Topstep LLC was the subject of a data breach notification filed with the IN Attorney General. The AG filing was recorded on January 20, 2026. The breach or discovery date reported in the filing is December 14, 2025.
Data Exposed
Topstep LLC was the subject of a data breach notification filed with the IN Attorney General. The AG filing was recorded on January 20, 2026. The breach or discovery date reported in the filing is December 14, 2025.
Topstep LLC operates within the financial technology and proprietary trading sector, providing evaluation accounts, funding, and advanced trading platforms for retail traders worldwide. Because of the nature of its business, Topstep collects and maintains a vast repository of highly sensitive consumer and financial data. Traders who register for evaluations or secure funded accounts must submit comprehensive personal identifying information, financial records, banking details, and government-issued identification to comply with strict regulatory frameworks, anti-money laundering protocols, and payout processing requirements. This deep integration of financial and personal data makes Topstep a central repository of lucrative information, heightening the target profile for cybercriminals seeking to exploit digital assets. In 2026, Topstep LLC reported a cybersecurity incident to the Indiana Attorney General, raising serious concerns among the trading community regarding the security of their stored credentials and financial data. While investigations into such corporate network breaches typically involve sophisticated tactics like credential harvesting, unauthorized database access, or deployment of ransomware by threat actors, the incident underscores vulnerabilities in digital infrastructure. Financial tech platforms often grapple with complex web applications, third-party software integrations, and large volumes of transactional data, any of which can serve as an entry point for malicious actors looking to bypass perimeter defenses and access internal environments. The data compromised in incidents affecting financial and trading technology platforms frequently includes full legal names, dates of birth, Social Security numbers, banking and routing numbers, government identification documents, and account login credentials. The exposure of this specific combination of information exposes victims to severe, long-term risks. Social Security numbers and dates of birth form the bedrock of identity theft, enabling cybercriminals to open fraudulent credit lines, secure loans, or intercept tax refunds in a victim's name. Furthermore, compromised banking details and trading account credentials create an immediate pathway for financial account takeover, unauthorized asset transfers, and severe monetary loss. Topstep LLC, like other entities handling sensitive consumer and financial data, was bound by statutory and common law duties to implement robust cybersecurity measures. Under state data protection laws and the overarching mandates of the Federal Trade Commission Act, financial service providers are required to deploy reasonable administrative, technical, and physical safeguards to protect digital assets from unauthorized access. The occurrence of a significant data breach strongly suggests a potential failure in these mandated security protocols, whether through unpatched vulnerabilities, inadequate encryption standards, or insufficient employee access controls, which may constitute actionable negligence under the law. Receiving a formal data breach notification letter from Topstep LLC is a direct acknowledgment by the company that your personal and financial information was exposed to unauthorized third parties. Legally, this notification establishes the foundational standing necessary to participate in a class action lawsuit aimed at holding the company accountable for its security failures. Importantly, affected individuals do not need to prove that they have already suffered actual financial theft or identity fraud to seek legal remedies; the increased risk of future harm and the cost of mitigating that risk are recognized grounds for compensation. Our firm evaluates these cases on a contingency fee basis, meaning you pay nothing out of pocket, and we only collect a fee if we successfully recover compensation on your behalf.
Based on the data types reported, affected individuals face:
Your SSN is the master key to your identity. Once exposed, criminals can open new lines of credit, take out loans, or file taxes in your name.
Combined with a name and other leaked data, date of birth helps criminals pass identity verification questions at banks and government agencies.
What the Indiana data breach notification law and federal statutes entitle you to recover:
The hours spent responding to a data breach — canceling accounts, contacting credit bureaus, updating passwords, and investigating fraud — represent compensable economic harm in data breach litigation.
Once your SSN is exposed, protection becomes an ongoing expense. Plaintiffs in data breach settlements have recovered costs for credit freezes, identity protection subscriptions, and time spent dealing with fraudulent accounts — sometimes covering multiple years of exposure.
Fees charged to close and reopen accounts, issue replacement cards, or dispute fraudulent transactions are recoverable in data breach litigation. So are the costs of overdrafts, late payments, and credit damage caused by unauthorized activity.
When login credentials are exposed, the costs of downstream account compromises — password managers, security audits, and recovery costs for hijacked downstream accounts — can be recovered. Courts in recent class actions have awarded damages for credential exposure even without proven misuse.
Several state data breach laws provide for statutory minimum damages — fixed amounts recoverable per affected individual regardless of actual loss. These provisions exist specifically to make legal action viable for victims who have not yet experienced direct harm.
Note: an attorney general breach filing does not by itself establish a settlement fund, a payment amount, or a claim deadline. If an official settlement notice is later issued, rely on that notice for payment details and deadlines.
No. Under Indiana data breach notification law and federal law, the unauthorized exposure of your personal data — regardless of whether it has been actively misused — can be sufficient grounds for a claim. The breach itself is the injury.
Nothing. The Law Office of David S. Harris handles data breach cases on contingency — you pay zero upfront and owe nothing unless compensation is recovered.
Immediately place a free credit freeze at all three bureaus (Equifax, Experian, TransUnion). A freeze blocks new accounts from being opened in your name. Then file a complaint with the FTC at IdentityTheft.gov and contact our office — SSN exposure is one of the most serious breach types.
Banks may reverse fraudulent charges, but they are not obligated to compensate you for time lost, stress, or indirect damages. A class action claim against the breached company can recover those additional categories of harm.
State statutes of limitations for data breach claims typically run 2–4 years from the date of the breach or its discovery. Because this breach was recently disclosed, the window is open — but acting early preserves your options and strengthens the case.
Accepting free credit monitoring from Topstep LLC does not waive your right to pursue legal action unless you signed a specific release waiving claims. In most cases, victims who accepted monitoring can still file.
Not necessarily. Many data breach victims are never notified directly. If your personal information was held by Topstep LLC during the relevant period, you may still qualify even without receiving a letter. A free eligibility review can confirm your status.
Received a notification letter from Topstep LLC?
What it means and what to do next.
Topstep LLC breach?
Free case review · No fee unless you win