On MovieTome: Whedon makes an offer on Terminator
BNET Business Network:
BNET
TechRepublic
ZDNet

September 14th, 2007

TD Ameritrade discovers database breach

Posted by Larry Dignan @ 6:59 am

Categories: E-commerce, General, Security, Web Technology

Tags: Database, Ameritrade Inc., Larry Dignan

Online broker TD Ameritrade said Friday that it has discovered a database breach that compromised customer accounts.

In a statement, TD Ameritrade said it “discovered and eliminated unauthorized code from its systems that allowed access to an internal database.” TD Ameritrade found the breach as it was investigating stock-related spam.

Disclosure: I have more than a passing interest in this since I’m a TD Ameritrade customer.

Here’s what TD Ameritrade’s analysis revealed:

  • Assets are safe since user IDs, personal identification numbers and passwords were kept in a separate database;
  • Email addresses, names, addresses and phone numbers were taken. This fact explains why TD Ameritrade was investigating a bunch of spam complaints;
  • Account numbers, date of birth and Social Security numbers were in the breached database but not taken.

CEO Joe Moglia apologized for the unwanted spam and said there was “no evidence” that sensitive data was taken. TD Ameritrade also hired ID Analytics to monitor for potential identity theft.

The company also said that clients don’t have to do anything special other than monitoring their personal information.

Update:  TD Ameritrade is seeing heavy call volume over this issue. The log-in screen gives you the following message:

For more information regarding the recent communications about the SPAM investigations, please go to www.amtd.com. You’ll find our Frequently Asked Questions and see a message from our CEO, Joe Moglia. If you would like to discuss this with one of our representatives, please feel free to send us an email or give us a call. We are anticipating higher than normal call volumes, so you may experience longer than normal hold times.

Further comment from Michael Krigsman.

Larry DignanLarry Dignan is Editor in Chief of ZDNet and Editorial Director of ZDNet sister site TechRepublic. See his full profile and disclosure of his industry affiliations.

For daily updates, follow Larry on Twitter.

Email Larry Dignan

Subscribe to Between the Lines via Email alerts or RSS.

  • Talkback
  • Most Recent of 8 Talkback(s)
RE: TD Ameritrade discovers database breach
Trying to secure every data source out there containing personal information is futile. We need to overhaul the way business is done so that it takes more than a name, dob, and ss number to commit fi... (Read the rest)
Posted by: Someguy2 Posted on: 09/18/07 You are currently: a Guest | | Terms of Use
That's great  BoisD'Arc | 09/14/07
Two Years Ago  Renceward | 09/14/07
Well that explains a lot (I'm a customer of theirs as well)  shawkins | 09/14/07
Explains a lot for me as well  analytic168@... | 09/14/07
RE: TD Ameritrade discovers database breach  Emmy22 | 09/14/07
RE: TD Ameritrade discovers database breach  ekistics22 | 09/14/07
They'd have already known if they listened to their customers...  chaisty | 09/14/07
RE: TD Ameritrade discovers database breach  Someguy2 | 09/18/07

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement
Click Here

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here