MalwareRansomwareData ExfiltratedData EncryptedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
US TIGER SECURITIES INC.
bd_7fa2aa1eedf7d7e4 · schema v1 · pii pii-v1
Full breach record for US TIGER SECURITIES INC. →US Tiger Securities Inc., a fintech brokerage, notified the NH Attorney General of a July 2025 ransomware incident affecting its virtual back-office environment. Files were encrypted and copied by an unauthorized third party between July 8-9, 2025. The incident impacted 53 New Hampshire residents, exposing names, SSNs, and expired driver's license numbers. US Tiger engaged forensic experts, notified law enforcement, and began mailing notifications on May 15, 2026, offering 24 months of credit monitoring.
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_08d3e651a1fbee44Vermont State AGfiled 2026-05-15Verified
- bd_11827b814e70462fTexas State AGfiled 2026-05-15Verified
- bd_678b9bdd9ac8e7f0Washington State AGfiled 2026-05-15Verified
- bd_9083d9bde07929f2Indiana State AGfiled 2026-05-15Verified
Show 3 more filings ↓Show fewer ↑up to 14d gap
- bd_a75c3a2bd552ad81Maine State AGfiled 2026-05-15Verified
- bd_f29aee610e2ff2c9California State AGfiled 2026-05-15Verified
- bd_74b756aa1437bfe2Massachusetts State AGfiled 2026-05-01(14d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/us-tiger-securities-20260515.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 15, 2026
- Raw hash
- a8ece90e7117940984a4979c700c5634ddec6b9817ea2cb99cadbc8a0377005c
Reporting entity
- Name
- Norton Rose Fulbright US LLPnorm: norton rose fulbright us
Victim entity
- Name
- US TIGER SECURITIES INC.norm: us tiger securities
Incident
- Discovered
- Jul 10, 2025
- Materiality determined
- —
- Notification sent
- May 15, 2026
- Affected individuals
- 53
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
Compliance
- Time to disclose
- 44 weeks(309 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.