Charles Schwab announces TD Ameritrade data breach

Charles Schwab announces TD Ameritrade data breach
Tens of thousands of clients could have been affected by huge attack resulting from vulnerabilities found in MOVEit file transfer software.
JUL 14, 2023

Charles Schwab Corp., the parent company of TD Ameritrade, Inc., has disclosed that it is just the latest company to suffer a data breach resulting from vulnerabilities found in MOVEit file transfer software. While the company claims that the computer systems of both companies remains unharmed, customer data stored on Ameritrade's MOVEit server was compromised.

The incident is currently under investigation by both Schwab and Ameritrade, with a thorough analysis expected to be completed soon. Upon conclusion, Schwab says, affected customers will be notified.

This data breach holds significant implications, as it contributes to one of the largest breaches of 2023, affecting millions of Americans. The compromised information puts individuals at an increased risk of identity theft and other fraudulent activities. It is crucial for customers who receive a data breach notification from TD Ameritrade or Charles Schwab to understand the potential risks and take appropriate measures.

The cause of the breach stems from vulnerabilities discovered in the MOVEit software, which TD Ameritrade used on a limited basis. The incident came to light after the software's developers detected a zero-day vulnerability.

Promptly responding to the potential security breach, TD Ameritrade ceased using MOVEit and promptly informed law enforcement. Simultaneously, an investigation was initiated to determine the scope of the breach and the specific client data that may have been exposed. Although this investigation remains ongoing, Schwab estimates that approximately 0.5% of Ameritrade's clients may have been affected. That could mean up to 55,000 clients have been affected.

In a release, Schwab emphasized its commitment to providing regular updates to clients as new information emerges, ensuring direct communication with affected individuals. It is anticipated that one of the two companies will issue data breach letters to impacted customers in the near future.

The MOVEit hack has already claimed some big scalps — the biggest U.S. pension fund, Calpers, and Genworth Financial have both said that clients personal information has been compromised.

Some of the companies that have been affected by the MOVEit hack already:
1st Source Bank
First Merchants Bank
Deutsche Bank
ING
Commerzbank
TD Ameritrade
Shell PLC
British Airways
Radisson Hotels
Jones Lang LaSalle
UofL Health
Tom Tom
U of Colorado

Russian-based group Cl0p, which who claimed responsibility for the attack, has already published Shell’s data to the dark web after the company failed to pay a ransom — there is no indication yet what fate awaits TD Ameritrade.

Latest News

What should RIAs have on their regulatory radar right now?
What should RIAs have on their regulatory radar right now?

With a new regime at the SEC, Savvy Wealth's Lisandra Wilmott speaks out on ongoing and unfolding risks around off-channel communications, AI, and private market investments.

Emigrant Bank appoints Mark Rogozinski to lead family office services
Emigrant Bank appoints Mark Rogozinski to lead family office services

The veteran leader from Cresset will support Emigrant’s network of high-net-worth advisory firms and specialty platforms.

'Truly concerning:' Social media is winning Gen Z's wallets over financial advisors
'Truly concerning:' Social media is winning Gen Z's wallets over financial advisors

Gallup finds 42% of American adults under 30 are getting financial advice from social media, raising concerns of "misinformation being shared by finfluencers."

After investment success, Warren Buffett-backed college at risk from GOP tax threat
After investment success, Warren Buffett-backed college at risk from GOP tax threat

Draft tax legislation by House Republicans raises concerns for aid-giving private universities, with steep hikes on levies based on "lifeblood" endowment dollars per pupil.

Federal judge dismisses LPL’s defamation suit against Ameriprise
Federal judge dismisses LPL’s defamation suit against Ameriprise

But that doesn’t mean the contentiousness between the two is over.

SPONSORED Beyond the dashboard: Making wealth tech human

How intelliflo aims to solve advisors' top tech headaches—without sacrificing the personal touch clients crave

SPONSORED The evolution of private credit

From direct lending to asset-based finance to commercial real estate debt.