Massachusetts Fined TradeZero $750,000 Over Security Failures

State regulators penalized the firm for a 2024 data breach and systemic automated account approval errors.

Updated on Sept. 21, 2026 in Cybersecurity

Isometric editorial illustration showing a heavy steel lock and security gate mechanism, representing structural oversight of financial data security.
The Massachusetts Securities Division fined TradeZero America $750,000 for failures in its third-party security vetting and automated account approval processes. AI Illustration. Upload story photo >

Live Poll

Do you trust that your financial service providers take adequate steps to protect your personal data?

The Massachusetts Securities Division issued a $750,000 fine to TradeZero America following a data breach and failures in its automated account approval processes. The firm must now reimburse investors for trading losses and hire an independent compliance consultant to rectify its operational lapses.

Why it matters

This enforcement action underscores the mounting regulatory scrutiny on firms that neglect the security vetting of third-party software vendors. It highlights the risks financial institutions face when outsourcing sensitive functions to external digital services.

The $750,000 fine follows an investigation into a July 2024 incident where a hacker accessed customer records through a Tawk.to chat service. The investigation also found the firm’s automated software routinely approved unsuitable margin and options accounts.

The players

TradeZero America

A brokerage firm that offers margin and options trading services to individual investors.

Massachusetts Securities Division

The state regulatory authority responsible for protecting investors and enforcing securities laws.

Tawk.to

A third-party vendor providing online chat software for customer communication and support.

The details

The breach occurred when the firm failed to properly vet the security controls of Tawk.to, a third-party chat service integrated into its platform. Furthermore, the firm relied on an automated program for customer account applications, which bypassed necessary checks to ensure suitability for high-risk margin and options trading. The parent company subsequently attempted to contain the breach by paying an unspecified ransom in Bitcoin to the unauthorized party.

Timeline

  1. July 2024: A hacker accessed customer information through a third-party chat service.

The Tech Race

This enforcement action aligns with Massachusetts Securities Division compliance mandates requiring firms to vet third-party vendors and ensure the suitability of customer trading accounts. The ruling sets a benchmark for how state regulators evaluate the risks posed by automated, vendor-dependent financial infrastructure.

Investors affected by the security failures are entitled to reimbursement for verified trading losses. The mandated hiring of an independent compliance consultant aims to ensure the platform’s future automated account approvals meet rigorous security and suitability standards.

The takeaway

Regulators are increasingly holding firms financially liable for the security shortcomings of their third-party digital tools. Investors should monitor the progress of the court-ordered compliance overhaul to ensure the platform meets updated security benchmarks.

Further reading

For broader trends in digital security governance, visit Cybersecurity.

Source note: This article includes information reported by 22 News WWLP.

Live Poll

Do you trust that your financial service providers take adequate steps to protect your personal data?

Massachusetts Fined TradeZero $750,000 Over Security Failures