CUSTOMER INFORMATION
Last updated: 29 August 2026 17:30 CET.
On 17 August 2026, we were informed by a company that provides services to us that a third party had gained unauthorized access to its systems. That company processes certain personal data on our behalf in order to provide platform and operational services as part of the Calida Financial service offering. We immediately suspended the affected connection and commenced an investigation with independent forensic specialists to establish whether, and to what extent, any customer data was affected.
On 27 August 2026 the investigation confirmed that some personal data was extracted from the affected system by the third party. The extracted data includes the following categories of customer information: name, date of birth, email address, residential address, IP address, identity document type, identity document number.
Passwords, financial instrument data and customer funds were not held in the affected system and could therefore not have been extracted.
Some customers’ data was affected. We are contacting every affected customer directly with a personal notification confirming that their information was involved and the recommended protective steps. If you are not contacted, your information was not among the extracted data.
Customer funds are not affected: funds are safeguarded in accordance with our regulatory obligations and are held separately from the affected system. To date, no unauthorized transactions have been identified on any account as a result of this incident.
FREQUENTLY ASKED QUESTIONS
(Version from 29 August 2026 17:30 CET, Updated 31 August 2026 19:16 CET: Changed date in “Am I affected?” section to 01 September 2026.)
Am I affected?
Every customer whose information was among the extracted data is being contacted directly by email. If you are not contacted by 01 September 2026, your information was not among the extracted data. If the ongoing investigation alters this position, we will contact you.
Has my information actually been taken?
The investigation has confirmed that data was extracted from the affected system. The categories concerned are listed above. Affected customers are being notified directly with confirmation that their information was involved.
Is my money safe?
Yes. Customer funds are safeguarded and held separately from our own funds in accordance with our regulatory obligations, and were held separately from the affected system. To date, no unauthorised transactions have been identified on any account as a result of this incident.
Is the system now safe?
The third-party provider did immediately implement additional security measures preventing external access. The attack vector was identified and eliminated already on 17 August 2026.
Was my password taken?
No. Passwords were not held in the affected system and were not extracted. However, we strongly recommend changing your password as a precautionary measure, particularly if you use the same password elsewhere.
Was my financial instrument data taken?
No. Financial instrument data was not held in the affected system and was not extracted.
Do I need to do anything?
We ask all customers — and affected customers in particular — to apply the following measures now:
- Treat unexpected contact with suspicion. Third parties may use the extracted information to contact you pretending to be us, and such contact may appear convincing because it references accurate personal details. We will never call, email or message you to ask for your password, PIN, one-time code, or any financial information. If anyone does, it is not us — end the contact.
- Check your account regularly and report anything you do not recognise straight away.
- Change your password if you use the same one anywhere else. Change it in the app under Settings → Security.
- Turn on all available security notifications in the app.
- Be alert to misuse of your identity information. Report any suspected misuse to us at privacy@calida.financial and to the police.
How will I know a message is really from you?
We will never ask you for your password, PIN, one-time passcode or full card number — by phone, email, SMS or in the app. Our emails come from privacy@calida.financial or bcsupport@calida.financial . If you are unsure, do not click anything: open the app directly, or message us at privacy@calida.financial. Our direct notifications to affected customers do not ask you to click links, provide credentials, or make payments.
What happened, exactly?
A third party gained unauthorized access to systems operated by one of our service providers and extracted data held there. The provider’s investigation indicates the access was obtained by exploiting a vulnerability in third-party software used by the provider. The forensic investigation is continuing, including verification of the remediation applied by the provider, and we will update this page as further findings are confirmed.
When will services be restored?
Calida Financial services have been fully regenerated and can be used as before.
When will you know more?
The forensic investigation is ongoing. We will update this page as findings are confirmed, and affected customers will be notified directly of any further findings that materially affect them.
Have you told the regulators?
Yes. We have notified the Malta Financial Services Authority and the Information and Data Protection Commissioner, and both are being kept informed of the investigation’s findings.
Can I close my account or refund my balance?
Yes, by reaching out to our customer service on bcsupport@calida.financial.
How can I exercise my GDPR rights?
Our Privacy Department can be reached at privacy@calida.financial for any request relating to your personal information.
Who can I complain to?
Our complaints process is located here: Complaints Policy. You may also complain to the Information and Data Protection Commissioner (www.idpc.org.mt) or, in relation to our services, to the Office of the Arbiter for Financial Services (www.financialarbiter.org.mt).
Initial Information
Last updated: 20/08/2026 16:15 CET
On 17 August 2026, we were informed by a company that provides services to us that a third party had gained access to their systems. This company processes certain information on our behalf in order to provide platform and operational services as part of the Calida Financial service offering. An investigation was commenced immediately and is being conducted with independent forensic specialists. It remains ongoing and this notification is being issued on a precautionary basis pending
its outcome.
At this stage, it has not been established whether any customer information was in
fact viewed or extracted.
Customer funds are not affected: funds are safeguarded in accordance with our regulatory obligations and are held separately from the affected system. We are notifying potentially affected customers on a precautionary basis, and we will publish confirmed findings on this page as they become available.
FREQUENTLY ASKED QUESTIONS (Last updated: 20/08/2026 16:15 CET)
Am I affected?
This has not yet been established. If you have not been contacted, we do not currently believe your information was held in the affected system. If our understanding changes in either direction, we will contact you.
Has my information actually been taken?
We do not yet know. The investigation has not established whether any customer information was viewed or extracted. What we can currently confirm is which categories of information were held in the affected system. Once the investigation reaches confirmed findings, we will notify affected customers directly and update this page.
Is my money safe?
Yes. Customer funds are safeguarded and held separately from our own funds in accordance with our regulatory obligations, and were held separately from the affected system. To date, no unauthorised transactions have been identified on any account as a result of this incident.
Was my password taken?
No. However, we strongly recommend changing your password as a precautionary measure.
Was my financial instrument data taken?
No.
Do I need to do anything?
Although it has not been established whether your information was affected, we recommend the following precautions:
1. Be alert to phishing. Criminals may use this information to contact you pretending to be us. We will never call, email or message you to ask for your password, PIN, one-time code, or any financial information. If anyone does, it is not us — end the contact.
2. Check your account regularly and report anything you do not recognise straight away.
3. Change your password if you use the same one anywhere else. Change it in the app under Settings → Security as soon as the service is online again.
- Turn on all available security notifications in the app.
How will I know a message is really from you?
We will never ask you for your password, PIN, one-time passcode or full card number — by phone, email, SMS or in the app. Our emails come from privacy@calida.financial. If you are unsure, do not click anything: open the app directly, or message us at privacy@calida.financial.
What happened, exactly?
A third party gained access to systems operated by one of our service providers. The provider’s investigation indicates the access was obtained by exploiting a vulnerability in third-party software used by the provider. The full technical facts, including the extent of any access to information, are still being established by independent forensic investigators. We will update this page when confirmed findings are available.
Why are you telling me this if you don’t yet know whether I’m affected?
We are required to act — and choose to communicate — on a precautionary basis rather than wait for the investigation to conclude. Early notification allows you to take simple protective steps now.
We will follow up with confirmed findings.
When will you know more?
The forensic investigation is ongoing. We will update this page as findings are confirmed, and will contact potentially affected customers directly with the outcome — including if the outcome is that their information was not affected.
Have you told the regulators?
Yes. We have notified the Malta Financial Services Authority and the Information and Data Protection Commissioner.
Can I close my account?
Yes, by reaching out to our customer service at bcsupport@calida.financial.
How can I exercise my GDPR rights?
Our Privacy Department can be reached at privacy@calida.financial for any request relating to your personal information.
Who can I complain to?
Our complaints process is at located here: Complaints Policy . You may also complain to the Information and Data Protection Commissioner (www.idpc.org.mt) or, in relation to our services, to the Office of the Arbiter for Financial Services (www. https://www.financialarbiter.org.mt/ ).
