What Happened in the US Tiger Securities Data Breach?
US Tiger Securities Inc., a fintech brokerage firm affiliated with TradeUP Securities, Inc., recently notified customers about a data security incident. The company discovered the issue in July 2025, when it found that files in its shared virtual back-office environment had been encrypted. This environment supports back-office functions for both US Tiger and TradeUP.
According to the notification, unauthorized access to the network occurred in July 2025. Investigators later determined that an outside party copied certain files during that time. Importantly, the intrusion did not reach the separate TradeUP production environment, so customer-facing trading operations continued without disruption.
As soon as US Tiger became aware of the incident, it brought in legal counsel to guide the response. Legal counsel then engaged a cybersecurity firm to conduct a forensic investigation. This process took time because the company needed to carefully review the affected files to identify which individuals were impacted.
The review process concluded in April 2026, nearly nine months after discovery. Because of this lengthy investigation, affected individuals were not notified until May 2026. This gap between discovery and notification reflects the complexity of determining exactly whose data was involved.
Who was affected?
US Tiger has not publicly disclosed the exact number of individuals affected by this breach. However, the notification letters indicate that customers of US Tiger Securities had their personal information contained in the compromised files. As a fintech brokerage, its customer base likely includes individuals across the United States who use the platform for trading and investment services.
Because the breach involved the shared back-office environment rather than the trading platform itself, the exposure appears tied to administrative and account-related records rather than active trading data. Still, anyone who received a notice from US Tiger should assume their personal information was part of the exposed files. The company has not indicated whether employees, in addition to customers, were affected.
What Information Was Potentially Exposed?
The notification letter confirms that names were included in the exposed files, along with additional personal details. While the specific list of exposed data categories was not fully detailed in the notice, the letter references additional personal information beyond just names.
- Full name
- Additional personal information specific to each individual, as identified during the company’s review
Even when the exact scope of exposed data isn’t fully spelled out, any breach involving a brokerage firm raises serious concerns. Financial services companies typically hold sensitive account details, identification numbers, and contact information. As a result, affected individuals should treat this incident seriously, regardless of the exact data fields involved.
Identity thieves often combine stolen names with other personal details to open fraudulent accounts or file false tax returns. In addition, because US Tiger operates in the financial sector, there’s a heightened risk that account-related information could be used for targeted phishing attempts. This means affected customers should remain alert to unusual account activity or suspicious communications claiming to be from financial institutions.
What is the company doing?
Once US Tiger discovered the incident, it acted quickly to engage legal counsel and a forensic cybersecurity firm. This investigation aimed to determine the scope of the intrusion and confirm that the core trading environment remained secure. As a result, the company confirmed that customer trading operations were not impacted by the breach.
Following the investigation, US Tiger implemented additional safeguards and technical security measures to better protect its network and systems going forward. The company also arranged a complimentary 24-month subscription to Experian IdentityWorks for affected individuals. This service helps monitor credit files and alert users to potential fraudulent activity tied to their personal information.
What Should Affected Individuals Do?
Monitor Your Credit Reports Closely
Affected individuals should regularly check their credit reports for unfamiliar accounts or inquiries. Because personal information was copied in this breach, monitoring your credit file is one of the most effective ways to catch fraud early.
You can request free credit reports from each of the three major credit bureaus. Reviewing these reports every few months, rather than just once, increases the chance of spotting suspicious activity before it causes lasting damage.
Enroll in the Offered Identity Protection Service
US Tiger is offering a complimentary 24-month membership to Experian IdentityWorks for those affected. This service includes credit monitoring, identity restoration support, and up to $1 million in identity theft insurance coverage.
To take advantage of this protection, affected individuals must enroll by the deadline stated in their notification letter. Since this service comes at no cost, there’s little reason not to activate it promptly after receiving your notice.
Consider a Fraud Alert or Credit Freeze
Because personal information tied to a financial brokerage was exposed, placing a fraud alert or credit freeze can add another layer of protection. A fraud alert requires creditors to verify your identity before opening new accounts in your name.
A credit freeze goes a step further by restricting access to your credit file entirely. Although a freeze may require extra steps when you apply for new credit yourself, it offers stronger protection against unauthorized account openings.
Stay Alert for Phishing Attempts
Following any data breach, scammers often use exposed information to craft convincing phishing emails or phone calls. Because this breach involved a brokerage firm, be especially cautious of messages claiming to be from financial institutions asking for login credentials or personal details.
Never click links or provide information in unsolicited messages. Instead, contact the company directly using verified contact information if you’re unsure whether a communication is legitimate.
Consult a Data Breach Attorney
If you received a notification letter from US Tiger, you may want to speak with a data breach attorney about your legal options. An attorney can help you understand whether you qualify for compensation related to this incident.
Many law firms offer free consultations to review your situation. This means you can explore your options without any upfront cost or obligation.
More Information
Official data breach notification from Washington State Attorney General
Official data breach notification from California Attorney General
