[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f1a5ov5xjpl95c":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":12,"contentUpdatedAt":12,"source":13,"sourceUrl":14,"sourceUrls":15,"pwnCount":16,"affectedCount":16,"affectedCountStatus":17,"affectedCountLowerBound":18,"affectedCountUnit":19,"hasEnglishDescription":4,"severity":20,"dataClasses":21,"description":26,"seoTitle":27,"seoTitleEn":28,"seoDescription":27,"seoDescriptionEn":29,"logoUrl":30,"isVerified":4,"isSensitive":4,"isSpamList":31,"isMalware":31,"company":32},"6a715afb87fddb4d31ef8aef","EarnIn2025","EarnIn 2025 Data Breach","earnin-2025","earnin.com","2025-04-16T00:00:00.000Z","2026-08-04T03:22:34.967Z","Activehours \u002F EarnIn consumer notice and Texas Attorney General","https:\u002F\u002Foag.my.site.com\u002Fdatasecuritybreachreport\u002Fapex\u002FDataSecurityReportsPage",[14],202480,"known",null,"people","High",[22,23,24,25],"Names","Physical addresses","Dates of birth","Social security numbers","\u003Cp>\u003Cstrong>The 2025 EarnIn data breach\u003C\u002Fstrong> was a disclosure incident in which the company's system inadvertently sent encrypted personal information belonging to Lead Bank customers to another partner bank. The Texas Attorney General reports 202,480 affected people nationwide.\u003C\u002Fp>\u003Cp>EarnIn, operated by Activehours, Inc., provides earned-wage access and related financial services. The incident specifically involved customer information associated with the Early Pay service supported by Lead Bank.\u003C\u002Fp>\u003Ch2>When did the EarnIn data breach occur?\u003C\u002Fh2>\u003Cp>The Texas Attorney General record gives an incident period of April 16 through October 14, 2025. EarnIn's consumer notice says the transfers occurred from April 2025 through October 15 and that the issue was discovered on October 14.\u003C\u002Fp>\u003Cp>The one-day difference in the reported end date has not been resolved. The Texas record was published on November 12, 2025 and identifies email as the notification method.\u003C\u002Fp>\u003Ch2>How did the incident happen?\u003C\u002Fh2>\u003Cp>According to EarnIn, its system sent encrypted personal information belonging to Lead Bank customers to another partner bank. The incident was therefore an accidental transfer to the wrong recipient, rather than an attacker breaking into the network.\u003C\u002Fp>\u003Cp>The receiving bank was subject to federal and state regulation and contractual confidentiality obligations. EarnIn did not report a threat actor, malware, or publication of the data on the open internet.\u003C\u002Fp>\u003Ch2>What information was affected?\u003C\u002Fh2>\u003Cp>The consumer notice and Texas record list names, mailing addresses, dates of birth, and Social Security numbers.\u003C\u002Fp>\u003Cp>These are sensitive identity fields. However, the company says the transferred data was encrypted, and the list does not necessarily mean that every field was present for every affected person.\u003C\u002Fp>\u003Ch2>How many people were affected?\u003C\u002Fh2>\u003Cp>The Texas Attorney General reports 202,480 affected people nationwide, including 21,178 Texas residents. The Texas figure is included in the nationwide total and is not an additional count.\u003C\u002Fp>\u003Ch2>What risks can this incident create?\u003C\u002Fh2>\u003Cp>Social Security numbers and dates of birth can support identity theft or fraudulent account applications if obtained by an unauthorized person. In this incident, encryption and delivery to a regulated bank are important conditions that reduce the risk compared with a dataset published openly online.\u003C\u002Fp>\u003Cp>EarnIn said it had no evidence that the information had been misused or that there was a reasonable threat of identity theft or fraud. People aware of the incident should nevertheless be alert to fraudulent messages claiming to come from EarnIn or a bank.\u003C\u002Fp>\u003Ch2>How did EarnIn respond?\u003C\u002Fh2>\u003Cp>The company said it secured the affected environment, began an investigation with independent specialists, and reported the incident to the appropriate authorities. It also said the unintended partner bank destroyed the data it had received.\u003C\u002Fp>\u003Ch2>What should affected people do?\u003C\u002Fh2>\u003Cp>Notice recipients can verify the communication through EarnIn's official support channels and regularly review credit reports and unfamiliar accounts opened in their name.\u003C\u002Fp>\u003Cp>If an unfamiliar account or application appears, contact the relevant financial institution directly and consider adding a fraud alert or security freeze to the credit file. Do not provide a Social Security number, password, or verification code in response to an unexpected message.\u003C\u002Fp>","","EarnIn Data Breach (202.5 Thousand People Affected)","The EarnIn data breach affected 202,480 people when encrypted identity data was sent to the wrong partner bank. Learn what happened and what to do.","\u002Fuploads\u002Flogo\u002Fearnin.png",false,{"name":33,"sector":34,"country":35,"website":36,"websiteArchiveUrl":27,"websiteStatus":27,"websiteCheckedAt":18},"Activehours, Inc. d\u002Fb\u002Fa EarnIn","Financial Services","United States","https:\u002F\u002Fwww.earnin.com\u002F"]