Secretary of the Commonwealth William F. Galvin has fined broker-dealer TradeZero America, Inc. $750,000 over a data breach caused by a poorly-vetted online chatbot that the company used for its website.
According to a consent order filed by Galvin’s Securities Division this week, the online chat service Tawk.to was used on TradeZero’s website through late 2024. In July 2024, an unknown hacker was able to gain access to TradeZero customer personally identifiable information through Tawk.to. Documents uploaded via the chatbot were also compromised.
The consent order states that an investigation by the Securities Division revealed that TradeZero failed to follow state and federal laws, and its own internal procedures, requiring the vetting of third-party vendors before and after using their services. As a result of the poor vetting, TradeZero failed to ensure adequate security controls implanted by Tawk.to, and the personal information of thousands of customers was compromised.
Though TradeZero’s parent company made a payment in Bitcoin to the hacker to in exchange for a promise to return the data, the company has not received proof from the hacker that the data was deleted. To date, TradeZero has been unable to obtain full or complete information from the vendor regarding the breach.
In the course of the investigation, the Securities Division also discovered TradeZero used an automated program to review customer applications. The use of the automated program resulted in TradeZero’s approval of certain applications not suitable for margin accounts or options trading, the consent order states.
In addition to the $750,000 administrative fine, the consent order requires TradeZero to reimburse the trading losses of Massachusetts investors who were improperly approved for margin accounts or options trading, retain an independent compliance consultant, and to implement improvements to cybersecurity and account approval policies.