TD Ameritrade, Inc. and Charles Schwab & Co., Inc.
ent_a1dcd50c5a45c1ed91e38676
Disclosures
4
State AG · 4 jurisdictions
Incidents
2
filings grouped by incident
Max affected reported
61,160
as filed · State AG OR
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- TD Ameritrade, Inc. and Charles Schwab & Co., Inc.
- Normalized
- td ameritrade inc and charles schwab— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (4)newest first
- ⛰️New Hampshire State AGas reporting2023-08-09
TD Ameritrade, a subsidiary of Charles Schwab, disclosed a security incident involving MOVEit Transfer software. Between May 28 and May 30, 2023, unauthorized individuals accessed the application and stole personal information, including names. The incident was discovered on May 30, 2023. TD Ameritrade halted use of the software, engaged independent experts, and notified law enforcement. Affected individuals were offered credit monitoring services.
- 🦫Oregon State AGas victim2023-08-08
TD Ameritrade, Inc. and Charles Schwab & Co., Inc., a TD Ameritrade affiliate. reported a data breach to the Oregon Attorney General. The breach was reported on 2023-08-08. 61,160 individuals were affected.
- 🌲Washington State AGas victim2023-08-08
TD Ameritrade, Inc. and Charles Schwab & Co., Inc., a finance sector entity reported a malware incident to the Washington Attorney General. The organization became aware of the incident on 2023-05-30 and filed notice on 2023-08-08. 1,662 Washington residents were affected. 70 days elapsed between awareness and notification. 2 days to identify the breach. 0 days to contain the breach.
- 🦞Maine State AGas victim2023-08-08
TD Ameritrade, Inc. and Charles Schwab & Co., Inc. reported an external system breach (hacking) occurring between May 28 and May 30, 2023, discovered on August 1, 2023. The incident affected 61,160 individuals, including 143 Maine residents. Acquired data included names and financial account or credit/debit card numbers (with security codes, PINs, or passwords). Affected individuals were notified in writing on August 8, 2023, and offered 24 months of identity theft protection services.