SoFi disclosed a breach at its Hong Kong unit exposing 26,000 customers' personal data, including HK ID numbers. Detected Feb 16, 2025.

Continue reading
A data breach at SoFi Technologies’ Hong Kong subsidiary exposed the personal data of approximately 26,000 customers, the company disclosed on February 25, 2025.
A Form 8-K filed with the U.S. Securities and Exchange Commission confirmed that an unauthorized access incident hit SoFi Hong Kong. The breach was detected on February 16, 2025, and the company notified Hong Kong privacy regulators.
Unauthorized Database Access Security teams at SoFi Hong Kong identified anomalous activity on February 16 and immediately engaged external cybersecurity experts. Investigators determined an unauthorized third party had penetrated a database environment storing current and former customer records. The intrusion was contained, and access was cut off, according to the SEC filing. SoFi stated that no U.S. systems or the broader SoFi platform were affected.
26,000 Customer Records The incident touched roughly 26,000 individuals. Exposed data fields included full name, date of birth, Hong Kong identity card number, SoFi account number, and securities holdings information. Crucially, Social Security numbers, U.S. taxpayer identification numbers, passwords, and payment card data were not present in the accessed tables. The database was limited to the Hong Kong unit’s operations.
Exposed Personal Identifiers SoFi has not publicly detailed the attack vector used to gain entry, but the company categorized it as external unauthorized access. The accessed database did not store credentials that would enable direct account takeover. There is no evidence of fraud or misuse of the exposed data at this stage, the filing noted. The exposure window remains under forensic review.
Threat Actor Unknown No threat actor, group, or campaign has claimed responsibility for the breach. The investigation is ongoing, and SoFi has not attributed the activity to any known advanced persistent threat or criminal entity. The incident does not match current known patterns tied to regional cybercrime groups operating in Hong Kong’s financial sector.
No Financial Impact Found SoFi Hong Kong notified affected individuals in line with the Hong Kong Personal Data (Privacy) Ordinance. Complimentary identity monitoring services were offered to all impacted customers. SoFi assessed the operational and financial impact as immaterial in the 8-K, adding that the incident did not disrupt core business functions or trigger regulatory enforcement action.
Regulator Notification Filed The subsidiary hardened affected systems, engaged a specialist forensic firm, and implemented additional security controls. Notifications were submitted to the Hong Kong Office of the Privacy Commissioner for Personal Data. The full technical findings remain confidential, but SoFi stated it is cooperating with regulatory inquiries. The SEC filing serves as the official public disclosure.
Subsidiary Breach Pattern Breaches at subsidiary breaches continue to surface in financial services, often originating from regional units with thinner security stacks. Hong Kong’s data protection regulator has increased scrutiny of fintech operations handling sensitive identity documents. SoFi’s incident echoes a pattern where attackers exploit subsidiary access to harvest customer PII without triggering main-entity alarms.
Hardening Subsidiary Defenses Security teams managing multi-jurisdictional operations should enforce unified logging and access controls across all subsidiaries. Database-level encryption for identity card numbers and account identifiers reduces blast radius. Breach notification playbooks must align with local privacy laws for each operating region.

A third-party software flaw inside one of Japan's largest telcos exposed login credentials for up to 14.2 million email accounts across six ISPs. The passwords? Some were hashed. Some may not have been