Join a community of professionals and get:
on all CeFPro events.
unlock speaker decks and audience polls.
Full library access the moment you sign up.
Digital Content

- Unlimited access to peer-contribution articles and insights
- Global research and market intelligence reports
- Discover Connect Magazine, a monthly publication
- Panel discussion and presentation recordings
- Data on about 689,000 FinWise customers accessed in May 2024
- Breach discovered June 18, 2025 and disclosed Sept 12 via Maine AG
- Bank notified users July 29; class actions consolidated in Utah
- Suits name FinWise and partner American First Finance
- Allegations include unencrypted storage and negligent safeguards
- Plaintiffs seek stronger controls and more than $5 million in relief
- FinWise offers 12 months of credit monitoring and ID protection
- Plaintiffs push for lifetime monitoring after SSN exposure
- Bank says impact not expected to be material and will defend
- Some affected data tied to the fintech partnership structure
FinWise Bank disclosed that personal information for roughly 689,000 customers may have been exposed in a cybersecurity incident first detected more than a year after it occurred.
According to a notice published by the Maine attorney general’s office on Sept. 12, a former FinWise employee accessed names, dates of birth, Social Security numbers and account numbers on May 31, 2024. The bank said it did not learn of the breach until June 18, 2025.
FinWise notified affected customers on July 29. Within days, multiple lawsuits were filed against the bank and its fintech partner, American First Finance, and six class actions have since been consolidated in federal court in Utah.
At least one complaint contends that FinWise stored data unencrypted and “negligently and unlawfully failed to safeguard” it.
Plaintiffs also accuse the companies of breach of contract and unjust enrichment and are seeking a court order requiring stronger protections, including encryption of all data collected in the course of business.
In letters to customers, FinWise said that once the breach was discovered it immediately launched an investigation with external cybersecurity specialists to determine whether sensitive data had been accessed.
The bank is offering 12 months of free credit monitoring and identity theft protection to those affected.
Some plaintiffs argue that a year of services is inadequate given the exposure of Social Security numbers and are pushing for lifetime monitoring and protection.
The consolidated complaint seeks more than $5 million in relief, without specifying how much would be allocated to damages.
FinWise warned investors in an August quarterly filing that additional lawsuits may follow. The bank said it intends to defend the litigation vigorously and, while unable to estimate potential losses or damages, expects the impact will not be material.
A FinWise spokesperson did not immediately respond to a request for comment. American First Finance, which partners with FinWise to offer installment loans, was also named in the litigation. Under their arrangement, FinWise acts as lender while the fintech provides technology.
FinWise told customers that “some” of the impacted data is connected to American First Finance.
The cases are likely to scrutinize partner oversight, third-party controls and incident detection capabilities, given the lengthy gap between the initial access and the bank’s discovery of the breach.
Regulatory attention may also intensify as plaintiffs highlight allegations of weak controls and delayed detection, while the companies point to their post-discovery investigation and remediation steps.
For customers, the immediate questions center on credit monitoring, identity protection and how long the fallout could last.