The Maryland Office of the Attorney General reported a data breach involving SogoTrade, Inc. on April 28, 2025. The breach, which began on approximately May 8, 2024, and ended on approximately May 22, 2024, was caused by a phishing email that compromised four email accounts, potentially exposing personal information including names, financial account numbers, and Social Security Numbers. The number of affected individuals is currently unknown.
Source: https://oag.ca.gov/ecrime/databreach/reports/sb24-602415
TPRM report: https://www.rankiteo.com/company/sogotrade-inc-
"id": "sog600072825",
"linkid": "sogotrade-inc-",
"type": "Breach",
"date": "5/2024",
"severity": "60",
"impact": "3",
"explanation": "Attack with significant impact with internal employee data leaks"
{'affected_entities': [{'industry': 'Financial Services',
'name': 'SogoTrade, Inc.',
'type': 'Company'}],
'attack_vector': 'Phishing',
'data_breach': {'personally_identifiable_information': True,
'sensitivity_of_data': 'High',
'type_of_data_compromised': ['names',
'financial account numbers',
'Social Security Numbers']},
'date_detected': '2025-04-28',
'date_publicly_disclosed': '2025-04-28',
'description': 'The Maryland Office of the Attorney General reported a data '
'breach involving SogoTrade, Inc. on April 28, 2025. The '
'breach, which began on approximately May 8, 2024, and ended '
'on approximately May 22, 2024, was caused by a phishing email '
'that compromised four email accounts, potentially exposing '
'personal information including names, financial account '
'numbers, and Social Security Numbers. The number of affected '
'individuals is currently unknown.',
'impact': {'data_compromised': ['names',
'financial account numbers',
'Social Security Numbers']},
'initial_access_broker': {'entry_point': 'Phishing Email'},
'post_incident_analysis': {'root_causes': 'Phishing Email'},
'references': [{'date_accessed': '2025-04-28',
'source': 'Maryland Office of the Attorney General'}],
'title': 'Data Breach at SogoTrade, Inc.',
'type': 'Data Breach',
'vulnerability_exploited': 'Email Compromise'}