Item 8.01. Other Events.
On June 25, 2024, Evolve Bank & Trust (“Evolve”), the third-party issuer of the Affirm Card, notified the Company that Evolve had experienced a cybersecurity incident whereby a third party gained unauthorized access to personal information and financial information (“Personal Information”) of Evolve retail banking customers¹,²,³,⁴ and the customers of its financial technology partners. Because the Company shares the Personal Information of Affirm Card users with Evolve to facilitate the issuance and servicing of Affirm Cards, the Company believes that the Personal Information of Affirm Card users was compromised as part of Evolve’s cybersecurity incident. However, the Company’s information systems were not compromised, nor was the ability for Affirm Card holders to continue using their Affirm Card. This incident has not impacted any other part of the Company’s business or operations.⁵,⁶
Upon being notified of the Evolve cybersecurity incident, the Company immediately began an investigation independent of Evolve’s investigation to determine whether any Affirm Card user Personal Information had been compromised, and that investigation, along with remediation efforts, is ongoing as of the date of this Current Report on Form 8-K (the “Filing”). Evolve has communicated to the Company that this cybersecurity incident has been contained.⁷ However, the full scope, nature and impact of the incident on the Company and Affirm Card users, including the extent to which there has been unauthorized access to Affirm Card user Personal Information, are not yet known. The Company has notified law enforcement and all Affirm Card users of the Evolve cybersecurity incident. Affirm Card users continue to be able to transact with their Affirm Cards, and the Company heightened its fraud monitoring.⁸,⁹
As of the date of this Filing, the Company does not expect that the Evolve cybersecurity incident is reasonably likely to have a material impact on the Company, including its financial condition or results of operations¹⁰,¹¹.
Forward-Looking Statements
This Current Report on Form 8-K contains forward-looking statements within the meaning of Section 27A of the Securities Act of 1933, as amended, and Section 21E of the Securities Exchange Act of 1934, as amended, that involve risks and uncertainties. All statements other than statements of historical fact are forward-looking statements, including statements regarding: the Company’s ongoing investigation and remediation of the Evolve cybersecurity incident; the nature and extent of the incident, including the extent of unauthorized access to Affirm Card user Personal Information; Evolve’s mitigation and remediation efforts; the potential disruption to our business or operations, including whether and to what extent Affirm Card usage may be impacted now and in the future; and the potential impact on the Company’s reputation, financial condition and results of operations. These forward-looking statements involve known and unknown risks, uncertainties and other important factors that may cause actual results to differ materially from expectations as of the date of this filing. Among the factors that could cause actual results to differ materially from those indicated in the forward-looking statements are risks and uncertainties associated with the ongoing investigation and remediation of the Evolve cybersecurity incident, risks related to security breaches or incidents, as well as other risks listed or described from time to time in our most recent Annual Report on Form 10-K and in our other filings with the U.S. Securities and Exchange Commission. Except as required by law, the Company assumes no obligation to update any of the statements in this Current Report on Form 8-K.