Hacking
TD Ameritrade has revealed the theft of user data including names, email addresses and phone numbers

Hackers hit US stockbroker TD Ameritrade

Spam investigation uncovers database breach

Written by Shaun Nichols in California

US stock broking firm TD Ameritrade has revealed a breach to one of its databases resulting in the theft of user data.

The company confirmed that, while online account numbers and passwords were not compromised, customer names, email addresses and phone numbers had all been stolen.

The database also contains Social Security numbers, although TD Ameritrade claimed that there is no evidence to suggest that the numbers were among the stolen data.

A spokesperson for the company told vnunet.com that the compromised database stored information on all of the company's 6.3 million customer accounts. It is not yet known how many customers were directly affected.

The breach came to light after an investigation into a surge of spam emails sent to TD Ameritrade customers.

The spokesperson confirmed that the spam was stock-related, but could not clarify whether the messages were part of a 'pump-and-dump' operation or served another purpose.

The exact nature of the breach was not disclosed, but TD Ameritrade and security firm ID Analytics, which was hired to help in the investigation, assured users that the breach had been fixed and that measures had been taken to prevent further break-ins.

Dave Marcus, security research and communications manager at McAfee, suggested that the breach was achieved with a mixture of break-in tactics.

"Based on TD Ameritrade's statements the attackers most likely used old-fashioned hacking, social engineering and a cocktail of malicious software, including password stealing Trojans and bots, to pilfer the customer data."

Tags:

Further reading

More P2P fraud victims expected

Criminals increasingly using peer-to-peer software to commit fraud   More...

France joins Chinese hacking row

Fourth country points the finger at Chinese hackers following breaches   More...

Companies still ignoring mobile data perils

Nine out of 10 firms putting information and reputation at risk   More...

Pfizer admits to third major data breach

Details on 34,000 staff stolen by former employee   More...

Related articles

Monster.com suffers job lot of data theft

Details stolen from hundreds of thousands of users   More...

Ameritrade may have been hacked since 2005

First warning issued to share trading firm in January 2006   More...

Police on alert after phone information theft

All data securely protected, says forensic company   More...

Hackers step up website attacks

Security forecast for 2008 makes grim reading   More...

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

12 May 2008

2.4 MBMicrosoft's battles, data breach fines and website rip-offs More...

09 May 2008

2.51 MBWiMax muddle, Google tactics and asteroid bunkum More...

08 May 2008

3.26 MBBroadband Anywhere, phone-free transport and Web 3.0 More...

Poll

DATA ENCRYPTION

DATA ENCRYPTION

Should encryption be mandatory for all personal data held by companies and governments?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

BlackBerry Bold

RIM unveils slimmed-down BlackBerry Bold

New handset due this summer   More...

BlackBerry Bold

BlackBerry Bold takes on 3G iPhone

New models go head-to-head, says analyst   More...

Advertisement

HP

HP 'in talks' to buy EDS

Company offering upwards of $12bn   More...

Virgin Media

Virgin prepares 50Gbps launch in 2008

Successful trial clears network for higher speeds   More...

Advertisement