[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f4ysrMvlmJeEUQmjYw81nSTrff0kf5xwhcxL2S9Mdgdk":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"company":11,"breachDate":15,"addedDate":16,"modifiedDate":16,"pwnCount":17,"totalRecords":17,"dataClasses":18,"description":20,"source":21,"isVerified":4,"isSpamList":22,"isSensitive":4,"severity":23,"processingStatus":24,"logoUrl":25,"contentUpdatedAt":16,"hasEnglishDescription":4},"6a66a3e572b31fc0381e3dc9","SoFiHongKong2026","SoFi Hong Kong 2026 Data Breach","sofi-hong-kong-2026","sofi.hk",{"name":12,"sector":13,"country":14,"website":10},"SoFi Securities (Hong Kong) Limited","Financial Services","Hong Kong","2026-04-30T00:00:00.000Z","2026-07-27T00:18:45.026Z",0,[19],"Customer database information; specific categories under investigation","\u003Cp>\u003Cstrong>The SoFi Hong Kong 2026 data breach\u003C\u002Fstrong> is an incident in which SoFi Securities (Hong Kong) Limited confirmed unauthorized access to a customer database held by a third-party provider. The company detected the access on April 30, 2026, engaged an outside cybersecurity firm, and told customers that the investigation had not yet determined the full scope or which personal-data categories might be involved.\u003C\u002Fp>\n\u003Cp>BleepingComputer published the customer-notification email and direct confirmation from a SoFi spokesperson, while SC Media summarized the incident and the company's disclosed limits in a separate report. SoFi did not identify an affected-person count, third-party provider, or specific data fields. LeakData therefore keeps pwnCount at zero as an unknown total and does not invent personal-data types.\u003C\u002Fp>\n\u003Ch2>How Was the Incident Confirmed?\u003C\u002Fh2>\n\u003Cp>In an email to customers, SoFi Hong Kong said it detected unauthorized access through one of its providers to a database belonging to SoFi Securities (Hong Kong) Limited. A company spokesperson separately confirmed the breach to BleepingComputer. These primary statements establish a completed third-party data-access event rather than merely suspicious activity.\u003C\u002Fp>\n\u003Cp>April 30 is the company's detection date, not the attacker's initial-access date or duration in the database. The public account does not identify the exploited vulnerability, compromised account, network path, or exfiltration method. Because the provider was not named, no platform or company is labeled as technically responsible.\u003C\u002Fp>\n\u003Ch2>Why Is the Data Scope Unknown?\u003C\u002Fh2>\n\u003Cp>SoFi confirmed access to a customer database while saying it did not yet know whether, and which, categories of personal data were involved. Customer names, contact details, identity documents, account numbers, transaction history, password hashes, and financial records were not individually confirmed by the company.\u003C\u002Fp>\n\u003Cp>LeakData uses only “customer database information with categories under investigation” in dataClasses. This broad description identifies the system type without claiming that every customer field was stolen. The record can be updated with more specific classes if the investigation determines which rows and fields were viewed or copied.\u003C\u002Fp>\n\u003Ch2>Affected-Person Count\u003C\u002Fh2>\n\u003Cp>SoFi did not disclose how many customers were affected, and its spokesperson declined additional questions on that point. SoFi Hong Kong's total customer or account count is not a breach total, and copying of the entire database was not confirmed. pwnCount is therefore zero, with no figure inferred from company-size metrics.\u003C\u002Fp>\n\u003Cp>Zero does not mean that the event had no customers or no impact. Customer notifications and extra monitoring on affected accounts indicate potential person-level impact but provide no unique total. This record can change if a regulatory filing, completed forensic review, or company update publishes a reliable number.\u003C\u002Fp>\n\u003Ch2>Third Party and SoFi Systems\u003C\u002Fh2>\n\u003Cp>The confirmed access occurred in a database held by an outside provider on behalf of SoFi Hong Kong. The disclosure does not say that all United States banking, lending, investing, or other systems operated by SoFi Technologies were compromised. This record covers only the notified incident involving SoFi Securities (Hong Kong) Limited customers.\u003C\u002Fp>\n\u003Cp>Because the provider and any impact on its other customers were not disclosed, the event should not be merged with unrelated supply-chain cases. The phrase third party also does not prove that a particular SaaS product, cloud vendor, or integration was the attack path. Technical attribution remains open until supporting evidence emerges.\u003C\u002Fp>\n\u003Ch2>SoFi's Response\u003C\u002Fh2>\n\u003Cp>After detection, SoFi engaged an outside cybersecurity firm to respond and investigate scope and impact. Additional safeguards and monitoring were applied to affected accounts. The company said support requests or account changes might require customers to provide extra verification information.\u003C\u002Fp>\n\u003Cp>Customers were advised to watch for suspicious emails and messages, phishing attempts, and unusual account activity. SoFi recommended updating passwords, enabling two-factor authentication where possible, monitoring financial accounts, and avoiding links or attachments in unsolicited messages. These are precautionary steps and do not prove a specific password or financial-data exposure.\u003C\u002Fp>\n\u003Ch2>How to Interpret This LeakData Record\u003C\u002Fh2>\n\u003Cp>This record confirms unauthorized access to a SoFi Hong Kong customer database; it does not identify which personal fields were accessed or how many people were affected. The financial-services context alone is insufficient to add unverified balances, transactions, identities, or password fields. The content preserves the investigation's stated uncertainty.\u003C\u002Fp>\n\u003Cp>The verified conclusion is that SoFi Hong Kong detected unauthorized access to a third-party customer database on April 30, 2026, engaged outside experts, warned customers, and applied additional protections. The provider, attacker, technical method, person count, accessed categories, and extent of copying were undisclosed, so the record uses a broad data class and unknown total.\u003C\u002Fp>","Unauthorized access to third-party customer database",false,"Low","completed","\u002Fuploads\u002Flogo\u002Fsofi_hk.svg"]