CHARLES SCHWAB & CO., INC.
bd_3f19b6e6e347a91c · schema v1 · pii pii-v1
Full breach record for CHARLES SCHWAB & CO., INC. →31 incidents on fileCharles Schwab & Co., Inc. disclosed that between May 18, 2021, and December 16, 2021, certain chat and email messages sent through Schwab.com were inadvertently sent to external email systems. The incident was discovered on December 16, 2021. Affected data may include names, Social Security numbers, tax ID numbers, driver's license numbers, passport numbers, and usernames/passwords. Schwab stated there is no evidence of misuse or unauthorized access. The company remediated the issue and offered two years of credit monitoring and identity protection services.
J jump to incidentP pin to compareR raw source
Incident timeline
May 18, 2021
Begins
Dec 16, 2021
Discovered
Mar 23, 2022
Filed
vs. sector median
+5 wks slower
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- Maine State AGbd_61155f67c4c7204a2022-03-23Verified
- Indiana State AGbd_b253d38aa342fb412022-03-23Verified
- Montana State AGbd_fa7595d9df0ccd592022-03-23Verified by operator
- Massachusetts State AGbd_1abb864ead347d592022-03-25 · +2dVerified
Show 1 more filing ↓Show fewer ↑up to 5d gap
- New Hampshire State AGbd_94260cb23b33690a2022-03-28 · +5dVerified
Filing propagation · 6 filings · 6 states
View merged incident ↗Pattern: first filing Mar 23 (ME), last Mar 28 (NH) — a 5-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.