Hacker News new | ask | show | jobs
by blakeburnette 751 days ago
The data breach did not cause the collapse of Synapse. Synapse has been a slow rolling collapse for the past 2ish years due to horrible management. Ultimately Synapse imploded when Mercury left Synapse as a BaaS provider to partner directly with Evolve BT. The Synapse collapse definitely put Evolve into the spotlight as someone with a ton of turmoil, lack of sufficient oversight and insufficient technological governance.

Evolve is an otherwise obscure bank chartered in Arkansas but headquartered in Tennessee (a little sketchy) that has over-leveraged itself. This is why it was hit with a Cease and Desist from the FDIC. The C&D also probably contributed to them becoming a target for LockBit.

Evolve is also the underlying bank for Stripe Treasury, although to my knowledge, their have been no new partnerships with them. I have heard the number 2 thrown around. Of note, Shopify is the main person for whom this was built and uses this.

Consequently if you have submitted KYC/KYB information for Shopify, Mercury, Yotta, Dave, any other past Synapse partners, or some Modern Treasury partners your data was breached. This seems to be the primary information shared along with account and routing numbers. This becomes problematic especially as part of the check involves external account and routing numbers along with SSN of any UBOs.

Fintechs do not partner with small banks because of debit card fees but because of Dodd Frank regulations (primarily).

1 comments

Wow, Mercury’s account and routing numbers were all leaked, along with all KYC info? Is there a way to confirm that?

Their email made it sound much less serious.

(Apropos nothing, sorry about your motorcycle accident — I hope you’ve recovered well. Thank you for this comment; the severity of this breach wasn’t apparent till now.)

Is now afraid to get on my motorcycle today. If you linked an external account, then most likely. However, it is my understanding that Mercury had a very relaxed KYC and I would suppose their user are not impacted by external accounts. The more likely victim of external accounts are B2B participants of partners of Evolve. This would most likely be true for Shopify. FWIW, routing numbers are public. Other data included in the hack is Evolve's emails in the form of outlook data files. Affirm is another definite impacted individual. VA loan data is probably also included in this hack.