Topstep Brokerage
ent_a67da6a4365cfce9610f8a65
Disclosures
10
State AG · 5 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
1,922
nationwide · State AG NH
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Topstep Brokerage
- Normalized
- topstep brokerage— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- topstepbrokerage.com
Disclosure history (10)newest first
- Indiana State AGas victim2026-01-20
Topstep LLC reported a data breach to the Indiana Attorney General. The breach occurred on 2025-12-14 and was reported on 2026-01-20. 11 Indiana residents were affected. 938 individuals affected in total.
- Indiana State AGas victim2026-01-20
Topstep LLC reported a data breach to the Indiana Attorney General. The breach occurred on 2025-12-14 and was reported on 2026-01-20. 11 Indiana residents were affected. 938 individuals affected in total.
- Vermont State AGas victim2026-01-16
Topstep LLC reported a cybersecurity incident on December 14, 2025, involving credential stuffing attacks using stolen credentials from external sources. The attack may have granted unauthorized access to user accounts containing PII, including names, DOBs, government IDs, and SSNs. Topstep blocked malicious IPs, forced password resets, and is offering credit monitoring. The incident is currently contained.
- Massachusetts State AGas victim2026-01-12
Topstep LLC notified Massachusetts residents of a cybersecurity incident involving high-volume traffic attacks blocked at the Web Application Firewall. The company forced password resets for affected accounts and is implementing mandatory multifactor authentication. Complimentary 24-month identity monitoring via Experian is being offered. No specific dates for discovery or occurrence were provided in the sample letter.
- New Hampshire State AGas victim2026-01-05
Topstep LLC notified the New Hampshire Attorney General of a security incident involving password stuffing. Between September 8 and October 16, 2025, unauthorized access occurred, potentially exposing names and Social Security numbers of one New Hampshire resident. Topstep discovered the breach on December 3, 2025, engaged cybersecurity experts, and began notifying affected individuals on December 30, 2025, offering credit monitoring services.
- Indiana State AGas victim2025-12-30
Topstep LLC reported a data breach to the Indiana Attorney General. The breach occurred on 2025-09-08 and was reported on 2025-12-30. 4 Indiana residents were affected. 520 individuals affected in total.
- Indiana State AGas victim2025-12-22
Topstep LLC reported a data breach to the Indiana Attorney General. The breach occurred on 2025-11-26 and was reported on 2025-12-22. 14 Indiana residents were affected. 1,920 individuals affected in total.
- New Hampshire State AGas victim2025-12-22
Topstep LLC experienced a credential-stuffing attack on November 26, 2025, resulting in unauthorized access to user accounts. Approximately 1,922 individuals were affected, including 2 New Hampshire residents. Compromised data included names, contact info, dates of birth, and tax/SSN information. Topstep contained the incident, forced password resets, and is implementing mandatory MFA.
- Maine State AGas victim2025-12-22
Topstep LLC experienced a data breach due to an external system breach (hacking), affecting 1920 individuals, including 1 Maine resident.
- Indiana State AGas victim2025-12-20
Topstep LLC reported a data breach to the Indiana Attorney General. The breach occurred on 2025-11-21 and was reported on 2025-12-20. 1 Indiana residents were affected. 37 individuals affected in total.