SoFi Hong Kong confirms third-party vendor data breach exposing customer personal information
SoFi customers in Hong Kong have had personal data exposed. SoFi $SOFI confirmed June 8 that attackers reached a customer database run by a third-party vendor, taking names, birth dates, addresses, emails, phone numbers and employment details. Passwords and account numbers were n
Customers of SoFi's Hong Kong unit are being warned that their personal information may have been exposed in a breach tied to an outside vendor. According to BleepingComputer and SC Media, SoFi Hong Kong detected unauthorized access to a customer database managed by a third-party vendor on April 30, 2026, and publicly disclosed the incident on June 8. Investigators say the attackers used social engineering and abused the vendor's access rather than deploying malware or ransomware, making this a supply chain compromise that reached data SoFi itself did not directly hold. The exposed records included names, dates of birth, addresses, email addresses, phone numbers, and employment and education details. SoFi $SOFI says account passwords and financial account numbers were not part of the affected data. The company has engaged outside cybersecurity experts, notified affected individuals and regulators, and added monitoring and verification measures, though it has said the investigation is ongoing and it cannot yet confirm exactly which records were touched. Customers have been advised to change passwords, turn on two-factor authentication, watch their accounts for unusual activity, and treat unexpected messages with caution.