Ameritrade leak looks to have started in late '05, much earlier than reported
E-mails obtained by Network World show that Ameritrade received explicit and repeated warnings from an IT security expert starting Jan. 9, 2006 that its customer data had apparently been compromised …
Context & Ripple Effects
Six days after TD AMERITRADE published the results of its own client SPAM investigation, Network World has obtained e-mails that rewrite the timeline: an IT security expert warned the firm explicitly and repeatedly starting Jan. 9, 2006 that customer data had apparently been compromised, pointing to a leak that began in late 2005 — far earlier than anything the company had reported.
That gap matters because the firm's September 2007 account framed the compromise around recently surfaced stock-tipping spam, not around a documented internal warning stretching back some twenty months. The e-mails turn a technical incident into a disclosure question.
First-order effects
- Ameritrade's customer-exposure window now extends back to late 2005, meaning affected clients were potentially at risk for spam-driven stock pitches roughly two years before public acknowledgment.
- Plaintiffs and regulators gain documentary evidence of foreknowledge — dated warning e-mails are exactly the artifact securities-fraud and negligence claims are built on.
Second-order effects
- TD AMERITRADE is forced to reconcile its September 2007 investigation narrative with the January 2006 warnings, since any inconsistency between the two becomes the core of litigation and regulatory inquiry.
- Other retail brokerages holding similar contact databases face pressure to audit their own internal warning trails before announcing breach findings, rather than dating incidents from detection.
Third-order effects
- If the pattern holds, breach liability in financial services shifts from 'when the intrusion happened' to 'when the firm knew' — making internal security correspondence discoverable evidence that shapes how companies document — or avoid documenting — early warnings.
- Long undetected dwell times become the planning assumption for brokerage data security, pushing firms toward external validation of compromises instead of self-reported discovery timelines.
The trend: Financial-sector breach disclosure is being redefined by internal warning records rather than detection dates, with documented foreknowledge becoming the decisive fact in litigation.