Commentary

Tom Smith
VP, Web Analytics  

Ameritrade Notifies Customers Of Data Breach -- Proactively

Online brokerage TD Ameritrade is warning customers today that some of their personal information, including e-mail addresses, was accessed by an external source. Its handling of the situation shows there's some progress being made toward more proactive disclosure of security breaches, since the disclosure comes before any known loss of personal identity data such as Social Security numbers.

Online brokerage TD Ameritrade is warning customers today that some of their personal information, including e-mail addresses, was accessed by an external source. Its handling of the situation shows there's some progress being made toward more proactive disclosure of security breaches, since the disclosure comes before any known loss of personal identity data such as Social Security numbers.In a letter to account holders (full disclosure: I received the letter), CEO Joe Moglia explains:

While investigating client reports about the industry-wide issue of investment-related SPAM, we recently discovered and eliminated unauthorized code from our systems. This code allowed certain information stored in one of our databases, including e-mail addresses, to be retrieved by an external source.

More Insights

White Papers

More >>

Reports

More >>

Webcasts

More >>

Please be assured that UserIDs and passwords are not included in this database, and we can confirm that your assets remain secure at TD AMERITRADE.

He goes on to say the code was quickly eliminated and customer assets are protected in the event of any loss. Of course, if someone's identity gets stolen as a result of this, that's another matter. The letter also says:

While Social Security numbers are stored in this particular database, we have no evidence to establish they were retrieved or used to commit identity theft.

I'll take the liberty of appending "yet" to that final sentence.

As a potential identity theft victim, this explanation doesn't give me much comfort. It makes me even more uneasy about sharing personal data or using online financial services. Obviously there was a significant security hole that allowed the "unauthorized code" to get in. I just hope that gap has been closed permanently.

Although User IDs and passwords apparently weren't breached, I'd still like to see TD Ameritrade put tougher account access requirements in place. (Vanguard Group and HSBC Direct are two examples of online transaction sites with a more rigorous sign-on process).

This will be the third time Ameritrade has made it onto the Privacy Rights Clearinghouse's list of data breaches. The first two were small in comparison with many of the higher-profile breaches that have occurred.

Yet I appreciate what appears to be a proactive stance by Ameritrade to make this notification. Let's just hope it results in nothing more than some additional spam. Update 2:25 p.m on 9/14/07: See our complete news coverage by Sharon Gaudin here.


Related Reading




Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

InformationWeek encourages readers to engage in spirited, healthy debate, including taking us to task. However, InformationWeek moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. InformationWeek further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
T-Shirt Giveaway T-Shirt Giveaway: Each week we're selecting one great comment from our readers. The author of the comment will receive an InformaitonWeek Community t-shirt. So get posting!
Subscribe to RSS

Resource Links