Topstep LLC
ent_9dc308a48c21756cc40277bc
Disclosures
6
State AG · 3 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
1,920
nationwide · State AG TX
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Topstep LLC
- Normalized
- topstep— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- topstep.com
Disclosure history (6)newest first
- Nebraska State AGas victim2026-01-15
Topstep LLC notified affected individuals of a cybersecurity incident discovered on December 15, 2025. Cyber threat actors used credential stuffing with stolen credentials from external sources to gain unauthorized access to user accounts. The incident potentially exposed names, contact info, dates of birth, government IDs, tax info, and SSNs. Topstep blocked malicious IPs, forced password resets, and is implementing mandatory MFA. Affected individuals were offered complimentary Experian IdentityWorks.
- Massachusetts State AGas victim2025-12-30
Topstep LLC reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2025-12-30. 17 Massachusetts residents were affected.
- Nebraska State AGas victim2025-12-30
Topstep LLC notified Nebraska residents of a data security incident detected on September 8, 2025, involving a DDoS attack that may have led to unauthorized access to customer accounts. The company discovered on December 3, 2025, that PII was potentially accessed between September 8 and October 16, 2025. Topstep engaged external cybersecurity professionals and is offering complimentary credit monitoring and fraud assistance via Cyberscout (TransUnion).
- Texas State AGas victim2025-12-22
Topstep LLC based in Chicago, Illinois, a other entity reported a data breach to the Texas Attorney General. The breach was discovered on 2025-12-05 and reported on 2025-12-22. 222 Texas residents were affected. 1,920 individuals affected in total. Types of information involved: Name of individual;Address;Social Security Number Information;Other. Consumers were notified via U.S. Mail.
- Nebraska State AGas victim2025-12-22
Topstep LLC notified affected individuals of a credential-stuffing attack discovered on November 26, 2025. Threat actors used stolen credentials from external sources to gain unauthorized access to user accounts. Potentially compromised data includes names, contact info, screen names, tax ID numbers, and Social Security Numbers. Topstep blocked attacker IPs, forced password resets, and offered 24 months of Experian IdentityWorks. Notifications were sent in December 2025.
- Massachusetts State AGas victim2025-12-22
Topstep LLC reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2025-12-22. 19 Massachusetts residents were affected.