed whether the incident involved extortion or ransomware demands; threat actor attribution is also unknown.▾
Identity of the third-party vendor involved has not been disclosed.▾
No threat actor attribution has been reported.▾
Scope and categories of personal data affected have not been disclosed by the company.▾
Identity of the third-party vendor has not been disclosed.▾
Whether the incident involved extortion or ransomware demands has not been disclosed; threat actor attribution is also unconfirmed.▾
The identity of the third-party vendor whose database was accessed has not been disclosed.▾
The scope and categories of personal data potentially exposed remain undisclosed; SoFi has stated it does not yet have complete information about scope, impact, or which categories of personal data were involved.▾
It has not been confirmed whether the incident involved any extortion or ransomware demands.▾
The identity of the third-party vendor whose database was accessed has not been publicly disclosed.▾
The scope and categories of personal data exposed, total number of customers impacted, and identity of the third-party vendor remain unconfirmed.▾
No insured loss estimate has been disclosed for the incident.▾
No insured loss estimate has been disclosed.▾
No insured loss estimate has been disclosed.▾
Identity of the third-party vendor has not been disclosed.▾
Scope and categories of personal data affected have not been disclosed.▾
Total number of customers impacted has not been disclosed.▾
Whether the incident involved extortion or ransomware demands has not been disclosed.▾
Threat actor attribution has not been disclosed.▾
Whether the incident involved extortion demands, ransomware, or other coercive tactics has not been confirmed.▾
The categories of personal data potentially exposed have not been confirmed.▾
No threat actor group has been attributed to the breach in public reporting.▾
The categories and scope of personal data exposed in the breach have not been confirmed by SoFi.▾
It has not been confirmed whether the incident involved ransomware, extortion or any ransom demand.▾
The total number of customers impacted by the breach has not been disclosed.▾
The categories of personal data potentially involved (e.g., identifiers, financial, KYC) have not been confirmed.▾
No Hong Kong Privacy Commissioner or other regulator action has been publicly reported as of the latest refresh.▾
Geographic Zone Matches
3 active matches
- TRIA Certified AreasRule-basedConfidence 100%
- Pacific Ring of FireRule-basedConfidence 100%
- Caribbean Hurricane ZoneRule-basedConfidence 100%
Geographic zone matches are RiskEvents spatial/analytical indicators, not coverage determinations or Lloyd's official classifications.
Affected countries
Latest developments
- Identity of the third-party vendor remains undisclosed. — BleepingComputer
- Confirmed affected entity is SoFi Securities (Hong Kong) Limited. — BleepingComputer
- Breach discovery date confirmed as April 30, 2026. — BleepingComputer
- Unauthorized access was via a third-party vendor's database, confirming a supply-chain attack vector. — BleepingComputer
- Customer data was potentially exposed; specific categories and scope remain undisclosed. — BleepingComputer
- External incident response has been engaged. — BleepingComputer
- A Hong Kong support line (+852 26938888) has been established for affected customers. — BleepingComputer
- Scope and categories of personal data affected remain undisclosed. — BleepingComputer
Timeline
SoFi Hong Kong disclosed a data breach at a third-party vendor containing customer information from its securities business. The scope, number of affected customers, and specific data exposed remain unknown. The incident represents a supply chain cyber attack on a fintech subsidiary with potential cyber liability and regulatory exposure.
Source: r/cybersecurity (Social / Community) · View source
Status changed to developing
evidence_trigger: corroboration >= 2
signal -> developing
SoFi has disclosed a data breach affecting its Hong Kong securities subsidiary, where hackers gained unauthorized access to a third-party vendor's database containing customer information. The incident was discovered on April 30, 2026, and the scope of exposed data remains under investigation, with potential implications for cyber liability coverage and regulatory exposure across multiple jurisdictions.
Source: r/privacy (Social / Community) · View source
Initial Detection
SoFi Securities (Hong Kong) Limited disclosed a data breach discovered on April 30, 2026, in which unauthorized actors accessed customer data via a third-party vendor's database. The scope of exposed personal data remains unknown, and the company has not confirmed customer count impact, extortion demands, or vendor identity. This is a supply-chain cyber incident affecting a financial services entity in Hong Kong, with potential third-party liability and cyber insurance implications.
We do not yet have complete information about the scope and impact of the incident, or whether (and, if so, which categories of) your personal data was involved.
Source: BleepingComputer (Trade Media) · View source
Lloyd's classifications
Tracking this kind of risk? Get an email when Cyber events escalate.
Get alerts