HackingSupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
TRADEZERO AMERICA, INC.
bd_62f236eaafb48355 · schema v1 · pii pii-v1
Full breach record for TRADEZERO AMERICA, INC. →TradeZero America Inc. notified California residents of a data breach involving its third-party vendor, Tawk.To. On July 29, 2024, TradeZero learned of suspicious activity affecting the Tawk.To environment. An unauthorized actor may have accessed personal information including names, Social Security numbers, driver's license numbers, financial brokerage/bank account information, and passport numbers. TradeZero launched an investigation, confirmed system security, and is offering 12 months of credit monitoring. No evidence of identity theft or fraud was found.
California clockDiscovered Jul 29, 2024 → Notified Sep 19, 202452d ✓ CA 60-day OK7 weeks discovery → filing
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_23d0e16efaa82b00Maine State AGfiled 2024-09-19Candidate
- bd_a004f9015b01165bIndiana State AGfiled 2024-09-19Verified
- bd_c1b1002275e8fcedMontana State AGfiled 2024-09-19Verified
- bd_c66ea600f46a7580New Hampshire State AGfiled 2024-09-19Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-592107
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 19, 2024
- Raw hash
- 1945bc00aa99fc36027b78503b9c68b8fb27f1a7454c6891e759a9011216465e
Reporting entity
- Name
- TRADEZERO AMERICA, INC.norm: tradezero america
- Domain
- tradezero.com
Victim entity
- Name
- TRADEZERO AMERICA, INC.norm: tradezero america
- Domain
- tradezero.com
Incident
- Discovered
- Jul 29, 2024
- Materiality determined
- —
- Notification sent
- Sep 19, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- External
- Regulator citations
- Notified applicable regulatory authorities, as required by law
- Third party
- via Tawk.To
- Initial access
- supply_chain
Compliance
- Time to disclose
- 7 weeks(52 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 52d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jul 29, 2024→ Notified: Sep 19, 202452d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.