OANDA CORPORATION
bd_931f2fe241f97100 · schema v1 · pii pii-v1
Full breach record for OANDA CORPORATION →On March 3, 2014, OANDA Corporation experienced an unauthorized breach affecting a server containing historical PayPal payment logs (pre-2007) and credentials for the 'fxPense' expense reporting tool. Exposed data included names, email addresses, and fxPense usernames/passwords. The incident did not impact fxTrade services, client trades, or funds. OANDA disabled access, notified the FBI and regulators, and conducted a security review.
J jump to incidentP pin to compareR raw source
Incident timeline
Mar 3, 2014
Begins
Mar 3, 2014
Discovered
Mar 5, 2014
Filed
vs. sector median
9 wks faster
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.