HackingStolen CredentialsCustomer Data InvolvedIDENTITY_BASICCREDENTIALSFINANCIAL_ACCOUNTLowContained
You Can Trade, Inc.
bd_0dbd93a8386e2d20 · schema v1 · pii pii-v1
Full breach record for You Can Trade, Inc. →You Can Trade, Inc. (YCT), a subsidiary of TradeStation Group, Inc., discovered on May 28, 2020, that unauthorized persons accessed personal data of YCT customers and prospective customers. The accessed data included names, usernames, salted and hashed passwords, email addresses, phone numbers, and limited credit card information (type, last four digits, expiration date) for subscribers. YCT shut down two domains mimicking its website and implemented additional security measures.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-190827
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 12, 2020
- Raw hash
- f1bc40dcab3ecad5277fc608f8ed065555d5802cdfb0ac9d3150d64a3b591fbb
Reporting entity
- Name
- You Can Trade, Inc.norm: you can trade
- Domain
- youcantrade.com
Victim entity
- Name
- You Can Trade, Inc.norm: you can trade
- Domain
- youcantrade.com
Incident
- Discovered
- May 28, 2020
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICCREDENTIALSFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
Compliance
- Time to disclose
- 15 days(15 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.