North America
FinWise Bank
Not every attack comes from outside. Adding to the surge in insider threats in recent months, the U.S. fintech firm FinWise Bank has warned that its customer data may have been exposed following a malicious insider attack.
FinWise Bank, which provides banking services and technology solutions to financial organizations, revealed that a former employee may have accessed or acquired its customer data after leaving the firm. The Utah-based company confirmed that the personal data of 689,000 customers, including information such as full names and other undisclosed data elements, may have been compromised. Some of the exposed records belonged to American First Finance (AFF), a poor-credit lender that partners with FinWise to offer installment loans.
According to a filing with the Office of the Maine Attorney General, the incident occurred on May 31, 2024, but wasn't detected until June 18 this year. In response, FinWise is offering all affected customers 12 months of free credit monitoring and identity theft protection.
This is the latest in a growing string of high-stakes malicious insider attacks. Earlier in May, Coinbase Global, Inc., an American cryptocurrency exchange, also suffered a similar incident when an overseas support staffer accepted a bribe and stole data belonging to nearly 70,000 customers.
How it could affect your business
Insider threats can be just as damaging as external attacks. Enforcing strict privilege controls and layering defenses with measures like multifactor authentication (MFA) is critical to prevent unauthorized access and reduce insider risk.
