CSIDB logo
Incident

Fidelity Investments

Incident posture

Attack window
2024
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-09-01 12:00

Linked entities

Victim
Fidelity Investments
Threat actors
0 actors
Sources
5 sources

Timeline

Occurred
2024
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

In August, an unauthorized third party exploited a vulnerability in Fidelity Investments' online access controls, allowing them to manipulate a ten-digit "Image ID" in the browser to retrieve documents belonging to other users from the company's internal Document Image Repository over a three-day period. The breach exposed sensitive personal information—including Social Security numbers, financial account details, driver's licenses, passports, and medical records—of more than 77,000 customers, as well as beneficiaries and minor relatives, though no customer accounts or funds were directly accessed. The incident led to a $2.5 million class-action settlement offering affected individuals up to $5,000 for documented losses, credit monitoring services, and pro rata cash payments, along with a separate $1.25 million fine from Massachusetts securities regulators for inadequate cybersecurity enforcement and delayed notifications.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

Between August 17 and August 19, 2024, Fidelity Investments experienced a data breach when an unidentified and unauthorized third party accessed personal information belonging to tens of thousands of customers and associated individuals. The breach was carried out by exploiting a vulnerability in Fidelity's online access controls within an internal database known as the Document Image Repository. Under normal operation, the repository was intended to restrict each customer to viewing only the images of documents associated with their own account. However, because Fidelity did not reasonably enforce its own technical security policies, any Fidelity customer could manipulate a ten-digit "Image ID" value displayed in the browser while accessing their own documents in order to view the documents of other users. Over the course of approximately three days in August 2024, the bad actor used this method to access and obtain images of documents containing highly sensitive personal information, including Social Security numbers, active credit card numbers, financial account numbers, medical information, passports, driver's licenses, and other personally identifiable information. The documents exposed in the breach belonged not only to existing Fidelity customers but also to beneficiaries, relatives, and in some cases minor children of those customers, expanding the pool of affected individuals beyond direct account holders. Notably, the incident did not involve any unauthorized access to Fidelity customer accounts or funds; the compromise was limited to the document images and the information contained within them.

Fidelity detected the unauthorized activity and stopped further access on August 19, 2024, bringing the three-day breach to a close. Following the discovery, the company took steps to notify affected customers in accordance with applicable laws and informed appropriate regulators. However, subsequent investigations determined that Fidelity had failed to notify many of the impacted individuals, including beneficiaries, relatives, and minor children of customers, whose personal information had also been exposed. Massachusetts Secretary of the Commonwealth William Galvin, the state's top securities regulator, found that at least 2,768 Massachusetts residents were affected by the breach. The broader scope of the incident was reported in various forms across different sources: while Fidelity's own statements and the Massachusetts regulator referenced approximately 77,000 customers directly affected, the class action litigation alleged that the personal information of more than 155,000 people was exposed in total. An additional group of roughly 86,000 customers had their financial account numbers and routing numbers specifically compromised during the same timeframe. In the nearly two years following the incident, Fidelity stated that it had no evidence that identity theft or fraud had occurred as a result of the breach.

In response to the breach and the regulatory findings, Fidelity faced both a $1.25 million administrative fine from the Massachusetts securities regulator and a $2.5 million class action settlement. On April 22, 2026, Fidelity submitted an Offer of Settlement to Galvin's office, agreeing to pay the $1.25 million penalty without admitting or denying the allegations. As part of the regulatory order, Fidelity was required to engage an independent cybersecurity consultant, certify that its cybersecurity controls related to customer data had been changed and enhanced, and identify and notify all Massachusetts residents whose personal information was exposed in the breach and who had not previously been notified. Separately, in mid-March 2026, Fidelity agreed to pay $2.5 million to settle the proposed class action lawsuit, and a U.S. District Judge in the District of Massachusetts granted preliminary approval of the deal. Under the terms of the class action settlement, class members became eligible for up to $5,000 in reimbursement for documented monetary losses directly related to the breach, including unreimbursed fraud, identity theft, professional fees, and credit expenses. All class members who filed valid claims were eligible to receive a pro rata cash payment of approximately $100, and California residents stood to receive an additional $50 under the state's Consumer Privacy Act. The settlement also provided two years of identity theft protection and credit monitoring services, which included up to $1 million in fraud and identity theft insurance coverage. The deadline for class members to submit a claim form was July 27, 2026, with a final approval hearing scheduled for July 9, 2026. Fidelity did not admit to wrongdoing in either the regulatory or civil proceedings, but committed to establishing a settlement fund and implementing enhanced business practices as part of the resolution.

Sources

Sources available to members: 5 sources.

CSIDB