Topstep LLC
bd_9075a6acb8fc2654 · schema v1 · pii pii-v2
Full breach record for Topstep LLC →2 incidents on fileTopstep LLC notified affected individuals of a cybersecurity incident discovered on December 15, 2025. Cyber threat actors used credential stuffing with stolen credentials from external sources to gain unauthorized access to user accounts. The incident potentially exposed names, contact info, dates of birth, government IDs, tax info, and SSNs. Topstep blocked malicious IPs, forced password resets, and is implementing mandatory MFA. Affected individuals were offered complimentary Experian IdentityWorks.
J jump to incidentP pin to compareR raw source
Incident timeline
Dec 14, 2025
Begins
Dec 15, 2025
Discovered
Jan 15, 2026
Filed
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.