HackingStolen CredentialsCustomer Data InvolvedIDENTITY_BASICCREDENTIALSLowContained
OANDA CORPORATION
bd_931f2fe241f97100 · schema v1 · pii pii-v1
Full breach record for OANDA CORPORATION →On March 3, 2014, OANDA Corporation experienced an unauthorized breach affecting a server containing historical PayPal payment logs (pre-2007) and credentials for the 'fxPense' expense reporting tool. Exposed data included names, email addresses, and fxPense usernames/passwords. The incident did not impact fxTrade services, client trades, or funds. OANDA disabled access, notified the FBI and regulators, and conducted a security review.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-44326
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 5, 2014
- Raw hash
- 0469527cb6f528190477cc6d443de49152ce291dd7cd2638d3036490113b76b1
Reporting entity
- Name
- OANDA CORPORATIONnorm: oanda
Victim entity
- Name
- OANDA CORPORATIONnorm: oanda
Incident
- Discovered
- Mar 3, 2014
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICCREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Alerted the Federal Bureau of Investigation (FBI)Alerted regulators and relevant privacy offices
Compliance
- Time to disclose
- 2 days(2 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.