/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Ameritrade leak looks to have started in late '05, much earlier than reported

E-mails obtained by Network World show that Ameritrade received explicit and repeated warnings from an IT security expert starting Jan. 9, 2006 that its customer data had apparently been compromised …

Network World Paul McNamara

Context & Ripple Effects

Six days after TD AMERITRADE published the results of its own client SPAM investigation, Network World has obtained e-mails that rewrite the timeline: an IT security expert warned the firm explicitly and repeatedly starting Jan. 9, 2006 that customer data had apparently been compromised, pointing to a leak that began in late 2005 — far earlier than anything the company had reported.

That gap matters because the firm's September 2007 account framed the compromise around recently surfaced stock-tipping spam, not around a documented internal warning stretching back some twenty months. The e-mails turn a technical incident into a disclosure question.

First-order effects

  • Ameritrade's customer-exposure window now extends back to late 2005, meaning affected clients were potentially at risk for spam-driven stock pitches roughly two years before public acknowledgment.
  • Plaintiffs and regulators gain documentary evidence of foreknowledge — dated warning e-mails are exactly the artifact securities-fraud and negligence claims are built on.

Second-order effects

  • TD AMERITRADE is forced to reconcile its September 2007 investigation narrative with the January 2006 warnings, since any inconsistency between the two becomes the core of litigation and regulatory inquiry.
  • Other retail brokerages holding similar contact databases face pressure to audit their own internal warning trails before announcing breach findings, rather than dating incidents from detection.

Third-order effects

  • If the pattern holds, breach liability in financial services shifts from 'when the intrusion happened' to 'when the firm knew' — making internal security correspondence discoverable evidence that shapes how companies document — or avoid documenting — early warnings.
  • Long undetected dwell times become the planning assumption for brokerage data security, pushing firms toward external validation of compromises instead of self-reported discovery timelines.

The trend: Financial-sector breach disclosure is being redefined by internal warning records rather than detection dates, with documented foreknowledge becoming the decisive fact in litigation.