SoFi Hong Kong disclosed a potential data breach after unauthorized access was detected in a database maintained by a third-party vendor for SoFi Securities (Hong Kong) Limited. The company said it discovered the incident on April 30 and has retained an external cybersecurity firm to investigate the scope and impact, but it has not yet confirmed what categories of customer information were exposed, how many customers were affected, or the identity of the vendor involved.
The firm warned customers to remain alert for phishing, suspicious communications, and unusual account activity while the investigation continues. SoFi said it has added extra safeguards and monitoring to affected accounts and may require additional verification for support requests or account changes, while advising customers to change passwords, enable two-factor authentication, and closely monitor financial accounts.

See attribution, scope, and your downstream exposure.
3 events from the most recent confirmed update back to the earliest known activity.
SoFi Hong Kong notified customers of the potential breach and advised them to watch for phishing, suspicious communications, and unusual account activity, while changing passwords, enabling two-factor authentication, and monitoring financial accounts. The company also said it added extra safeguards and monitoring to affected accounts and may require additional verification for support interactions or account changes.
After discovering the incident, SoFi Hong Kong engaged an external cybersecurity firm to investigate the breach involving its third-party vendor environment. At the time of disclosure, the company said it still had not confirmed what customer data was exposed, how many customers were affected, or the vendor's identity.
SoFi Hong Kong said it discovered on 2026-04-30 that an unauthorized party had accessed a database maintained by a third-party vendor for SoFi Securities (Hong Kong) Limited. The company said it had not yet determined the full scope or impact of the incident.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.