Topstep LLC
bd_2541b774d1659019 · schema v1 · pii pii-v2
Full breach record for Topstep LLC →2 incidents on fileTopstep LLC notified affected individuals of a credential-stuffing attack discovered on November 26, 2025. Threat actors used stolen credentials from external sources to gain unauthorized access to user accounts. Potentially compromised data includes names, contact info, screen names, tax ID numbers, and Social Security Numbers. Topstep blocked attacker IPs, forced password resets, and offered 24 months of Experian IdentityWorks. Notifications were sent in December 2025.
J jump to incidentP pin to compareR raw source
Incident timeline
Nov 26, 2025
Begins
Nov 26, 2025
Discovered
Dec 22, 2025
Filed
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- Texas State AGbd_03fab57c09efae722025-12-22Candidate
- Massachusetts State AGbd_7451ebd5f9fa712a2025-12-22Verified
- Massachusetts State AGbd_342fa38f154153c72025-12-30 · +8dCandidate
- Nebraska State AGbd_716ada46a8c7b0a22025-12-30 · +8dVerified
Filing propagation · 5 filings · 3 states
View merged incident ↗Pattern: first filing Dec 22 (TX), last Dec 30 (NE) — a 8-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.