CHARLES SCHWAB & CO., INC.
bd_fa7595d9df0ccd59 · schema v1 · pii pii-v1
Full breach record for CHARLES SCHWAB & CO., INC. →31 incidents on fileCharles Schwab & Co., Inc. notified Montana residents that between May 18 and December 16, 2021, certain chat and email messages sent through Schwab.com were inadvertently sent to external email systems. Affected data included names, SSNs, tax IDs, driver's licenses, passport numbers, or usernames/passwords. Schwab remediated the issue, offers two years of credit monitoring via IdentityForce, and states there is no evidence of misuse.
J jump to incidentP pin to compareR raw source
Incident timeline
May 18, 2021
Begins
Dec 16, 2021
Discovered
Mar 23, 2022
Filed
vs. sector median
+5 wks slower
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- California State AGbd_3f19b6e6e347a91c2022-03-23Candidate
- Maine State AGbd_61155f67c4c7204a2022-03-23Verified
- Indiana State AGbd_b253d38aa342fb412022-03-23Verified
- Massachusetts State AGbd_1abb864ead347d592022-03-25 · +2dVerified
Show 1 more filing ↓Show fewer ↑up to 5d gap
- New Hampshire State AGbd_94260cb23b33690a2022-03-28 · +5dVerified
Filing propagation · 6 filings · 6 states
View merged incident ↗Pattern: first filing Mar 23 (CA), last Mar 28 (NH) — a 5-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.