THE CHARLES SCHWAB CORPORATION
ent_019e412dcb7cc808fe3d6633b892f7a0
Disclosures
13
State AG · 3 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
975
as filed · State AG WA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- THE CHARLES SCHWAB CORPORATION
- Normalized
- the charles schwab— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300VSGCJ7E698NM85
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (13)newest first
- Montana State AGas victim2023-06-08
Charles Schwab & Co., Inc. issued a supplemental notification to Montana residents regarding unauthorized access to client accounts by a third-party service provider. Access occurred on or around April 19, 2023. Compromised data included names, SSNs, driver's license numbers, and financial account details. Schwab locked accounts, offered two years of credit monitoring via IdentityForce, and continues monitoring for unusual activity.
- Massachusetts State AGas victim2018-04-30
Charles Schwab reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2018-04-30. 3 Massachusetts residents were affected. The report records the breach type as paper.
- Massachusetts State AGas victim2018-04-30
Charles Schwab reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2018-04-30. 1 Massachusetts residents were affected. The report records the breach type as paper.
- Massachusetts State AGas victim2017-12-18
Charles Schwab reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2017-12-18. 2 Massachusetts residents were affected. The report records the breach type as electronic.
- Massachusetts State AGas victim2017-12-18
Charles Schwab reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2017-12-18. 2 Massachusetts residents were affected. The report records the breach type as paper.
- Massachusetts State AGas victim2017-12-15
Charles Schwab reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2017-12-15. 1 Massachusetts residents were affected. The report records the breach type as paper.
- Massachusetts State AGas victim2017-12-15
Charles Schwab reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2017-12-15. 1 Massachusetts residents were affected. The report records the breach type as paper.
- Massachusetts State AGas victim2017-09-05
Charles Schwab reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2017-09-05. 2 Massachusetts residents were affected. The report records the breach type as electronic.
- Massachusetts State AGas victim2017-07-20
Charles Schwab reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2017-07-20. 2 Massachusetts residents were affected. The report records the breach type as electronic.
- Washington State AGas victim2016-11-11
Charles Schwab & Co. Inc. notified Washington AG that a 'Credential Replay' incident involving stolen usernames and passwords affected 975 Washington residents starting March 25, 2016. Unauthorized parties accessed names, emails, and account numbers; some attempted unauthorized transfers. Schwab restricted access, notified the FBI, and offered 2 years of credit monitoring.
- Massachusetts State AGas victim2015-10-02
Charles Schwab reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2015-10-02. 63 Massachusetts residents were affected. The report records the breach type as electronic.
- Massachusetts State AGas victim2015-08-17
Charles Schwab reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2015-08-17. 1 Massachusetts residents were affected. The report records the breach type as electronic.
- Massachusetts State AGas victim2015-01-09
Charles Schwab reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2015-01-09. 2 Massachusetts residents were affected. The report records the breach type as paper.
Subsidiary disclosures (8)filed by group companies
◈ These filings were made by or about subsidiaries of THE CHARLES SCHWAB CORPORATION — not by THE CHARLES SCHWAB CORPORATION itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.
- New Hampshire State AGvia TD AMERITRADE CLEARING, INC.2023-08-09
TD Ameritrade, a subsidiary of Charles Schwab, disclosed a security incident involving MOVEit Transfer software. Between May 28 and May 30, 2023, unauthorized individuals accessed the application and stole personal information, including names. The incident was discovered on May 30, 2023. TD Ameritrade halted use of the software, engaged independent experts, and notified law enforcement. Affected individuals were offered credit monitoring services.
- Oregon State AGvia TD AMERITRADE CLEARING, INC.2023-08-08
TD Ameritrade, Inc. and Charles Schwab & Co., Inc., a TD Ameritrade affiliate. reported a data breach to the Oregon Attorney General. The breach was reported on 2023-08-08. 61,160 individuals were affected.
- Montana State AGvia TD AMERITRADE CLEARING, INC.2023-08-08
TD Ameritrade, Inc. notified Montana residents of a data breach involving MOVEit Transfer software. Unauthorized access occurred between May 28-30, 2023, resulting in the theft of names, SSNs, and potentially financial account data. TD Ameritrade halted the software, engaged experts, and notified law enforcement. Affected individuals are offered two years of credit monitoring.
- Washington State AGvia TD AMERITRADE CLEARING, INC.2023-08-08
TD Ameritrade, Inc. reported a cybersecurity incident involving the MOVEit Transfer software. Between May 28 and May 30, 2023, unauthorized individuals accessed the application and stole data including names, Social Security numbers, and potentially financial account information. The incident was discovered on May 30, 2023. Notices were sent to affected individuals on August 3, 2023. 1,662 Washington residents were affected. TD Ameritrade halted use of the software, engaged independent experts, notified law enforcement, and offered two years of credit monitoring.
- Maine State AGvia TD AMERITRADE CLEARING, INC.2023-08-08
TD Ameritrade, Inc. and Charles Schwab & Co., Inc. reported an external system breach (hacking) occurring between May 28 and May 30, 2023, discovered on August 1, 2023. The incident affected 61,160 individuals, including 143 Maine residents. Acquired data included names and financial account or credit/debit card numbers (with security codes, PINs, or passwords). Affected individuals were notified in writing on August 8, 2023, and offered 24 months of identity theft protection services.
- California State AGvia TD AMERITRADE CLEARING, INC.2023-08-08
TD Ameritrade, Inc. disclosed a data breach involving unauthorized access to its MOVEit Transfer software application between May 28 and May 30, 2023. The incident was discovered on May 30, 2023. Affected data includes names, Social Security numbers, financial account information, dates of birth, and government ID numbers. TD Ameritrade halted use of the software, engaged independent experts, notified law enforcement, and is offering two years of credit monitoring.
- GLOBALLeak Sitevia TD AMERITRADE CLEARING, INC.2023-07-07
Online Stock Trading, Investing, Brokerage - TD Ameritrade
- Hawaii State AGvia TD AMERITRADE CLEARING, INC.2007-09-14
TD Ameritrade reported a data breach to the Hawaii Office of Consumer Protection. The office was notified on 2007/09.14. Breach type: Hackers/Unauthorized Access. 33,157 Hawaii residents were affected. Recovered from the Internet Archive after the notice was removed from the OCP table.