Skip to content

Fidelity Investments

Disclosed Oct 9, 20241 year ago77,099 affectedConfirmed

Official notice

Fidelity breach exposes personal data of 77,099 customers

Fidelity said an unauthorized third party used two newly created customer accounts to submit fraudulent requests to an internal document database between August 17 and 19, 2024. The data of 77,099 people, including Social Security numbers and driver's licenses, was affected, though no Fidelity accounts or funds were accessed.

What is known

People affected77,099 (as reported by the organization)
DisclosedOct 9, 2024
DiscoveredAug 19, 2024
HappenedAug 17, 2024
AttackHacking
Data exposedNames, Social Security numbers, Government IDs, Other
SectorFinance · US
StatusConfirmed

Sources

Source
California Attorney General breach notice: Fidelity Investmentsoag.ca.gov · Official notice
Washington Attorney General breach notice: Fidelity Investmentsatg.wa.gov · Official notice
Oregon DOJ breach notice: Fidelity Investmentsjustice.oregon.gov · Official notice
California AG breach notice: Fidelity Investmentsoag.ca.gov · Regulator
Fidelity says data breach exposed personal data of 77,000 customerstechcrunch.com · News
Indiana Attorney General 2024 data breach report: Fidelity Investmentsin.gov · Official notice

Notices filed

WhereFiledPeople
California AGresidents of CAOct 9, 2024
Washington AGresidents of WAOct 9, 20242,731
Oregon DOJresidents of OROct 9, 202477,099
ResearchtotalOct 9, 202477,099
Indiana AGresidents of INOct 9, 20241,057

Other breaches at Fidelity Investments

BreachAffected
Disclosed Apr 12, 2016Apr 12, 201610 years ago31
Disclosed Nov 24, 2014Nov 24, 201411 years ago156
Disclosed Jul 31, 2013Jul 31, 201313 years agoUnknown
Stolen laptop held data of 196,000 HP retirement account customersMar 23, 200620 years agoLost or stolen deviceUnverified196K
History of this record
  • 2026-09-25 · source: empty to https://www.in.gov/attorneygeneral/consumer-protection-division/id-theft-prevention/files/DB-Year-to-Date-Reportdec-2024.pdf · backfill source
  • 2026-09-25 · data_types: [] to ["names","ssn","government-id","other"] · seed source
  • 2026-09-25 · records_basis: empty to organization · seed source
  • 2026-09-25 · records: empty to 77099 · seed source
  • 2026-09-25 · summary: empty to Fidelity said an unauthorized third party used two newly created customer accounts to submit fraudulent requests to an internal document database between August 17 and 19, 2024. The data of 77,099 people, including Social Security numbers a · seed source
  • 2026-09-25 · title: empty to Fidelity breach exposes personal data of 77,099 customers · seed source
  • 2026-09-25 · attack: unknown to hacking · backfill source
  • 2026-09-25 · discovered: empty to 2024-08-19 · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.

Everything about Fidelity Investments

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.