Confirmed breach. Intrusion Jul 3, 2025–Jul 9, 2025, discovered Jul 10, 2025 — the first regulatory filing landed 295 days later (flagged late). 29,340 individuals reported across the linked filings.
Regulatory clocksMassachusetts✗ MA AG >90dTexas✗ TX AG >30dWashington✗ WA AG >90dMaine✗ ME AG >90d · 309dCalifornia✗ CA 60-day late · 309dFull clock table in Litigation Timeline
State AGConfirmedLifecycle stage 2 of 3: ConfirmedUnverified claimConfirmedEnforcedlow sensitivity
Affected (total reported)
29,340
Data types
1
Identity (basic)
14days
Time between earliest and latest filing
Not recorded for this incident
Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster.
Jurisdictions
8
CA IN MA ME NH TX VT WA
Linked filings
8
all State AG
Affected residents by state
per-filing reported counts
IN26,985
ME26,985
TX1,417
WA885
NH53
State AGs report only their own residents; bars show per-filing counts.
Timeline
Earliest sighting first · deep chronology in Litigation Timeline
8 filings across 8 jurisdictions · May 1, 2026 – May 15, 2026 · 2 milestones
Breach window
Jul 8, 2025 → Jul 9, 2025
When the intrusion reportedly occurred, per the linked filings
Breach discoveredletter-grounded
Jul 10, 2025
Reported by MASSACHUSETTS AG, TEXAS AG, WASHINGTON AG, NEW HAMPSHIRE AG, MAINE AG, CALIFORNIA AG filings
295 days
8 State AG filingsMay 1, 2026 – May 15, 2026ExpandCollapse
MAVTTXWANHINMECA
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
US Tiger Securities Inc. reported a cybersecurity incident on July 10, 2025, involving the encryption of files in a virtual back-office environment supporting US Tiger and TradeUP Securities. An unauthorized third party copied files between July 8-9, 2025. The incident did not impact TradeUP's production trading environment. Personal information, including names, was involved. US Tiger engaged legal and forensic counsel, conducted a data review, and is offering 24 months of Experian IdentityWorks to affected individuals. Notification was sent on May 15, 2026.
MA AG >90d
🍁Vermont State AGlinked via multistate filing link · 100%
US Tiger Securities Inc. reported a data breach to the Vermont Attorney General. The breach was reported to the AGO on 2026-05-15. The reporting organization type is Financial Services. 17 Vermont residents were affected. Categories of data breached: Social Security Numbers, Government ID Numbers.
⭐Texas State AGlinked via multistate filing link · 95%
US Tiger Securities Inc. (“US Tiger”) based in New York, New York, a financial services entity reported a data breach to the Texas Attorney General. The breach was discovered on 2025-07-10 and reported on 2026-05-15. 1,417 Texas residents were affected. 26,985 individuals affected in total. Types of information involved: Name of individual;Address;Social Security Number Information;Driver’s License number;Government-issued ID number (e.g. passport, state ID card);Medical Information;Health Insurance Information. Consumers were notified via U.S. Mail.
Affected (this filing): 1,417
TX AG >30d
🌲Washington State AGlinked via multistate filing link · 100%
US Tiger Securities Inc. (“US Tiger”), a finance sector entity reported a ransomware incident to the Washington Attorney General. The organization became aware of the incident on 2025-07-10 and filed notice on 2026-05-15. 885 Washington residents were affected. 309 days elapsed between awareness and notification. 7 days to identify the breach. 5 days to contain the breach.
Affected (this filing): 885
WA AG >90d
⛰️New Hampshire State AGlinked via multistate filing link · 100%
US Tiger Securities Inc., a fintech brokerage, notified the NH Attorney General of a July 2025 ransomware incident affecting its virtual back-office environment. Files were encrypted and copied by an unauthorized third party between July 8-9, 2025. The incident impacted 53 New Hampshire residents, exposing names, SSNs, and expired driver's license numbers. US Tiger engaged forensic experts, notified law enforcement, and began mailing notifications on May 15, 2026, offering 24 months of credit monitoring.
Affected (this filing): 53
🏎️Indiana State AGlinked via multistate filing link · 95%
US Tiger Securities, Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2025-07-03 and was reported on 2026-05-15. 286 Indiana residents were affected. 26,985 individuals affected in total.
Affected (this filing): 26,985
🦞Maine State AGlinked via multistate filing link · 95%
US Tiger Securities Inc. reported an external system breach (hacking) occurring on July 3, 2025, discovered on July 10, 2025. The incident affected 26,985 individuals, including 31 Maine residents. The organization provided 24 months of Experian IdentityWorks credit monitoring and identity theft protection services to affected individuals.
Affected (this filing): 26,985
ME AG >90d · 309dME resident >180d · 309d
🐻California State AGlinked via multistate filing link · 95%
US Tiger Securities Inc. experienced a cybersecurity incident where files were encrypted and copied by an unauthorized third party from July 8-9, 2025. The incident was discovered on July 10, 2025. Affected data includes names and other personal information. The company engaged forensic investigators and is offering 24 months of credit monitoring.