MalwareFinancial ServicesRansomwareStolen CredentialsData EncryptedData ExfiltratedCustomer Data InvolvedIDENTITY_BASICPIILowContained
US TIGER SECURITIES INC.
bd_f29aee610e2ff2c9 · schema v1 · pii pii-v1
Full breach record for US TIGER SECURITIES INC. →US Tiger Securities Inc. experienced a cybersecurity incident where files were encrypted and copied by an unauthorized third party from July 8-9, 2025. The incident was discovered on July 10, 2025. Affected data includes names and other personal information. The company engaged forensic investigators and is offering 24 months of credit monitoring.
California clockDiscovered Jul 10, 2025 → Notified May 15, 2026309d ✗ CA 60-day late44 weeks discovery → filing
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_08d3e651a1fbee44Vermont State AGfiled 2026-05-15Verified
- bd_11827b814e70462fTexas State AGfiled 2026-05-15Verified
- bd_678b9bdd9ac8e7f0Washington State AGfiled 2026-05-15Verified
- bd_7fa2aa1eedf7d7e4New Hampshire State AGfiled 2026-05-15Verified
Show 3 more filings ↓Show fewer ↑up to 14d gap
- bd_9083d9bde07929f2Indiana State AGfiled 2026-05-15Verified
- bd_a75c3a2bd552ad81Maine State AGfiled 2026-05-15Verified
- bd_74b756aa1437bfe2Massachusetts State AGfiled 2026-05-01(14d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-623464
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 15, 2026
- Raw hash
- d130329ab56e88e69d0ceaef5154ed914ed89b90bcf70f1acf3b25187e1b430b
Reporting entity
- Name
- US TIGER SECURITIES INC.norm: us tiger securities
Victim entity
- Name
- US TIGER SECURITIES INC.norm: us tiger securities
- Industry
- Financial Services
Incident
- Discovered
- Jul 10, 2025
- Materiality determined
- —
- Notification sent
- May 15, 2026
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICPII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- External
Compliance
- Time to disclose
- 44 weeks(309 days from discovery to filing)
- Compliance flags
- CA 60-day late · 309dCA AG copy ≤15d · 0d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jul 10, 2025→ Notified: May 15, 2026309d 60 days (analyst band, pre-2026 discoveries) CA 60-day late California Consumers notified: May 15, 2026→ AG copy submitted: May 15, 20260d 15 calendar days CA AG copy ≤15d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.