2024 Interactive Brokers — business email compromise; limited client PII exposure
Data compromised
Customer-contact and limited identity fields referenced in state-filed notice samples
Technical writeup
Interactive Brokers LLC advised regulators that in January 2024 it uncovered a business email compromise giving an adversary unauthorized access to some consumer personal information within its mail environment—not a core trading-platform compromise in the firm’s public telling. Sample Massachusetts breach paperwork and trade press described notifications for hundreds of clients with names plus at least one additional sensitive category, credit monitoring offers, and no confirmed misuse statements typical of BEC blast-radius reviews at broker-dealers.
Root cause
Business email compromise against corporate email workflows