HackingStolen CredentialsTargetedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
CHARLES SCHWAB & CO., INC.
bd_6ba375156c12caa7 · schema v1 · pii pii-v1
Full breach record for CHARLES SCHWAB & CO., INC. →Charles Schwab & Co., Inc. notified clients of unusual login activity beginning on or after March 25, 2016. The incident involved credential stuffing, where attackers used usernames and passwords obtained from non-Schwab sites to access Schwab accounts. Affected data included names, account numbers, positions, and transaction history. Schwab restricted access and monitored accounts.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_d10937f215910e8fCalifornia State AGfiled 2016-05-03Verified
- bd_d2e00d06b003a7cbMontana State AGfiled 2016-05-04(1d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/charles-schwab-20160503.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 3, 2016
- Raw hash
- db7735dbda2ca467f38c93a50f89dce844cadf3656d4094bfd2261dc3c361db5
Reporting entity
- Name
- CHARLES SCHWAB & CO., INC.norm: charles schwab
- Domain
- schwab.com
Victim entity
- Name
- CHARLES SCHWAB & CO., INC.norm: charles schwab
- Domain
- schwab.com
Incident
- Discovered
- Mar 25, 2016
- Materiality determined
- —
- Notification sent
- May 4, 2016
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 6 weeks(39 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.