Topstep LLC
bd_716ada46a8c7b0a2 · schema v1 · pii pii-v2
Full breach record for Topstep LLC →2 incidents on fileTopstep LLC notified Nebraska residents of a data security incident detected on September 8, 2025, involving a DDoS attack that may have led to unauthorized access to customer accounts. The company discovered on December 3, 2025, that PII was potentially accessed between September 8 and October 16, 2025. Topstep engaged external cybersecurity professionals and is offering complimentary credit monitoring and fraud assistance via Cyberscout (TransUnion).
J jump to incidentP pin to compareR raw source
Incident timeline
Sep 8, 2025
Begins
Sep 8, 2025
Discovered
Dec 30, 2025
Filed
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- Massachusetts State AGbd_342fa38f154153c72025-12-30Candidate
- Texas State AGbd_03fab57c09efae722025-12-22 · +8dCandidate
- Nebraska State AGbd_2541b774d16590192025-12-22 · +8dVerified
- Massachusetts State AGbd_7451ebd5f9fa712a2025-12-22 · +8dVerified
Filing propagation · 5 filings · 3 states
View merged incident ↗Pattern: first filing Dec 22 (TX), last Dec 30 (NE) — a 8-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.