HackingStolen CredentialsCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
Fidelity Investments
bd_77897170293356c7 · schema v1 · pii pii-v1
Full breach record for Fidelity Investments →Fidelity Investments notified customers of a data security incident where a third party accessed and obtained personal information using two recently established customer accounts between August 17 and August 19, 2024. Fidelity detected the activity on August 19 and terminated access. The incident involved a small subset of customers. Fidelity offered 24 months of complimentary credit monitoring and identity restoration services.
California clockDiscovered Aug 19, 2024 → Notified Oct 9, 202451d ✓ CA 60-day OK7 weeks discovery → filing
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_78b327f683ac4935Washington State AGfiled 2024-10-09Verified
- bd_b3720a09163c4a4fOregon State AGfiled 2024-10-09Verified
- bd_c1a61cf002005952New Hampshire State AGfiled 2024-10-09Verified
- bd_d2abb4008659b425Maine State AGfiled 2024-10-09Verified
Show 2 more filings ↓Show fewer ↑
- bd_f24c35fc28546ae6Indiana State AGfiled 2024-10-09Verified
- bd_fa30fee34b59e35fMontana State AGfiled 2024-10-09Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-593165
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 9, 2024
- Raw hash
- 9c9712833b5cfc92413f6df6c288dffb82a78ba884ed3e9c197b8f9e641d63bb
Reporting entity
- Name
- Fidelity Investmentsnorm: fidelity investments
- Domain
- fidelity.com
Victim entity
- Name
- Fidelity Investmentsnorm: fidelity investments
- Domain
- fidelity.com
Incident
- Discovered
- Aug 19, 2024
- Materiality determined
- —
- Notification sent
- Oct 9, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 7 weeks(51 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 51d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Aug 19, 2024→ Notified: Oct 9, 202451d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.