Retail brokerage firm Scottrade says breach from late 2013 to early 2014 compromised up to 4.6M customers' contact information, including SSNs
Brian Krebs / Krebs on Security :
Context & Ripple Effects
Brian Krebs' report lands two years after the intrusion window closed: Scottrade's breach ran from late 2013 into early 2014, yet the disclosure only surfaced now, meaning up to 4.6M brokerage customers have spent years unaware their names, addresses, and SSNs were in attackers' hands. The combination matters — contact details plus SSNs is exactly the pairing that fuels targeted social engineering against financial accounts.
The disclosure also slots into a lineage the corpus keeps extending: the same SSN-centric exposure reappears in the Equifax breach affecting 143M consumers two years later, the healthcare.gov breach exposing partial SSNs in 2018, and the TransUnion filing covering 4.4M+ customers a decade on — with retail names like Neiman Marcus' 4.6M-customer notification echoing the same scale.
First-order effects
- Up to 4.6M Scottrade customers now face elevated identity-theft and targeted-phishing risk, since the stolen contact information paired with SSNs enables convincing impersonation of the broker itself.
- Scottrade bears immediate notification obligations across its customer base and answers for why detection and disclosure took roughly two years after the breach window ended.
Second-order effects
- Rival brokerages come under pressure to demonstrate their own breach-detection timelines, since a two-year lag between compromise and disclosure sets an unfavorable comparison point for the sector.
- Fraud-prevention and credit-monitoring vendors gain a recurring demand channel, as each large SSN exposure converts affected institutions into buyers of remediation services for their customers.
Third-order effects
- If the Scottrade-through-TransUnion pattern holds, SSNs function as a structural weak point across financial and government data holders, sustaining pressure toward regulatory mandates on breach-timeline disclosure and toward identity verification schemes that stop leaning on the SSN alone.
The trend: Consumer financial breaches keep recycling the same SSN-plus-contact-info exposure across a decade of disclosures — from Scottrade and Equifax to TransUnion — keeping identity data minimization and faster-mandated disclosure on the regulatory agenda.