Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
EVO Banco

EVO Banco Vendor Cyber Rating & Cyber Score

evobanco.com

EVO es una nueva manera de hacer banca, una banca inteligente, evolucionada, sencilla y transparente. Desarrollamos nuestra actividad en todo el ámbito nacional, excepto Galicia, Asturias y León. Tenemos nuestra sede central en Madrid y contamos con una red de oficinas que cubren las las principales ciudades españolas y en las que más de 600 profesionales dan servicio a nuestros clientes. Desplegamos un modelo que aspira a ser la evolución de la banca, combinando en una única entidad toda la facilidad, agilidad y comodidad de un banco on-line y la cercanía y profesionalidad de una amplia red de oficinas.


EVO Banco A.I CyberSecurity Scoring

EVO Banco
Company Information
Website:https://www.evobanco.com
Employees number:184
Number of followers:55,405
NAICS:52211
Industry Type:Banking
Homepage:evobanco.com
EVO Banco Risk Score (AI oriented)
Between 650 and 699
logo
EVO BancoBanking
Updated:
01/05/2026
667/1000
Weak
B
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
EVO Banco Global Score (TPRM)
xxxx
logo
EVO BancoBanking
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

EVO Banco
EVO BancoWeak
Current Score
667B (WEAK)
01000
1 incidents
0 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
673Before Incident
JULY 2026
672Before Incident
JUNE 2026
670Before Incident
MAY 2026
667Before Incident
APRIL 2026
667Before Incident
MARCH 2026
665Before Incident
FEBRUARY 2026
664Before Incident
JANUARY 2026
662Before Incident
DECEMBER 2025
660Before Incident
NOVEMBER 2025
658Before Incident
OCTOBER 2025
657Before Incident
SEPTEMBER 2025
655Before Incident
MARCH 2024
755Before Incident
Breach
23 Mar 2024EVO Banco
Bankinter and EVO Banco: Bankinter fined €240K for EVO Banco data breach exposing 1.27M records

Spain’s AEPD Fines Bankinter €240,000 Over 2024 EVO Banco Data Breach

612After Incident
CRITICAL-143
EVOBAN1777652813
Spain’s AEPD Fines Bankinter €240,000 Over 2024 EVO Banco Data Breach Spain’s data protection authority (AEPD) has concluded its investigation into a 2024 cyberattack on EVO Banco, imposing a €240,000 fine on Bankinter after the lender absorbed EVO Banco through a merger. The breach, which exposed sensitive personal and financial data of over 1.27 million individuals, stemmed from an API vulnerability introduced during a system migration in February 2024. The flaw, approved through EVO Banco’s internal change management process, removed access controls on an API used in customer onboarding, allowing unauthenticated queries to retrieve data. Between 23 and 27 March 2024, the vulnerable endpoint processed 5.47 million requests, with 1.27 million successfully accessing personal records. Exposed data included names, national identity numbers, IBANs, employment details, VAT declarations, and income levels far exceeding the bank’s initial characterization of the breach as limited to basic identifying information. EVO Banco only detected the incident on 8 April 2024 after a third-party cybercrime monitoring service flagged a Dark Web post advertising a database of 1.3 million customers. The attacker, who joined the forum weeks earlier with minimal reputation, later demanded a ransom, publishing data for 958 clients and four employees when EVO Banco refused to pay. The bank filed a police report on 22 April 2024, though forensic analysis could not confirm whether the full dataset was exfiltrated. The AEPD’s investigation identified three critical security failures: the API’s lack of authorization checks, unencrypted personal data, and a change management process that failed to test for access control vulnerabilities. While EVO Banco initially classified the breach as low-risk and declined to notify affected individuals, the AEPD intervened on 18 April 2024, ordering mandatory disclosures under GDPR Article 34. The proposed fine of €400,000 was reduced to €240,000 after Bankinter acknowledged liability and paid voluntarily in November 2025. The AEPD cited aggravating factors, including the scale of exposed financial and identity data, but applied mitigations due to the merger, which transferred legal responsibility to Bankinter following EVO Banco’s deregistration in April 2025. The case underscores the risks of inadequate API security and the limitations of internal risk assessments when financial data is involved. It also highlights the AEPD’s enforcement focus on data processing governance, with recent fines against Informa D&B (€1.8M), FC Barcelona (€500K), and Yoti (€950K) reinforcing its scrutiny across sectors.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Financial gain (ransom demand)
IMPACT
Financial Loss: €240,000 fineData Compromised: Personal and financial data of over 1.27 million individualsSystems Affected: Customer onboarding APIOperational Impact: Mandatory disclosures under GDPR Article 34, police report filedBrand Reputation Impact: Yes (EVO Banco and Bankinter)Legal Liabilities: GDPR violation, AEPD fineIdentity Theft Risk: High (exposed national identity numbers, IBANs, employment details, VAT declarations, income levels)Payment Information Risk: High (exposed IBANs)
DATA BREACH
NamesNational identity numbersIBANsEmployment detailsVAT declarationsIncome levelsNumber Of Records Exposed: 1.27 millionSensitivity Of Data: High (financial and personally identifiable information)Data Exfiltration: Unconfirmed (attacker published data for 958 clients and 4 employees)Data Encryption: No (unencrypted personal data)Personally Identifiable Information: Yes (national identity numbers, names, employment details, etc.)

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for EVO Banco ?
?
What was EVO Banco's A.I Rankiteo Cyber Score in July 2026 ?
?
What was EVO Banco's A.I Rankiteo Cyber Score in June 2026 ?
?
What was EVO Banco's A.I Rankiteo Cyber Score in May 2026 ?
?
What was EVO Banco's A.I Rankiteo Cyber Score in April 2026 ?
?
What was EVO Banco's A.I Rankiteo Cyber Score in March 2026 ?
?
What was EVO Banco's A.I Rankiteo Cyber Score in February 2026 ?
?
What was EVO Banco's A.I Rankiteo Cyber Score in January 2026 ?
?
What was EVO Banco's A.I Rankiteo Cyber Score in December 2025 ?
?
What was EVO Banco's A.I Rankiteo Cyber Score in November 2025 ?
?
What was EVO Banco's A.I Rankiteo Cyber Score in October 2025 ?
?
What was EVO Banco's A.I Rankiteo Cyber Score in September 2025 ?
?
What is the average per-incident point impact on EVO Banco's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with EVO Banco ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view EVO Banco's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?
EVO Banco Cyber Scoring History | Rankiteo