Massachusetts Fined TradeZero $750,000 Over Breach

The brokerage firm failed to secure customer data and misused automated software for account approvals.

Updated on Sept. 21, 2026 in Cybersecurity

Isometric editorial illustration featuring a hardened steel locking mechanism integrated into server rack architecture, symbolizing digital data security and regulatory compliance.
Massachusetts regulators fined TradeZero America $750,000 for cybersecurity failures and deficiencies in the firm's automated account approval systems. AI Illustration. Upload story photo >

Live Poll

Do you trust that your financial service providers take adequate steps to protect your personal data?

The Massachusetts Securities Division fined TradeZero America $750,000 for a security breach and failures in its automated account approval process. An unauthorized hacker accessed customer data in July 2024 through the company's third-party chat service.

Why it matters

The firm failed to vet the security controls of its third-party provider, Tawk.to, leaving sensitive customer information exposed to hackers. TradeZero has not received proof that the stolen information was deleted despite paying the ransom.

TradeZero used an automated software program to approve margin and options trading accounts for customers. The system lacked sufficient oversight, leading to the approval of unsuitable accounts.

The players

TradeZero America

This brokerage firm provides trading services and was found liable for data security lapses and faulty account automation.

Massachusetts Securities Division

This state regulatory body is responsible for enforcing investment laws and protecting consumers in Massachusetts.

The details

TradeZero America paid an unspecified amount in Bitcoin to the hacker to resolve the intrusion. The company must now hire an independent compliance consultant and reimburse Massachusetts investors for their trading losses.

Timeline

  1. July 2024: A hacker accessed customer information through a Tawk.to chat service.

The Tech Race

The enforcement action highlights the critical vulnerabilities introduced by delegating security to third-party vendors and automated systems. This case forces firms to reconsider the risks of outsourcing sensitive infrastructure to non-vetted partners.

Affected Massachusetts investors can expect a reimbursement process for trading losses incurred during the firm's period of non-compliance. Customers should monitor their financial statements closely for any signs of identity theft resulting from the July 2024 breach.

The takeaway

Firms must perform rigorous security audits on all third-party software providers to protect user data from unauthorized access. Investors should verify that their trading platforms utilize manual oversight rather than relying solely on automated approval processes.

Further reading

For more on the risks of digital platform vulnerabilities, visit Massachusetts Cybersecurity.

Source note: This article includes information reported by 22 News WWLP.

Live Poll

Do you trust that your financial service providers take adequate steps to protect your personal data?