Hacker Gained Access To Data On Millions Of TD Ameritrade Customers - InformationWeek

InformationWeek is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Software // Enterprise Applications

Hacker Gained Access To Data On Millions Of TD Ameritrade Customers

The online brokerage is blaming the database breach on "unauthorized code" that was found in the network. E-mail addresses, names and phone numbers were stolen.

Online brokerage TD Ameritrade Holding Corp. announced today that a hacker broke into one of its databases and stole personally identifying information for some of its 6.3 million customers.

An online advisory and letters to account holders disclosed that names, e-mail addresses, phone numbers and home addresses were taken in the data breach. Client assets, along with user IDs, personal identification numbers and passwords, were not stored in the compromised database.

However, the advisory noted that it's unclear if account numbers, dates of birth and Social Security numbers were stolen. The company said there is no evidence that any customers were the victim of identity theft because of this security breach.

TD Ameritrade did not say when the hackers got into the database or how long they remained there.

"While the financial assets our clients hold with us were never touched, and there is no evidence that our cleints' Social Security numbers were taken, we understand that this issue has increased unwanted spam, which is annoying and inconvenient for them," said Joe Moglia, chief executive officer of TD Ameritrade, in a statement. "We sincerely apologize for that and any added concern this may have caused."

TD Ameritrade tracked down the break-in while doing an internal investigation into stock-related spam. The company called in forensic investigators and they discovered "unauthorized code" in their system that provided access for the hacker or hackers. According to the advisory, the code has been eliminated from the system.

Moglia, speaking in an online video-taped message to customers, said he is "confidant" that they have figured out how the information was taken.

"This is an issue of the global e-commerce that will be with us the rest of our lives," he said in the video message. "You have my promise that we will remain totally committed to protecting the trust you've placed in us."

According to the Privacy Rights Clearinghouse's list of data breaches, TD Ameritrade lost a backup tape in 2005 that contained 200,000 records. And in December of 2006, a missing laptop contained unencrypted information, including names, addresses, birthdates and Social Security numbers. That incident affected about 300 current and former employees.

Today, the company is telling customers that they don't have to do anything with their accounts. They can change their passwords, but it's not necessary, according to an advisory.

We welcome your comments on this topic on our social media channels, or [contact us directly] with questions about the site.
Comment  | 
Print  | 
More Insights
2021 Outlook: Tackling Cloud Transformation Choices
Joao-Pierre S. Ruth, Senior Writer,  1/4/2021
Enterprise IT Leaders Face Two Paths to AI
Jessica Davis, Senior Editor, Enterprise Apps,  12/23/2020
10 IT Trends to Watch for in 2021
Cynthia Harvey, Freelance Journalist, InformationWeek,  12/22/2020
White Papers
Register for InformationWeek Newsletters
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you.
Flash Poll